0

OK, I think my lil' sis must have downloaded some nasty virus/spyware stuff. I am getting popups for spyware programs and fake security messages. I looked up all the processes that were running and these look pretty suspiscous:

ATMCLK.EXE
wuauclt windows
wgatray windows gen
inetinfo.exe Trojan.W32.RONTOKBRO
csrss.exe
smss.exe
dcomcfg.exe trojan

Also VirusScan grabbed a couple too, but it seems like it couldn't delete/quaranteen a couple. Here is the log file from VirusScan:

6/28/2006 2:28:44 AM Move failed (Clean failed) FISHLAPTOP\David firefox.exe C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\K1AV8L6Z\wind32[1].exe Generic MultiDropper.d (Trojan)
6/28/2006 2:28:47 AM Move failed (Clean failed) FISHLAPTOP\David firefox.exe C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\CL2V4LM7\wizp32[1].exe Generic StartPage.o (Trojan)
6/28/2006 2:28:50 AM Move failed (Clean failed) FISHLAPTOP\David firefox.exe C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\CL2V4LM7\wizp32[1].exe Generic StartPage.o (Trojan)
6/28/2006 2:28:51 AM Deleted FISHLAPTOP\David firefox.exe C:\Documents and Settings\David\Local Settings\Temp\win8E.tmp Generic StartPage.o (Trojan)
6/28/2006 2:51:01 AM Deleted FISHLAPTOP\David ldFE89.tmp C:\WINDOWS\system32\hvcycg.dll FakeAlert-B (Trojan)


And here is my HJT log file:

Logfile of HijackThis v1.99.1
Scan saved at 4:36:38 PM, on 6/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\LogMeIn\RaMaint.exe
C:\Program Files\LogMeIn\LogMeIn.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Apoint\HidFind.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dcomcfg.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\LIUtilities\WinTasks\wintasks.exe
C:\WINDOWS\system32\atmclk.exe
C:\Documents and Settings\David\My Documents\My Downloads\hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Nothing - {5f4c3d09-b3b9-4f88-aa82-31332fee1c08} - C:\WINDOWS\system32\hp100.tmp
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [39243471.exe] C:\WINDOWS\system32\39243471.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [39243471.exe] C:\Documents and Settings\David\Local Settings\Application Data\39243471.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winepi32 - C:\WINDOWS\SYSTEM32\winepi32.dll
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\LogMeIn.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Thanks in advance,
DC

2
Contributors
3
Replies
4
Views
11 Years
Discussion Span
Last Post by DMR
0

Congratulations- you are the proud father of a healthy, active Smitfraud infection! :mrgreen:


Please do the following:

You will need to close/quit all web browser programs and disconnect from the Internet for much of the following, so you should print out these instructions or save them into a text file with Notepad.

* Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

* Please download Ewido Anti-Malware it is a free version of the program.

  1. Install Ewido Anti-Malware
  2. When installing, under "Additional Options" uncheck..
    • Install background guard
    • Install scan via context menu
  3. Launch Ewido, there should be an icon on your desktop, double-click it.
  4. The program will now open to the main screen.
  5. You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Then click on Start Update.
  6. The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful")

Close Ewido for now.
==============

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only
Close the program for now.
==================

Next, please reboot your computer in Safe Mode by doing the following :

  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.

1) Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser : Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser: Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it does force a restart, please reboot into Safe Mode again, in order to complete the following step. If it does not reboot, please remain in Safe Mode until further notice.

3) Launch Ewido from your Desktop :

  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.

Close Ewido Anti-Malware.

4) Reboot your computer normally.

If SmitfraudFix did not force a reboot, then you should now see a text file appear onscreen with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Note : running option #2 on a non infected computer will remove your Desktop background.

5) Post the content of rapport.txt, the Ewido report and a new HijackThis! log in your next reply.

0

Thanks! I followed your instructions and it seems to have worked (no popups or other symptoms). Here are my logs you requested.

Thanks again,

DC

rapport.txt

SmitFraudFix v2.65

Scan done at 12:06:47.10, Thu 06/29/2006
Run from C:\Documents and Settings\David\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{7916f057-223f-4612-ac84-e882cbe043d4}"="bals"

[HKEY_CLASSES_ROOT\CLSID\{7916f057-223f-4612-ac84-e882cbe043d4}\InProcServer32]
@="C:\WINDOWS\system32\hvcycg.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{7916f057-223f-4612-ac84-e882cbe043d4}\InProcServer32]
@="C:\WINDOWS\system32\hvcycg.dll"


»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri

C:\WINDOWS\system32\hvcycg.dll -> Missing File


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\system32\dcomcfg.exe Deleted
C:\WINDOWS\system32\hp???.tmp Deleted
C:\WINDOWS\system32\ld????.tmp Deleted
C:\WINDOWS\system32\ot.ico Deleted
C:\WINDOWS\system32\regperf.exe Deleted
C:\WINDOWS\system32\simpole.tlb Deleted
C:\WINDOWS\system32\stdole3.tlb Deleted
C:\WINDOWS\system32\1024\ Deleted
C:\DOCUME~1\David\FAVORI~1\Antivirus Test Online.url Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

Ewido

---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 2:20:26 PM 6/29/2006

+ Scan result:

:mozilla.260:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.261:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.199:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.200:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.201:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.202:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.203:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.204:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.205:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.206:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.207:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.208:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.209:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.210:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.211:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.212:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.213:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.214:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.215:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.216:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.217:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.218:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.219:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.220:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.221:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.222:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.223:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.224:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.225:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.226:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.227:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.228:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.229:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.230:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.231:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.232:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.233:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.234:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.235:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.236:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.237:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.238:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.239:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.240:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.241:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.242:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.243:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.244:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.245:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.246:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.247:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.248:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.331:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.474:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.481:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.511:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.536:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
D:\Documents and Settings\501142534\Cookies\501142534@cnn.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.117:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.278:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.286:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.10:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.31:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.32:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.285:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.684:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.685:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.686:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.687:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.688:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.689:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.633:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.634:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.635:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.291:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.292:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.101:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.102:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.103:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.104:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.105:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.106:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.107:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.108:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.109:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
D:\Documents and Settings\501142534\Cookies\501142534@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.15:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\t5lilslx.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.9:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
D:\Documents and Settings\501142534\Cookies\501142534@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.120:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.736:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.330:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.10:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\t5lilslx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.11:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\t5lilslx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.12:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\t5lilslx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.8:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\t5lilslx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.340:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.341:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.14:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\t5lilslx.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.41:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
D:\Documents and Settings\501142534\Cookies\501142534@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.140:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.22:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.23:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.24:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.25:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.26:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.27:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.28:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.38:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.39:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.654:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.655:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.656:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.657:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.658:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.750:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.751:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.180:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.253:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.254:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.55:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.56:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.62:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.64:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.65:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.408:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.
:mozilla.699:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.700:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.701:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.703:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.704:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.705:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.706:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.100:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.709:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.710:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.711:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.712:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.713:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.522:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.69:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.71:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.287:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.288:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.289:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.290:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.148:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.149:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.30:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.33:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.42:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.43:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.186:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.187:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.188:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.189:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.190:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.191:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.192:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.193:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.194:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.195:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.537:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.538:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.539:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.540:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.280:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.281:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.282:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.283:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.284:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.550:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Spylog : Cleaned.
:mozilla.551:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.552:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.553:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.554:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.555:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.556:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.557:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.558:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.559:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.560:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.561:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.562:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.563:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.564:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.565:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.566:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.567:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.574:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.575:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.576:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.577:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.652:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.588:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.589:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.590:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.591:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.592:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.593:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.594:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Trafic : Cleaned.
:mozilla.11:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.12:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.13:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.13:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\t5lilslx.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.14:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.15:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.16:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.17:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.18:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.19:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.20:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.21:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.668:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.626:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.644:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.645:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.646:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.647:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.639:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.640:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.641:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\5mej9yee.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\WINDOWS\system32\winepi32.dll -> Trojan.Agent.vg : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\\kernel32.dll -> Trojan.Small : Cleaned with backup (quarantined).


::Report end

HijackThis!

Logfile of HijackThis v1.99.1
Scan saved at 3:47:11 PM, on 6/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\LogMeIn\RaMaint.exe
C:\Program Files\LogMeIn\LogMeIn.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\WINDOWS\system32\39243471.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Documents and Settings\David\My Documents\My Downloads\hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Nothing - {5f4c3d09-b3b9-4f88-aa82-31332fee1c08} - C:\WINDOWS\system32\hp100.tmp (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [39243471.exe] C:\WINDOWS\system32\39243471.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [39243471.exe] C:\Documents and Settings\David\Local Settings\Application Data\39243471.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winepi32 - winepi32.dll (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\LogMeIn.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

0

Much bettter, but there's still some cleanup to do by the looks of your latest log:

1. Run HijackThis again, put a check in the boxes to the left of the following entries, and then click the "Fix Checked" button. Close HijackThis once the fixes are complete:

O2 - BHO: Nothing - {5f4c3d09-b3b9-4f88-aa82-31332fee1c08} - C:\WINDOWS\system32\hp100.tmp (file missing)
O4 - HKLM\..\Run: [39243471.exe] C:\WINDOWS\system32\39243471.exe
O4 - HKCU\..\Run: [39243471.exe] C:\Documents and Settings\David\Local Settings\Application Data\39243471.exe
O20 - Winlogon Notify: winepi32 - winepi32.dll (file missing)

2. Reboot into Safe Mode again and:

* Open Windows Explorer, and in the Folder Options->View settings under the Tools menu, select "show hidden files and folders", and uncheck "Hide protected operating system files" and "Hide extentions for known file types".

* While still in Explorer, search for and delete the following files if they still exist:
C:\WINDOWS\system32\hp100.tmp
C:\WINDOWS\system32\39243471.exe
C:\Documents and Settings\David\Local Settings\Application Data\39243471.exe
C:\WINDOWS\system32\hvcycg.dll
winepi32.dll <- This file is probably in your C:\WINDOWS\system32 folder if it exist at all, but search your entire C: drive for the filename

* Run another complete system scan with ewido; as before, have it clean all items it finds. Save the new log.

* Empty your Recycle Bin and reboot normally.

* Run HJT again and post the new log. Also post the new ewido log.

-

This topic has been dead for over six months. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.