Author Topic: Aurora and who knows what else..:'(  (Read 1085 times)

Offline Tan18_01

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Aurora and who knows what else..:'(
« on: July 04, 2005, 07:47:16 AM »
1st of id like to say hi everyone as i am new to this website. Well ive got a problem with my pc starting up and it says cannot find nail.exe but i also have aurora pop-ups again. any help would be appreciated. thank you.

Logfile of HijackThis v1.99.1
Scan saved at 10:45:11 PM, on 7/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\HHVcdV7Sys\VC7Play.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\WINDOWS\system32\LXSUPMON.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\ctfmon.exe
c:\windows\system32\fjsgvga.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HHVcdV7Sys\VC7SecS.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\BitTornado\btdownloadgui.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://torax.outwar.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimtoday.com/search/aimtoolbar.jsp
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [VC7Player] C:\Program Files\HHVcdV7Sys\VC7Play.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [toooem] c:\windows\system32\fjsgvga.exe r
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Link Target in Firefox - file://C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewlink.html
O8 - Extra context menu item: View This Page in Firefox - file://C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewpage.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{22529674-3B9C-4E76-A387-59CBE06EA9AB}: NameServer = 203.0.178.191
O17 - HKLM\System\CS1\Services\Tcpip\..\{22529674-3B9C-4E76-A387-59CBE06EA9AB}: NameServer = 203.0.178.191
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Virtual CD v7 Management Service (VC7SecS) - H+H Software GmbH - C:\Program Files\HHVcdV7Sys\VC7SecS.exe
« Last Edit: July 05, 2005, 01:11:42 AM by Tan18_01 »

Offline Tan18_01

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Aurora and who knows what else..:'(
« Reply #1 on: July 05, 2005, 01:11:22 AM »
*bump*

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Aurora and who knows what else..:'(
« Reply #2 on: July 05, 2005, 07:23:54 PM »
Hi Tan18_01

Can you download the following tools please

download Nailfix from here:
http://www.noidea.us/easyfile/file.php?dow...050515010747824
Unzip it to the desktop but please do NOT run it yet

==Download and Install this small program
to help clean your temp folders,cookies, etc...
Windows Cleanup
Give the link time to load or try it twice, it may be busy
We'll need this later

==Download and then Install
Ewido Security Suite
When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We'll fix that with this next step
From the main ewido screen, click on Update in the left menu, then click the Start update button.
After the update finishes (the status bar at the bottom will display "Update successful")
Close out Ewido for now, we'll need it later
In the Event that Ewido can't update please download the full database from this link
http://www.ewido.net/en/download/updates/

Please Print this out or save these instructions to a Notepad file and save it to your Desktop

Access your Add/Remove Programs and remove if found
Viewpoint there may be more than one entry, if you didn't intentionally install this please remove them
Then remove the following if found
180 Solutions or Search assistant
Please allow internet connection and follow the prompts closely to ensure your uninstalling the software

RESTART your Computer in SAFE MODE

Once in safe mode

==Double-click on nailfix.cmd that you unzipped earlier. Your desktop and icons will disappear and reappear, and a window should open and close very quickly --- this is normal

==Open Windows CleanUp!>>START>>programs>>Cleanup!
Click on the CleanUp button, let it finish scanning for files, when it's done
DECLINE to Log off when scan is done.

==Open Ewido Security Suite
Click on the Scanner button on the left menu
Click on the Settings button on the right
Select "Scan Every File"
OK it and then click on the "Complete System Scan"
Please refrain from opening any other Windows as Ewido is running
*If Ewido finds something it will prompt you with "Infected Object found"
Ensure the following are Selected
  1. Perform Action = Remove
  2. Create Encrypted Backup in Quarantine (Recommended)
  Then click OK

Normally, I would ask that you also select "Perform action with all infections"
But if Ewido identifies
AVG's avgemc.exe as a possible infection, can you please Ignore it
You may get a couple prompts about it

When Ewido has finished it's scan click the "Save Report" button
Save the report to desktop
Exit Ewido

Do another scan with Hijackthis and put a check next to these entries:

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll

O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe

O4 - HKLM\..\Run: [toooem] c:\windows\system32\fjsgvga.exe r

O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)


After you have ticked the above entries, close All other open windows,
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis

Restart back to Normal mode

Run another scan with Hijackthis and post a fresh log
Could you also post the log from Ewido's

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Tan18_01

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Aurora and who knows what else..:'(
« Reply #3 on: July 05, 2005, 10:43:31 PM »
The Ewido Site is currently down so i cant access it. Are there any alternatives???

