1
   

[Resloved] Ewido Problem with Yuckware Removal

 
 
awyt
 
Reply Thu 11 Aug, 2005 05:21 pm
I followed you yuckware removal instructions except I hit a snag. I ran Ewido for the first time, and once it completed the scan it began fixing what it found. However, part of the way through the program froze. Now, every time that I open Ewido it freezes. All of the other steps worked fine.

Here is my HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 1:05:49 PM, on 11/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
C:\WINDOWS\system32\RunDll32.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mim.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Sony\Net MD Simple Burner\NetMDSB.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\r_server.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_3c00.dll"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [Launcher] C:\Program Files\Canon\PhotoStitch\Launcher.exe /P
O4 - HKLM\..\Run: [Kazaa Download Accelerator Updater] regsvr32 /s C:\WINDOWS\System32\kdpupd.dll
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_0dfd.dll"
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/06fe0e3c457a449ebd03/netzip/RdxIE601.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildtangent.com/bgn/partners/ea/needforspeed/install.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.com/games/popcaploader_v5.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O16 - DPF: {FE5D6722-826F-11D5-A24E-0060B0F1A5AE} (Tukati Launcher) - http://3dgamers.tukati.com/tukati/1.7.20.20/tukati.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{10254713-0DEA-467E-AA6B-EA88F79978DF}: NameServer = 199.185.220.36,199.185.220.52
O17 - HKLM\System\CS1\Services\Tcpip\..\{10254713-0DEA-467E-AA6B-EA88F79978DF}: NameServer = 199.185.220.36,199.185.220.52
O17 - HKLM\System\CS2\Services\Tcpip\..\{10254713-0DEA-467E-AA6B-EA88F79978DF}: NameServer = 199.185.220.36,199.185.220.52
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\Net MD Simple Burner\NetMDSB.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\System32\r_server.exe" /service (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Any help would be greatly appreciated!
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 865 • Replies: 13
No top replies

 
awyt
 
  1  
Reply Thu 11 Aug, 2005 09:26 pm
bump
0 Replies
 
Don77
 
  1  
Reply Thu 11 Aug, 2005 10:12 pm
Hi there awyt ,
Were you running it in safe mode ?
0 Replies
 
timberlandko
 
  1  
Reply Thu 11 Aug, 2005 10:15 pm
Patience partner - your turn will come. In the meanwhile, download Kazaabegone[/i][/u]. Unzip it, but don't run it yet.
Then download a new copy of Ewido, then uninstall your existing Ewido via Add/Remove Programs. While you're at it, uninstall MessengerPlus, Kazaa, and anything related to Kazaa, also. Next, consult your Norton documentation for instructions, and disable all your Norton components except Norton Antivirus - make sure you set their options so they do not load at boot.

Now, reboot, open Norton Systemworks or Internert Security, whichever you have, and verify nothing but Norton Antivirus started at boot. If any Norton apps are running, disable them (this time including Norton Antivirus), then use Taskmanager (Ctrl+Alt+Delete) to verify nothing else is running, then locate and launch KaZaaBegone.exe. Click on "Search for installed componerts only" and click "GO". You should see a list Kazaa-related objects. Click "Search & destroy all installed components" and click "GO". The program should inform you that it uninstalled succesfully. Click "Ok", and close it.

Then reboot, make certain again nothing else - particularly Norton - is running, run CCleaner, select "Issues", select "Analyze", and when the scan has completed, select "Fix selected issues". Save the registry backup when prompted, and note where it saves to, or, better yet, use the dropdown in the "Save To" box to navigate to the Ewido folder (probably C:\Programs\Ewido), and create a new folder named "Backups" and save to that folder. Then select and confirm to fix all issues found. When that has completed, select "Cleaner", select "Analyze", and when the scan has completed, select "Run Cleaner". Reboot into normal mode.


Now, after verifying no Norton apps, not even Norton Antivirus (Nortion Firewall would be OK if you have it running - but NOTHING ELSE), are running, install and update Ewido, then boot into safe mode and try to run it again - remember, run it while in safe mode.

