Author Topic: my computers screwed up  (Read 1302 times)

Offline kittyasha

  • Full Member
  • ***
  • Posts: 107
  • Karma: +0/-0
    • View Profile
my computers screwed up
« on: February 18, 2006, 04:24:09 PM »
=s my computers pretty messed up, i think because recently i downloaded a program from limewire.if i try to go to task manager it just doesnt do anything. it says error during execution of this program, or it says this operation has been restricted due to effect on system,please contact your sytem adminastrator, even though i am an adminastrator, also, i cant see my desktop icons.
if no one knows what the hell is going on i guess ill just have to reinstall windows
« Last Edit: February 18, 2006, 04:30:35 PM by kittyasha »
what is the opposite of the neutral god guthix?

--------------------------------------------

[color=\"#33ff33\"]sucsessful[/color]. transactions,10mill ,rs2gp  recomended user

[color=\"#33ff33\"]sucsessful.[color=\"#000000\"] transaction, 106 account.trusted mills

----------------------------------------------------------------------



... everyone knows that ie is the ultimate browser for downloading mozilla.

get your ass on firefox if your not on it click here

[/color][/color]

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
my computers screwed up
« Reply #1 on: February 18, 2006, 07:09:30 PM »
What are you able to do?
I just have to know where we stand
Do you have a task bar?
Can you download Hijackthis from my signature below
Run hijackthis.exe
Do a SCAN and Save a Log file---Save the log----copy and paste the WHOLE contents of the log  here?

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline kittyasha

  • Full Member
  • ***
  • Posts: 107
  • Karma: +0/-0
    • View Profile
my computers screwed up
« Reply #2 on: February 18, 2006, 10:10:31 PM »
yes i do have a taskbar, and heres my log. it also said i was denied write access to the host files

Logfile of HijackThis v1.99.1
Scan saved at 03:33:53 Pm, on 2/18/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Trend Micro\Antivirus\pccguide.exe
C:\Program Files\Trend Micro\Antivirus\PCClient.exe
C:\Program Files\Trend Micro\Antivirus\TMOAgent.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\WINDOWS\System32\bcmntray.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Standard\MiniMavis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ud7swe.t35.com/3wY26ss.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.ud7swe.t35.com/3wY26ss.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Antivirus\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Antivirus\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Antivirus\TMOAgent.exe" /run
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\System32\bcmntray
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [Synchronization Agent] "C:\Program Files\Sync Manager Demo\agent\syncagent.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: MiniMavis.lnk = C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Standard\MiniMavis.exe
O4 - Global Startup: rootz.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\Tmntsrv.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\tmproxy.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
what is the opposite of the neutral god guthix?

--------------------------------------------

[color=\"#33ff33\"]sucsessful[/color]. transactions,10mill ,rs2gp  recomended user

[color=\"#33ff33\"]sucsessful.[color=\"#000000\"] transaction, 106 account.trusted mills

----------------------------------------------------------------------



... everyone knows that ie is the ultimate browser for downloading mozilla.

get your ass on firefox if your not on it click here

[/color][/color]

Offline kittyasha

  • Full Member
  • ***
  • Posts: 107
  • Karma: +0/-0
    • View Profile
my computers screwed up
« Reply #3 on: February 19, 2006, 04:45:43 AM »
bump
what is the opposite of the neutral god guthix?

--------------------------------------------

[color=\"#33ff33\"]sucsessful[/color]. transactions,10mill ,rs2gp  recomended user

[color=\"#33ff33\"]sucsessful.[color=\"#000000\"] transaction, 106 account.trusted mills

----------------------------------------------------------------------



... everyone knows that ie is the ultimate browser for downloading mozilla.

get your ass on firefox if your not on it click here

[/color][/color]

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
my computers screwed up
« Reply #4 on: February 19, 2006, 08:08:10 AM »
Sorry for the delay,
Can you do the following please

==Download and save WinPFind.zip
UNZIP the contents to your desktop
Don't run it yet