Offline Tan18_01

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Aurora and who knows what else..:'(
« Reply #4 on: July 06, 2005, 10:37:45 AM »
I couldnt update ewido security suite. These were my results with an un-updated version:

---------------------------------------------------------
 ewido security suite - Scan report
---------------------------------------------------------

 + Created on:         1:20:58 AM, 7/7/2005
 + Report-Checksum:      799C43DE

 + Scan result:

   HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
   HKLM\SOFTWARE\sais -> Spyware.180Solutions : Cleaned with backup
   HKLM\SOFTWARE\SideFind -> Spyware.SideFind : Cleaned with backup
   HKLM\SOFTWARE\SideFind\History -> Spyware.SideFind : Cleaned with backup
   HKU\S-1-5-21-1644491937-861567501-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000010-6F7D-442C-93E3-4A4827C2E4C8} -> Spyware.InternetOptimizer : Cleaned with backup
   HKU\S-1-5-21-1644491937-861567501-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00320615-B6C2-40A6-8F99-F1C52D674FAD} -> Spyware.Transponder : Cleaned with backup
   HKU\S-1-5-21-1644491937-861567501-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10E42047-DEB9-4535-A118-B3F6EC39B807} -> Spyware.SideFind : Cleaned with backup
   HKU\S-1-5-21-1644491937-861567501-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9E98E84C-79E1-49C3-82EB-798FCD552EFB} -> Dialer.Generic : Cleaned with backup
   HKU\S-1-5-21-1644491937-861567501-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A3FDD654-A057-4971-9844-4ED8E67DBBB8} -> Spyware.ISTBar : Cleaned with backup
   HKU\S-1-5-21-1644491937-861567501-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AD0B8220-7DA4-4C0A-8532-B25A9F631D3D} -> Dialer.Generic : Cleaned with backup
   HKU\S-1-5-21-1644491937-861567501-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F4E04583-354E-4076-BE7D-ED6A80FD66DA} -> Spyware.BargainBuddy : Cleaned with backup
   HKU\S-1-5-21-1644491937-861567501-725345543-1003\Software\sais -> Spyware.180Solutions : Cleaned with backup
   C:\WINDOWS\system32\exul.exe -> Spyware.BargainBuddy : Cleaned with backup
   C:\WINDOWS\preInsln.exe -> Spyware.BiSpy : Cleaned with backup
   C:\WINDOWS\mbkjwr.exe -> Adware.BetterInternet : Cleaned with backup
   C:\WINDOWS\yalljrwrijs.exe -> Adware.BetterInternet : Cleaned with backup
   C:\Documents and Settings\t@N\Local Settings\Application Data\Wildtangent\Cdacache\00\00\0F.dat/files\wtvh.dll -> Spyware.WildTangent : Cleaned with backup
   C:\Documents and Settings\t@N\Desktop\DVDs\Kim's DVD's\Setup Software\MsgPlus-252.exe/70000011.exe -> TrojanDownloader.Swizzor.af : Cleaned with backup
   C:\Documents and Settings\t@N\Desktop\CD Image Games\SpellforceTheOrderofDawnv1.11NoCDFixedexeEng.rar/wsock32.dll -> Trojan.Patcher.a : Cleaned with backup
   C:\Documents and Settings\t@N\Desktop\CD Image Games\SpellforceTheOrderOfDawnv1.11NoCDFixedexeEng-2\wsock32.dll -> Trojan.Patcher.a : Cleaned with backup
   C:\Documents and Settings\t@N\Desktop\CD Image Games\SpellforceTheOrderofDawnv1.11NoCDFixedexeEng\wsock32.dll -> Trojan.Patcher.a : Cleaned with backup
   C:\Documents and Settings\t@N\Desktop\CD Image Games\SF_PACK_1.11.rar/SF_PACK_1.11\wsock32.dll -> Trojan.Patcher.a : Cleaned with backup
   C:\Documents and Settings\t@N\Desktop\CD Image Games\SF_PACK_1.11\SF_PACK_1.11\wsock32.dll -> Trojan.Patcher.a : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-10.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-10.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-1.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-1.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-1.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-2.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-2.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-3.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-3.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-4.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-4.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-5.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-5.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-6.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-6.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-7.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-7.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-8.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-8.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-9.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-9.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-11.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-11.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-143.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-143.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-12.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-12.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-13.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-13.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-14.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-14.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-15.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-15.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-16.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-16.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-17.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-17.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-18.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.9:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-18.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-19.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-19.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-20.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-20.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-21.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-21.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-22.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-22.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-23.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-23.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-24.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-24.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-25.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.12:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-25.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-26.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-26.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-27.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-27.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-28.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-28.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-29.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-29.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-30.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-30.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-31.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-31.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-32.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.12:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-32.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-33.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-33.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-34.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-34.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-35.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-35.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-36.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-36.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-37.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-37.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-38.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-38.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-39.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-39.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-40.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-40.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-41.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-41.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-42.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-42.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-43.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-43.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-44.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-44.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-45.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-45.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-46.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-46.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-47.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-47.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-48.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-48.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-49.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-49.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-50.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-50.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-51.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-51.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-52.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-52.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-53.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-53.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-54.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-54.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-55.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-55.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-56.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-56.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-57.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-57.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-58.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-58.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-59.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-59.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-60.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-60.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-61.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-61.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-62.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-62.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-63.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-63.