Remember also to re-enable Norton Antivirus before going out onto the web, but to keep all other Norton apps disabled.
0 Replies
 
awyt
 
  1  
Reply Fri 12 Aug, 2005 01:21 am
Thanks for the help guys!

Here's an updated HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 1:12:45 AM, on 12/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
C:\WINDOWS\system32\RunDll32.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\ahead\InCD\InCD.exe
C:\Program Files\DIGStream\digstream.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\ATI Multimedia\main\launchpd.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mim.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Sony\Net MD Simple Burner\NetMDSB.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_3c00.dll"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [Launcher] C:\Program Files\Canon\PhotoStitch\Launcher.exe /P
O4 - HKLM\..\Run: [Kazaa Download Accelerator Updater] regsvr32 /s C:\WINDOWS\System32\kdpupd.dll
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_0dfd.dll"
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/06fe0e3c457a449ebd03/netzip/RdxIE601.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildtangent.com/bgn/partners/ea/needforspeed/install.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.com/games/popcaploader_v5.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O16 - DPF: {FE5D6722-826F-11D5-A24E-0060B0F1A5AE} (Tukati Launcher) - http://3dgamers.tukati.com/tukati/1.7.20.20/tukati.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{10254713-0DEA-467E-AA6B-EA88F79978DF}: NameServer = 199.185.220.36,199.185.220.52
O17 - HKLM\System\CS1\Services\Tcpip\..\{10254713-0DEA-467E-AA6B-EA88F79978DF}: NameServer = 199.185.220.36,199.185.220.52
O17 - HKLM\System\CS2\Services\Tcpip\..\{10254713-0DEA-467E-AA6B-EA88F79978DF}: NameServer = 199.185.220.36,199.185.220.52
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\Net MD Simple Burner\NetMDSB.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\System32\r_server.exe" /service (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Thanks again.
0 Replies
 
timberlandko
 
  1  
Reply Fri 12 Aug, 2005 10:35 am
Were you able to correct the problem with Ewido? Also, I notice some Norton apps appear still to be running - lets try to work on these things first, or we're not gionna get very far. Seeing a set of Ewido logs will be very helpful.
0 Replies
 
awyt
 
  1  
Reply Fri 12 Aug, 2005 05:09 pm
0 Replies
 
awyt
 
  1  
Reply Fri 12 Aug, 2005 07:53 pm
I ran Ewido, and it worked fine. The log from the initial Ewido scan was too large to post (it was full of cookies). I ran the scan again and here is the log:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 7:49:37 PM, 12/08/2005
+ Report-Checksum: 5928AA41

+ Scan result:

No infected objects found.


::Report End
0 Replies
 
timberlandko
 
  1  
Reply Fri 12 Aug, 2005 11:03 pm
Woulda been nice to have seen that 1st Ewido log - they're always long the first time around, and they let us have real good idea of what all is going on. The cookies and listed files and actions taken etc. tell us a lot of what we need to know; that's why we want to see them. Oh, well.

First, look in Add/Remove Programs for SpyFighter - if found, remove it.

Download SilentRunners. Don't do anything with it yet, just download it. We'll use it later to see if it can give us some of the info we needed.

Now, update Ad-Aware SE, EWIDO, and Microsoft Antispyware. Don't scan with them yet, just update them then close them.

Now, lets start with trying to clean some stuff with HiJackThis. Boot into safe mode, and, with no other apps running or windows/browsers open, launch HJT. Place a checkmark next to each of these entries, if found:

O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - (no file)
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_3c00.dll"
O4 - HKLM\..\Run: [Kazaa Download Accelerator Updater] regsvr32 /s C:\WINDOWS\System32\kdpupd.dll
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_0dfd.dll"
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildtangent.com/bgn/partners/ea/needforspeed/install.cab
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\System32\r_server.exe" /service (file missing)


Click "Fix Checked". Do not reboot.

Now, using Windows Explorer, look in your Programs folder for the SpyFighter folder. If found, delete the entire folder.

Locate Microsoft Antispyware, and run a full system scan. Allow MS Antispyware to fix anything it finds.

Locate Ad-Aware SE and run a full system scan. Allow Ad-Aware SE to fix anything it finds.

Locate and launch CCleaner. Select "Issues", then select "Scan for Issues", and wait a few minutes while the scan completes. When it has completed, select "Fix Selected Issues". Save the registry backup when prompted to do so - the default location will be to your "My Documents" folder, I think it better to create a folder named Backups in the CCleaner folder and save them there, but thats your call. When prompted, choose and confirm to fix all issues. Do not reboot.