RESTART your Computer into SAFE MODE
You can do this by tapping the F8 key as the system is restarting, just before Windows loads
Choose Safe mode from the startup menu and hit Enter

In safe mode
Open the WinPFind folder you extracted to desktop
Double click on WinPFind.exe
Click START SCAN
This could take some time as it will scan your drive
Close out after

Reboot back to Normal mode

Back in Windows
Post the results of the WindPFind.txt located in the WinPFind folder

Additionally, do you recognize this file, can you scan it pleae
Can you also go to this site
Give this site time to load
Jotti's Online Malware scan

Use the browse button and navigate to this file on your hard disk
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rootz.exe <--this file

Right click on the file and choose Select
Then use the Submit button
Let it finish scanning
Could you post back the results of the scan back here please

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline kittyasha

  • Full Member
  • ***
  • Posts: 107
  • Karma: +0/-0
    • View Profile
my computers screwed up
« Reply #5 on: February 19, 2006, 05:08:07 PM »
yeah i noticed that the rootz file was downloaded about the same time as ive had problems.

Service load:                                      0%                                                                     100%                                                      File:                      rootz.exe                                    Status:                         [color=\"red\"]INFECTED/MALWARE[/color]  (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)                                      MD5                4c8cc4b1c24b17e62e741a3ca93a469d                           Packers detected:                   UPX                                        Scanner results                                               AntiVir                     Found  nothing                                        ArcaVir                     Found  nothing                                        Avast                     Found  nothing                                        AVG Antivirus                     Found  nothing                                        BitDefender                     Found  nothing                                        ClamAV                     Found  nothing                                        Dr.Web                     Found modification of Win32.HLLW.Generic.187                                         F-Prot Antivirus                     Found  nothing                                        Fortinet                     Found  nothing                                        Kaspersky Anti-Virus                     Found  nothing                                        NOD32                     Found probably unknown NewHeur_PE (probable variant)                                         Norman Virus Control                     Found  nothing                                        UNA                     Found  nothing                                        VBA32                     Found  nothing

results for the jottis thing
what is the opposite of the neutral god guthix?

--------------------------------------------

[color=\"#33ff33\"]sucsessful[/color]. transactions,10mill ,rs2gp  recomended user

[color=\"#33ff33\"]sucsessful.[color=\"#000000\"] transaction, 106 account.trusted mills

----------------------------------------------------------------------



... everyone knows that ie is the ultimate browser for downloading mozilla.

get your ass on firefox if your not on it click here

[/color][/color]

Offline kittyasha

  • Full Member
  • ***
  • Posts: 107
  • Karma: +0/-0
    • View Profile
my computers screwed up
« Reply #6 on: February 19, 2006, 06:19:20 PM »
WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP    Current Build: Service Pack 1    Current Build Number: 2600
Internet Explorer Version: 6.0.2800.1106

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...
UPX!                 2/15/2006 6:51:10 ??????     26112      C:\rootz.exe

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...

Checking %System% folder...
UPX!                 1/20/2006 6:01:18 ??????     80896      C:\WINDOWS\SYSTEM32\camplugin.exe
PEC2                 8/29/2002 2:00:00 ??????     41397      C:\WINDOWS\SYSTEM32\DFRG.MSC
UPX!                 1/20/2006 6:01:18 ??????     168484     C:\WINDOWS\SYSTEM32\mc-110-12-0000218.exe
PECompact2           2/7/2006 9:23:40 ??????     4513120    C:\WINDOWS\SYSTEM32\MRT.exe
aspack               2/7/2006 9:23:40 ??????     4513120    C:\WINDOWS\SYSTEM32\MRT.exe
PEC2                 2/17/2007 3:26:36 ??????     198780983  C:\WINDOWS\SYSTEM32\mscache.sys
Umonitor             8/29/2002 2:00:00 ??????     631808     C:\WINDOWS\SYSTEM32\RASDLG.DLL
UPX!                 2/15/2006 6:51:10 ??????     26112      C:\WINDOWS\SYSTEM32\rootz.exe
winsync              8/29/2002 2:00:00 ??????     1309184    C:\WINDOWS\SYSTEM32\WBDBASE.DEU