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-64.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-64.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-65.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-65.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-66.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-66.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-67.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-67.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-68.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-68.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-69.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-69.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-70.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-70.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-71.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-71.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-72.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-72.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-73.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-73.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-74.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-74.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-75.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-75.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-76.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-76.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-77.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-77.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-78.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-78.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-79.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-79.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-80.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-80.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-81.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-81.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-82.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-82.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-83.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-83.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-84.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-84.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-85.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-85.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-86.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-86.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-87.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-87.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-88.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-88.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-89.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-89.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-90.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-90.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-91.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-91.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-92.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-92.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-93.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-93.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-94.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-94.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-95.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-95.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-96.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-96.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-97.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-97.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-98.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-98.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-99.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-99.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-100.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-100.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-101.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-101.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-102.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-102.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-103.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-103.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-104.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-104.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-105.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-105.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-106.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-106.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-107.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-107.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-108.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-108.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-109.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-109.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-110.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-110.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-111.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-111.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-112.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-112.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-113.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-113.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-114.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-114.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-115.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-115.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-116.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-116.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-117.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-117.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-118.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-118.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-119.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.12:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-119.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-120.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.12:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-120.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-121.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-121.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-122.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-122.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-123.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.12:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-123.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-124.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-124.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-125.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.12:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-125.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-126.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-126.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-127.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-127.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-128.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.12:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-128.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-129.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-129.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.6:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-130.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-130.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-131.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-131.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-132.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.12:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-132.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-133.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.12:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-133.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-134.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.12:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-134.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-135.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.12:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-135.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-136.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-136.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-137.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-137.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-138.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.12:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-138.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-139.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-139.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-140.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-140.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-141.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-141.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-142.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\cookies-142.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   C:\Program Files\JoWooD\SpellForce\wsock32.dll -> Trojan.Patcher.a : Cleaned with backup
   C:\System Volume Information\_restore{AF4D12DC-60AE-4FC1-93D1-D5CB239C7AC7}\RP3\A0000262.exe -> Adware.BetterInternet : Cleaned with backup
   C:\System Volume Information\_restore{AF4D12DC-60AE-4FC1-93D1-D5CB239C7AC7}\RP4\A0000286.exe -> Adware.BetterInternet : Cleaned with backup
   C:\System Volume Information\_restore{AF4D12DC-60AE-4FC1-93D1-D5CB239C7AC7}\RP5\A0000655.exe -> Adware.BetterInternet : Cleaned with backup
   C:\System Volume Information\_restore{AF4D12DC-60AE-4FC1-93D1-D5CB239C7AC7}\RP5\A0000656.exe -> Adware.BetterInternet : Cleaned with backup
   C:\System Volume Information\_restore{AF4D12DC-60AE-4FC1-93D1-D5CB239C7AC7}\RP5\A0000657.dll -> Adware.BetterInternet : Cleaned with backup
   C:\My Folder\On DVD\Downloads\proxy.zip/proxy/proxyclicker.exe -> Spyware.Hijacker.Generic : Cleaned with backup
   C:\My Folder\On DVD\Downloads\

Offline Tan18_01

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Aurora and who knows what else..:'(
« Reply #5 on: July 06, 2005, 10:40:17 AM »
cont.