Locate EWIDO and run a full scan-and-fix, and saye the log.

Still in CCleaner, select "Cleaner", then select "Analyze", and when the scan has completed select "Run Cleanup" and confirm. Reboot normally, but do not connect to the internet. Disable or deactivate any security/privacy software you may have - antivirus, antispyware, popup blockers, or the like.

Locate and install "SilentRunners", then run a scan and save the log.

Launch Ewido and run another full scan, and save the log.

Close all running apps, and with no other browsers or windows open, run HiJckThis, just saving the log.

Now, reactivate your privacy/security software, connect to the internet, navigate back to this thread, and post the requested logs.
0 Replies
 
awyt
 
  1  
Reply Mon 15 Aug, 2005 06:44 pm
Sorry about the late reply, I was busy all weekend. Here are the requested logs.

HJT:
Logfile of HijackThis v1.99.1
Scan saved at 6:36:23 PM, on 15/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/06fe0e3c457a449ebd03/netzip/RdxIE601.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://antu.popcap.com/games/popcaploader_v5.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O16 - DPF: {FE5D6722-826F-11D5-A24E-0060B0F1A5AE} (Tukati Launcher) - http://3dgamers.tukati.com/tukati/1.7.20.20/tukati.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{10254713-0DEA-467E-AA6B-EA88F79978DF}: NameServer = 199.185.220.36,199.185.220.52
O17 - HKLM\System\CS1\Services\Tcpip\..\{10254713-0DEA-467E-AA6B-EA88F79978DF}: NameServer = 199.185.220.36,199.185.220.52
O17 - HKLM\System\CS2\Services\Tcpip\..\{10254713-0DEA-467E-AA6B-EA88F79978DF}: NameServer = 199.185.220.36,199.185.220.52
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\Net MD Simple Burner\NetMDSB.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\System32\r_server.exe" /service (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

First Ewido Log:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 4:12:04 PM, 15/08/2005
+ Report-Checksum: D3304111

+ Scan result:

:mozilla.9:C:\Documents and Settings\The Wytsmas\Application Data\Mozilla\Firefox\Profiles\w0h97mrv.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.10:C:\Documents and Settings\The Wytsmas\Application Data\Mozilla\Firefox\Profiles\w0h97mrv.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.23:C:\Documents and Settings\The Wytsmas\Application Data\Mozilla\Firefox\Profiles\w0h97mrv.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.24:C:\Documents and Settings\The Wytsmas\Application Data\Mozilla\Firefox\Profiles\w0h97mrv.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.25:C:\Documents and Settings\The Wytsmas\Application Data\Mozilla\Firefox\Profiles\w0h97mrv.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.26:C:\Documents and Settings\The Wytsmas\Application Data\Mozilla\Firefox\Profiles\w0h97mrv.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.27:C:\Documents and Settings\The Wytsmas\Application Data\Mozilla\Firefox\Profiles\w0h97mrv.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00000701.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00000701.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00000701.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00000701.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00000701.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00000701.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.105:C:\RECYCLER\NPROTECT\00000701.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.106:C:\RECYCLER\NPROTECT\00000701.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00000702.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00000702.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00000702.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00000702.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00000702.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.39:C:\RECYCLER\NPROTECT\00000702.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.106:C:\RECYCLER\NPROTECT\00000702.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.107:C:\RECYCLER\NPROTECT\00000702.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00000703.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00000703.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
-> : Error during cleaning
:mozilla.24:C:\RECYCLER\NPROTECT\00000703.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00000703.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.39:C:\RECYCLER\NPROTECT\00000703.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.106:C:\RECYCLER\NPROTECT\00000703.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.107:C:\RECYCLER\NPROTECT\00000703.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00000704.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00000704.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00000704.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00000704.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00000704.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00000704.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.105:C:\RECYCLER\NPROTECT\00000704.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.106:C:\RECYCLER\NPROTECT\00000704.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00000705.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00000705.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
-> : Error during cleaning
:mozilla.24:C:\RECYCLER\NPROTECT\00000705.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00000705.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00000705.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.105:C:\RECYCLER\NPROTECT\00000705.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.106:C:\RECYCLER\NPROTECT\00000705.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00000706.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00000706.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00000706.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00000706.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00000706.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.39:C:\RECYCLER\NPROTECT\00000706.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.106:C:\RECYCLER\NPROTECT\00000706.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.107:C:\RECYCLER\NPROTECT\00000706.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00000707.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00000707.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00000707.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00000707.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00000707.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.39:C:\RECYCLER\NPROTECT\00000707.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.106:C:\RECYCLER\NPROTECT\00000707.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.107:C:\RECYCLER\NPROTECT\00000707.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00000708.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00000708.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00000708.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00000708.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00000708.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.39:C:\RECYCLER\NPROTECT\00000708.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.106:C:\RECYCLER\NPROTECT\00000708.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.107:C:\RECYCLER\NPROTECT\00000708.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00000709.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00000709.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.29:C:\RECYCLER\NPROTECT\00000709.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00000709.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.41:C:\RECYCLER\NPROTECT\00000709.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.42:C:\RECYCLER\NPROTECT\00000709.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.109:C:\RECYCLER\NPROTECT\00000709.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.110:C:\RECYCLER\NPROTECT\00000709.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00000710.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00000710.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00000710.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.29:C:\RECYCLER\NPROTECT\00000710.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.40:C:\RECYCLER\NPROTECT\00000710.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.41:C:\RECYCLER\NPROTECT\00000710.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.108:C:\RECYCLER\NPROTECT\00000710.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.109:C:\RECYCLER\NPROTECT\00000710.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00000711.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00000711.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00000711.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.29:C:\RECYCLER\NPROTECT\00000711.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.40:C:\RECYCLER\NPROTECT\00000711.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.41:C:\RECYCLER\NPROTECT\00000711.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.108:C:\RECYCLER\NPROTECT\00000711.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.109:C:\RECYCLER\NPROTECT\00000711.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00000712.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00000712.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00000712.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.29:C:\RECYCLER\NPROTECT\00000712.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.40:C:\RECYCLER\NPROTECT\00000712.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.41:C:\RECYCLER\NPROTECT\00000712.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.108:C:\RECYCLER\NPROTECT\00000712.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.109:C:\RECYCLER\NPROTECT\00000712.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00000713.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00000713.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00000713.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.29:C:\RECYCLER\NPROTECT\00000713.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.40:C:\RECYCLER\NPROTECT\00000713.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.41:C:\RECYCLER\NPROTECT\00000713.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.108:C:\RECYCLER\NPROTECT\00000713.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.109:C:\RECYCLER\NPROTECT\00000713.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00000714.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00000714.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00000714.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.29:C:\RECYCLER\NPROTECT\00000714.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.40:C:\RECYCLER\NPROTECT\00000714.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.41:C:\RECYCLER\NPROTECT\00000714.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.108:C:\RECYCLER\NPROTECT\00000714.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.109:C:\RECYCLER\NPROTECT\00000714.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00000720.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00000720.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00000720.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.29:C:\RECYCLER\NPROTECT\00000720.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.40:C:\RECYCLER\NPROTECT\00000720.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.41:C:\RECYCLER\NPROTECT\00000720.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.108:C:\RECYCLER\NPROTECT\00000720.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.109:C:\RECYCLER\NPROTECT\00000720.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.32:C:\RECYCLER\NPROTECT\00000721.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.33:C:\RECYCLER\NPROTECT\00000721.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.34:C:\RECYCLER\NPROTECT\00000721.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00000721.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.46:C:\RECYCLER\NPROTECT\00000721.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.47:C:\RECYCLER\NPROTECT\00000721.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.108:C:\RECYCLER\NPROTECT\00000721.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.109:C:\RECYCLER\NPROTECT\00000721.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.32:C:\RECYCLER\NPROTECT\00000723.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.33:C:\RECYCLER\NPROTECT\00000723.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.34:C:\RECYCLER\NPROTECT\00000723.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00000723.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.46:C:\RECYCLER\NPROTECT\00000723.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.47:C:\RECYCLER\NPROTECT\00000723.MOZ -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.108:C:\RECYCLER\NPROTECT\00000723.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.109:C:\RECYCLER\NPROTECT\00000723.MOZ -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00001378.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00001378.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00001379.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00001379.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001380.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001380.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00001381.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00001381.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00001381.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00001381.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00001382.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00001382.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00001382.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001382.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00001383.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00001383.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00001383.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001383.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00001384.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00001384.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00001384.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001384.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001384.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00001386.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00001386.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00001386.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001386.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001386.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00001387.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00001387.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00001387.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001387.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001387.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001388.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001388.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001388.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001388.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00001388.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001389.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001389.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001389.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00001389.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001389.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001390.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00001390.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00001390.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00001390.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00001390.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001393.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00001393.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00001393.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00001393.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00001393.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00001395.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00001395.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00001395.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00001395.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00001395.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00001396.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00001396.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00001396.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00001396.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00001396.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00001397.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00001397.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00001397.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00001397.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.29:C:\RECYCLER\NPROTECT\00001397.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00001398.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00001398.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00001398.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00001398.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.29:C:\RECYCLER\NPROTECT\00001398.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00001399.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00001399.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00001399.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00001399.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.29:C:\RECYCLER\NPROTECT\00001399.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00001400.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00001400.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00001400.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00001400.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00001400.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001400.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00001400.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00001401.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00001401.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00001401.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00001401.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001401.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001401.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00001401.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00001402.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00001402.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00001402.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00001402.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001402.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001402.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00001402.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00001403.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00001403.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00001403.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00001403.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001403.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001403.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00001403.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00001404.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001404.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001404.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001404.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001404.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001404.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.33:C:\RECYCLER\NPROTECT\00001404.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00001406.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001406.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001406.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001406.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001406.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001406.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.33:C:\RECYCLER\NPROTECT\00001406.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001409.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001409.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001409.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001409.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001409.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001409.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.34:C:\RECYCLER\NPROTECT\00001409.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001410.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001410.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001410.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00001410.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001410.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001410.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.39:C:\RECYCLER\NPROTECT\00001410.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00001411.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00001411.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00001411.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00001411.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00001411.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00001411.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.39:C:\RECYCLER\NPROTECT\00001411.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00001413.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00001413.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00001413.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00001413.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.29:C:\RECYCLER\NPROTECT\00001413.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00001413.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.41:C:\RECYCLER\NPROTECT\00001413.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.33:C:\RECYCLER\NPROTECT\00001414.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.34:C:\RECYCLER\NPROTECT\00001414.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00001414.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00001414.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00001414.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00001414.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.43:C:\RECYCLER\NPROTECT\00001414.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.40:C:\RECYCLER\NPROTECT\00001415.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.41:C:\RECYCLER\NPROTECT\00001415.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.42:C:\RECYCLER\NPROTECT\00001415.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.43:C:\RECYCLER\NPROTECT\00001415.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.44:C:\RECYCLER\NPROTECT\00001415.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.45:C:\RECYCLER\NPROTECT\00001415.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.50:C:\RECYCLER\NPROTECT\00001415.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00001416.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00001416.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00001416.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00001416.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00001416.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001416.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001416.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001416.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.56:C:\RECYCLER\NPROTECT\00001416.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00001417.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00001417.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00001417.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00001417.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001417.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001417.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001417.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001417.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.57:C:\RECYCLER\NPROTECT\00001417.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00001418.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00001418.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00001418.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001418.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001418.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001418.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001418.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001418.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.57:C:\RECYCLER\NPROTECT\00001418.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001419.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001419.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001419.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001419.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001419.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001419.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00001419.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00001419.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.57:C:\RECYCLER\NPROTECT\00001419.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00001420.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00001420.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00001420.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00001420.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001420.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001420.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001420.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001420.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001420.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001420.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.60:C:\RECYCLER\NPROTECT\00001420.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001421.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001421.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001421.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001421.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00001421.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001421.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00001421.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00001421.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00001421.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00001421.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.62:C:\RECYCLER\NPROTECT\00001421.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001422.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001422.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001422.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00001422.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001422.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001422.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00001422.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00001422.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00001422.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00001422.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.62:C:\RECYCLER\NPROTECT\00001422.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00001423.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00001423.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00001423.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00001423.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001423.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001423.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001423.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001423.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001423.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001423.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.64:C:\RECYCLER\NPROTECT\00001423.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001424.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001424.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001424.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001424.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001424.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001424.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001424.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00001424.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00001424.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00001424.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.64:C:\RECYCLER\NPROTECT\00001424.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00001425.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00001425.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00001425.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00001425.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00001425.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001425.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001425.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001425.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001425.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001425.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001425.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001425.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.66:C:\RECYCLER\NPROTECT\00001425.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001426.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001426.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001426.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001426.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001426.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001426.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00001426.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001426.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001426.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00001426.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00001426.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00001426.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.66:C:\RECYCLER\NPROTECT\00001426.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001427.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001427.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001427.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001427.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001427.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001427.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00001427.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001427.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001427.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00001427.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00001427.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00001427.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.66:C:\RECYCLER\NPROTECT\00001427.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001428.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001428.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001428.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001428.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001428.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001428.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001428.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001428.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00001428.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001428.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001428.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00001428.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.71:C:\RECYCLER\NPROTECT\00001428.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001429.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001429.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001429.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001429.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001429.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001429.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001429.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001429.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00001429.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001429.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001429.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00001429.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.71:C:\RECYCLER\NPROTECT\00001429.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001430.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001430.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001430.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001430.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001430.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001430.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001430.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001430.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00001430.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001430.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001430.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00001430.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.71:C:\RECYCLER\NPROTECT\00001430.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001431.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001431.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001431.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001431.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001431.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001431.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001431.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001431.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00001431.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001431.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001431.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00001431.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.71:C:\RECYCLER\NPROTECT\00001431.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001432.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001432.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001432.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001432.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001432.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001432.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001432.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001432.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00001432.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001432.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001432.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00001432.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.71:C:\RECYCLER\NPROTECT\00001432.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00001433.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001433.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001433.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001433.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001433.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001433.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001433.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001433.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00001433.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001433.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001433.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00001433.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.71:C:\RECYCLER\NPROTECT\00001433.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00001435.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001435.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001435.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001435.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001435.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001435.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001435.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00001435.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001435.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001435.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00001435.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00001435.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.72:C:\RECYCLER\NPROTECT\00001435.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00001436.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001436.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001436.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001436.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001436.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001436.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00001436.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001436.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001436.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00001436.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00001436.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00001436.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.73:C:\RECYCLER\NPROTECT\00001436.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001437.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001437.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001437.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001437.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001437.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00001437.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001437.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001437.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00001437.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00001437.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00001437.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00001437.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.74:C:\RECYCLER\NPROTECT\00001437.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001438.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001438.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001438.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001438.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001438.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00001438.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001438.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001438.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00001438.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00001438.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00001438.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00001438.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.74:C:\RECYCLER\NPROTECT\00001438.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00001439.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00001439.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00001439.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00001439.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00001439.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00001439.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00001439.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00001439.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00001439.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:
0 Replies
 