   C:\My Folder\On DVD\Downloads\proxy\proxyclicker.exe -> Spyware.Hijacker.Generic : Cleaned with backup
   C:\My Folder\On DVD\Misc Data\Backed Up Files\Funny [censored]\FUNNY_PROGRAMS\SLIPPERY.EXE -> Not-A-Virus.Joke.CrazyMouse : Cleaned with backup
   C:\My Folder\On DVD\Misc Data\Backed Up Files\Funny [censored]\FUNNY_PROGRAMS\STRIPTEASE.EXE -> Not-A-Virus.Joke.Stript : Cleaned with backup
   C:\My Folder\On DVD\Misc Data\Backed Up Files\Exe Files\WinMP3Locator.exe/tsad.dll -> Spyware.TimeSink : Cleaned with backup
   C:\My Folder\On DVD\Misc Data\Backed Up Files\Exe Files\WinMP3Locator.exe/TSAdBot.exe -> Spyware.TimeSink : Cleaned with backup


::Report End

The HJT log was missing a couple of the entries you told me to remove

O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll

O4 - HKLM\..\Run: [toooem] c:\windows\system32\fjsgvga.exe r
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML

I think... i cant remember

Here is the HJT log after fixing what i could.
Logfile of HijackThis v1.99.1
Scan saved at 1:31:00 AM, on 7/7/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\HHVcdV7Sys\VC7Play.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\WINDOWS\system32\LXSUPMON.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Virtual CD v7\System\VC7Tray.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HHVcdV7Sys\VC7SecS.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://torax.outwar.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimtoday.com/search/aimtoolbar.jsp
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O4 - HKLM\..\Run: [VC7Player] C:\Program Files\HHVcdV7Sys\VC7Play.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Link Target in Firefox - file://C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewlink.html
O8 - Extra context menu item: View This Page in Firefox - file://C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewpage.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Virtual CD v7 Management Service (VC7SecS) - H+H Software GmbH - C:\Program Files\HHVcdV7Sys\VC7SecS.exe

My taskbar has changed from the starndard xp blue display to the old classic grey display. Is this normal? If not how do i change it?

I'm not getting the "missing nail.exe" anymore tho.
Thanks

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Aurora and who knows what else..:'(
« Reply #6 on: July 06, 2005, 09:11:27 PM »
Ewido scan looks right up to date
It's the newest version of Ewido that just came out
So it includes the latest updates  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

Can you do the following for me please

Download Find.Zip
Unzip the contents  to desktop
Double click on Find.bat and post back the contents
Also Double click on Find1.bat and post the contents
« Last Edit: July 06, 2005, 09:35:20 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Tan18_01

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Aurora and who knows what else..:'(
« Reply #7 on: July 11, 2005, 08:28:19 AM »
Sorry about the late reply.... Things have been hectic for me right now. Here are my results:

find.bat-

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoDriveTypeAutoRun"=dword:00000091

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ThemeManager]
"WCreatedUser"="1"
"LoadedBefore"="1"
"ThemeActive"="1"
"LastUserLangID"="1033"
"DllName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,72,00,65,00,73,00,6f,00,75,00,72,00,63,00,65,00,73,00,5c,\
  00,54,00,68,00,65,00,6d,00,65,00,73,00,5c,00,6c,00,75,00,6e,00,61,00,5c,00,\
  6c,00,75,00,6e,00,61,00,2e,00,6d,00,73,00,73,00,74,00,79,00,6c,00,65,00,73,\
  00,00,00
"ColorName"="NormalColor"
"SizeName"="NormalSize"

find1.bat -

 Volume in drive C has no label.
 Volume Serial Number is 205D-1BD8

 Directory of C:\WINDOWS\Resources\Themes

09/15/2004  04:55 PM    <DIR>          .
09/15/2004  04:55 PM    <DIR>          ..
09/15/2004  04:55 PM    <DIR>          Luna
08/23/2001  12:00 PM             3,025 Windows Classic.theme
08/23/2001  12:00 PM             1,222 Luna.theme
               2 File(s)          4,247 bytes

 Directory of C:\WINDOWS\Resources\Themes\Luna

09/15/2004  04:55 PM    <DIR>          .
09/15/2004  04:55 PM    <DIR>          ..
09/15/2004  04:55 PM    <DIR>          Shell
               0 File(s)              0 bytes

 Directory of C:\WINDOWS\Resources\Themes\Luna\Shell

09/15/2004  04:55 PM    <DIR>          .
09/15/2004  04:55 PM    <DIR>          ..
09/15/2004  04:55 PM    <DIR>          NormalColor
09/15/2004  04:55 PM    <DIR>          Metallic
09/15/2004  04:55 PM    <DIR>          Homestead
               0 File(s)              0 bytes