awyt
 
  1  
Reply Mon 15 Aug, 2005 06:46 pm
Second Ewido Log:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 6:34:52 PM, 15/08/2005
+ Report-Checksum: 830432AD

+ Scan result:

:mozilla.21:C:\RECYCLER\NPROTECT\00000703.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00000705.MOZ -> Spyware.Cookie.adcounter : Cleaned with backup


::Report End

SilentRunners Log:

"Silent Runners.vbs", revision 39, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
"msnmsgr" = ""C:\Program Files\MSN Messenger\msnmsgr.exe" /background" [MS]
"ATI Launchpad" = ""C:\Program Files\ATI Multimedia\main\launchpd.exe"" ["ATI Technologies Inc."]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"PrinTray" = "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" ["Lexmark"]
"Lexmark X83 Button Monitor" = "C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe" ["Jetsoft Development Company"]
"Lexmark X83 Button Manager" = "C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe" ["Jetsoft Development Company"]
"Cmaudio" = "RunDll32 cmicnfg.cpl,CMICtrlWnd" [MS]
"ccApp" = ""C:\Program Files\Common Files\Symantec Shared\ccApp.exe"" ["Symantec Corporation"]
"ccRegVfy" = ""C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"" ["Symantec Corporation"]
"Symantec NetDriver Monitor" = "C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer" ["Symantec Corporation"]
"SunJavaUpdateSched" = "C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe" ["Sun Microsystems, Inc."]
"DAEMON Tools-1033" = ""C:\Program Files\D-Tools\daemon.exe" -lang 1033" ["DAEMON'S HOME"]
"UserFaultCheck" = "C:\WINDOWS\system32\dumprep 0 -u" [MS]
"gcasServ" = ""C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"" [MS]
"TkBellExe" = ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot" ["RealNetworks, Inc."]
"MSConfig" = "C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Real\RealOne Player\rpshellext.dll" ["RealNetworks"]
"{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
"{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
INFECTION WARNING! "{9EF34FF2-3396-4527-9D27-04C8C1C67806}" = "Microsoft AntiSpyware Service Hook"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft AntiSpyware\shellextension.dll" [MS]
INFECTION WARNING! "{54D9498B-CF93-414F-8984-8CE7FDE0D391}" = "ewido shell guard"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\shellhook.dll" ["TODO: <Firmenname>"]

HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\
"load" = (value not set)
"run" = (value not set)

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\
"AppInit_DLLs" = (value not set)

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
INFECTION WARNING! AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\context.dll" ["ewido networks"]
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\context.dll" ["ewido networks"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]


Active Desktop and Wallpaper:
-----------------------------

Active Desktop is disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\The Wytsmas\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"


Enabled Screen Saver:
---------------------

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\System32\ssflwbox.scr" [MS]


Enabled Scheduled Tasks:
------------------------

"Norton AntiVirus - Scan my computer" -> launches: "C:\PROGRA~1\NORTON~1\NORTON~1\NAVW32.exe /task:C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\NORTON~1\Tasks\mycomp.sca" ["Symantec Corporation"]
"Norton SystemWorks One Button Checkup" -> launches: "C:\Program Files\Norton SystemWorks\OBC.exe /CUSTOM /SCHEDULE" ["Symantec Corporation"]
"Symantec NetDetect" -> launches: "C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE" ["Symantec Corporation"]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000004\LibraryPath = "%SystemRoot%\System32\nwprovau.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 28
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" = "Norton AntiVirus" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" = "Norton AntiVirus"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll" ["Sun Microsystems, Inc."]

{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]


All Non-Disabled Services (Display Name, Service Name, Path {Service DLL}):
---------------------------------------------------------------------------

Adobe LM Service, Adobe LM Service, ""C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"" [null data]
Application Management, AppMgmt, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\appmgmts.dll" [file not found]}
ASP.NET State Service, aspnet_state, "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe" [MS]
Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\system32\Ati2evxx.exe" ["ATI Technologies Inc."]
ATI Smart, ATI Smart, "C:\WINDOWS\system32\ati2sgag.exe" [empty string]
HTTP SSL, HTTPFilter, "C:\WINDOWS\System32\svchost.exe -k HTTPFilter" {"C:\WINDOWS\System32\w3ssl.dll" [MS]}
Logical Disk Manager Administrative Service, dmadmin, "C:\WINDOWS\System32\dmadmin.exe /com" ["Microsoft Corp., Veritas Software"]
MD Simple Burner Service, NetMDSB, "C:\Program Files\Sony\Net MD Simple Burner\NetMDSB.exe" ["Sony Corporation"]
Network Provisioning Service, xmlprov, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\xmlprov.dll" [MS]}
Norton AntiVirus Auto Protect Service, navapsvc, ""C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe"" ["Symantec Corporation"]
Norton Unerase Protection, NProtectService, ""C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE"" ["Symantec Corporation"]
PACSPTISVR, PACSPTISVR, "C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe" ["Sony Corporation"]
Portable Media Serial Number Service, WmdmPmSN, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\system32\MsPMSNSv.dll" [MS]}
Remote Administrator Service, r_server, ""C:\WINDOWS\System32\r_server.exe" /service" [file not found]
ScriptBlocking Service, SBService, "C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe" ["Symantec Corporation"]
Sony SPTI Service, SPTISRV, "C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe" ["Sony Corporation"]
Speed Disk service, Speed Disk service, "C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe" ["Symantec Corporation"]
Symantec Event Manager, ccEvtMgr, ""C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"" ["Symantec Corporation"]
Symantec Network Drivers Service, SNDSrvc, ""C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"" ["Symantec Corporation"]
Symantec Password Validation Service, ccPwdSvc, ""C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"" ["Symantec Corporation"]
SymWMI Service, SymWSC, ""C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe"" ["Symantec Corporation"]
Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]
WMI Performance Adapter, WmiApSrv, "C:\WINDOWS\System32\wbem\wmiapsrv.exe" [MS]


Keyboard Driver Filters:
------------------------

HKLM\System\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\
"UpperFilters" = INFECTION WARNING! "Lkbdflt2" ["Logitech"]


----------
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 102 seconds.
+ The search for all Registry CLSIDs containing dormant Explorer Bars
took 26 seconds.
---------- (total run time: 168 seconds)


PS: I couldn't find SpyFighter anywhere on my system.
0 Replies
 
timberlandko
 
  1  
Reply Wed 17 Aug, 2005 12:55 am
That's looking pretty good now; just a couple minor issues to deal with, and I think you'll be good to go. Don't worry about not finding Spyfighter - its a good sign it doesn't seem to be there.

Boot into safe mode, and with no windows, browsers, or other apps open or running, launch HJT, place a checkmark next to the following:

O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - (no file)
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\System32\r_server.exe" /service (file missing)


then click "Fix Checked". Do not reboot.

Locate and launch CCleaner, select "Issues", and in the left panel, uncheck "Unused File Extensions", then click "Scan for issues". When the scan has completed, click "Fix All Selected issues", and when prompted, save the registry backup it will offer to perform, then in the "Issues" popup that opens, select and confirm that you wish to "Fix all issues". When that has been done, select "Cleaner" and run a full system scan-and-clean. Reboot normally, immediately run a scan-and-save-log with HJT (fxing nothing), connect to the internet, and post the HJT log for confirmation that all the nasties are gone.
0 Replies
 
awyt
 
  1  
Reply Sat 20 Aug, 2005 02:19 am
Here's the requested HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 2:17:04 AM, on 20/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\ATI Multimedia\main\launchpd.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Sony\Net MD Simple Burner\NetMDSB.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/06fe0e3c457a449ebd03/netzip/RdxIE601.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://antu.popcap.com/games/popcaploader_v5.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O16 - DPF: {FE5D6722-826F-11D5-A24E-0060B0F1A5AE} (Tukati Launcher) - http://3dgamers.tukati.com/tukati/1.7.20.20/tukati.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{10254713-0DEA-467E-AA6B-EA88F79978DF}: NameServer = 199.185.220.36,199.185.220.52
O17 - HKLM\System\CS1\Services\Tcpip\..\{10254713-0DEA-467E-AA6B-EA88F79978DF}: NameServer = 199.185.220.36,199.185.220.52
O17 - HKLM\System\CS2\Services\Tcpip\..\{10254713-0DEA-467E-AA6B-EA88F79978DF}: NameServer = 199.185.220.36,199.185.220.52
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\Net MD Simple Burner\NetMDSB.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\System32\r_server.exe" /service (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


Thanks again for your help!
0 Replies
 
timberlandko
 
  1  
Reply Sat 20 Aug, 2005 02:41 am
that's a clean log. You ought to have HJT fix this entry:

O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\System32\r_server.exe" /service (file missing)

its not malicious, its just a reference to a non-existant item, and should be cleaned up. One other do-or-don't/"your call" suggestion: use Microsoft Antispyware to set your home and search pages to Microsoft defaults. You can always cutomize them to your own preferences later, but setting the MS defaults gives you a known-good starting point. If you want to do that, locate and launch Microsoft Antispyare, select "Advanced Tools", select "Browser Rstore", select "Check All", then click "Restore", and reboot when the process completes - which will be just a few moments.

Other than that, I'd say you're looking fine. Test things for a while - and of course stay absolutely current on all of your updates and make sure your security/privacy software is active and functioning properly. If after a brief period of normal use things seem to stay normal and you're satisfied all is as it should be, you can delete the tools you won't be using any more (they won't hurt anything, but they do take up some disk space) - though I strongly recommend keeping, using, and maintaining updates for Ad-Aware SE, CCleaner, and/or Cleanup, Microsoft Antispyware, Spybot S&D and SpywareBlaster.

When you're ready, run Cleanup one more time while in safe mode, then defrag your machine, re-enable System Restore, boot back into safe mode, and when the system has fully booted, set a fresh restore point. Reboot normally, Stay Safe Out There, and you're good to go.

I think we can mark this one resolved, but if you find otherwise, jump right back here with the details - shouldn't be any problems, though.
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » [Resloved] Ewido Problem with Yuckware Removal
Copyright © 2025 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.03 seconds on 12/28/2025 at 02:05:34