 Directory of C:\WINDOWS\Resources\Themes\Luna\Shell\NormalColor

09/15/2004  04:55 PM    <DIR>          .
09/15/2004  04:55 PM    <DIR>          ..
08/23/2001  12:00 PM           361,472 shellstyle.dll
               1 File(s)        361,472 bytes

 Directory of C:\WINDOWS\Resources\Themes\Luna\Shell\Metallic

09/15/2004  04:55 PM    <DIR>          .
09/15/2004  04:55 PM    <DIR>          ..
08/23/2001  12:00 PM           362,496 shellstyle.dll
               1 File(s)        362,496 bytes

 Directory of C:\WINDOWS\Resources\Themes\Luna\Shell\Homestead

09/15/2004  04:55 PM    <DIR>          .
09/15/2004  04:55 PM    <DIR>          ..
08/23/2001  12:00 PM           362,496 shellstyle.dll
               1 File(s)        362,496 bytes

     Total Files Listed:
               5 File(s)      1,090,711 bytes
              17 Dir(s)   7,997,030,400 bytes free

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Aurora and who knows what else..:'(
« Reply #8 on: July 11, 2005, 06:39:35 PM »
You appear to be running the English version of XP
If you are, can you do the following please

Download and Save to desktop
LUNA.Zip

UNZIP the contents of Luna.zip
To
C:\WINDOWS\Resources\Themes\Luna <-this folder

You must unzip only to that folder
You should now have luna.msstyles unzipped to the Luna folder
Double click on luna.msstyles in the luna folder
It should open your Display options>>Appearance tab
Let me know if you can change your appearance to XP style now
Also check out your Themes tab to ensure you can have Windows XP style

Could you also run another scan with Hijackthis and post a fresh log
Let's make sure it still looks good

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Tan18_01

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Aurora and who knows what else..:'(
« Reply #9 on: July 13, 2005, 06:46:22 AM »
Thx. Xp Theme working all fine now.

here is my HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 9:45:46 PM, on 7/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HHVcdV7Sys\VC7SecS.exe
C:\Program Files\HHVcdV7Sys\VC7Play.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\WINDOWS\system32\LXSUPMON.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Virtual CD v7\System\VC7Tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://torax.outwar.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimtoday.com/search/aimtoolbar.jsp
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O4 - HKLM\..\Run: [VC7Player] C:\Program Files\HHVcdV7Sys\VC7Play.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Link Target in Firefox - file://C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewlink.html
O8 - Extra context menu item: View This Page in Firefox - file://C:\Documents and Settings\t@N\Application Data\Mozilla\Firefox\Profiles\default.y13\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewpage.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{22529674-3B9C-4E76-A387-59CBE06EA9AB}: NameServer = 203.0.178.191
O17 - HKLM\System\CS1\Services\Tcpip\..\{22529674-3B9C-4E76-A387-59CBE06EA9AB}: NameServer = 203.0.178.191
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Virtual CD v7 Management Service (VC7SecS) - H+H Software GmbH - C:\Program Files\HHVcdV7Sys\VC7SecS.exe

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Aurora and who knows what else..:'(
« Reply #10 on: July 14, 2005, 08:58:23 PM »
Sorry for the delay
Your log looks good

If everything is running better, please do the following
You should disable system restore---restart your computer--enable system restore
This will clear all your restore points and ensure you don't restore any nasties
How to Disable and Re-enable System Restore feature

Once back in Windows and System Restore is reenabled

You should set up protection against future attacks

SpywareBlaster 3.4 by JavaCool
*Will block bad ActiveX Controls
*Block Malevolent cookies in Internet Explorer and Firefox
*Restrict actions of potentially dangerous sites in Internet Explorer
After installation, Check for updates and then click the "Enable all protection"

IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
Here is a tutorial and download link
TUTORIAL==Link to Tutorial
Download link

With both, Check for updates every couple of weeks
Keep the link to IE-Spyad bookmarked so you can check for updates
SpywareBlaster, after every update just simply click the "enable all protection"
IE-Spyad is compatible with SP2 as well

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Aurora and who knows what else..:'(
« Reply #11 on: July 20, 2005, 10:18:23 PM »
As the problems appear to be resolved, I'll lock this topic
If the original poster needs it reopened, please PM a Mod or the site Admin
Supply a link to this thread
 
take care  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here