Checking %System%\Drivers folder and sub-folders...
UPX!                 12/8/2005 9:19:02 ??????     1022432    C:\WINDOWS\SYSTEM32\drivers\VSAPINT.SYS
aspack               12/8/2005 9:19:02 ??????     1022432    C:\WINDOWS\SYSTEM32\drivers\VSAPINT.SYS

Items found in C:\WINDOWS\SYSTEM32\drivers\ETC\HOSTS
127.0.0.1 download.abetterinternet.com  # ***Inserted By STOPzilla***


Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
                     2/18/2007 10:45:28 ??????   S 2048       C:\WINDOWS\BOOTSTAT.DAT
                     2/17/2007 7:01:06 ??????  H  54156      C:\WINDOWS\QTFont.qfn
                     2/18/2007 10:45:16 ??????  H  8192       C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG
                     2/18/2007 10:45:42 ??????  H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG
                     2/18/2007 10:45:30 ??????  H  12288      C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG
                     2/18/2007 10:51:00 ??????  H  163840     C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG
                     2/18/2007 10:45:34 ??????  H  1007616    C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG
                     2/17/2007 5:38:32 ??????  H  1024       C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\NTUSER.DAT.LOG
                     2/17/2007 9:00:56 ??????  HS 388        C:\WINDOWS\SYSTEM32\Microsoft\Protect\S-1-5-18\User\b604a3f6-64ec-4d0c-aa4a-78a9a0713ef9
                     2/17/2007 9:00:56 ??????  HS 24         C:\WINDOWS\SYSTEM32\Microsoft\Protect\S-1-5-18\User\Preferred
                     2/18/2007 10:44:28 ??????  H  6          C:\WINDOWS\Tasks\SA.DAT

Checking for CPL files...
Microsoft Corporation          8/29/2002 2:00:00 ??????     66048      C:\WINDOWS\SYSTEM32\ACCESS.CPL
Microsoft Corporation          8/29/2002 2:00:00 ??????     578560     C:\WINDOWS\SYSTEM32\APPWIZ.CPL
Broadcom Corporation           5/8/2003 4:25:18 ??????     815104     C:\WINDOWS\SYSTEM32\B57exp.cpl
Broadcom Corporation           2/17/2005 8:50:20 ??????     1130496    C:\WINDOWS\SYSTEM32\bcmcfg.cpl
                               5/10/2001 9:00:00 ??????     183808     C:\WINDOWS\SYSTEM32\BDEADMIN.CPL
                               9/18/2003 12:18:00 ?????? R   24576      C:\WINDOWS\SYSTEM32\cpl_moh.cpl
Microsoft Corporation          8/29/2002 2:00:00 ??????     129024     C:\WINDOWS\SYSTEM32\DESK.CPL
Microsoft Corporation          8/29/2002 2:00:00 ??????     150016     C:\WINDOWS\SYSTEM32\HDWWIZ.CPL
Intel Corporation              4/6/2003 9:14:30 ??????     94208      C:\WINDOWS\SYSTEM32\igfxcpl.cpl
Microsoft Corporation          8/29/2002 2:00:00 ??????     292352     C:\WINDOWS\SYSTEM32\INETCPL.CPL
Microsoft Corporation          8/29/2002 2:00:00 ??????     121856     C:\WINDOWS\SYSTEM32\INTL.CPL
Microsoft Corporation          8/29/2002 2:00:00 ??????     65536      C:\WINDOWS\SYSTEM32\JOY.CPL
Sun Microsystems               4/14/2004 7:32:26 ??????     53352      C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation          8/29/2002 2:00:00 ??????     187904     C:\WINDOWS\SYSTEM32\MAIN.CPL
Microsoft Corporation          8/29/2002 2:00:00 ??????     559616     C:\WINDOWS\SYSTEM32\MMSYS.CPL
Microsoft Corporation          8/29/2002 2:00:00 ??????     35840      C:\WINDOWS\SYSTEM32\NCPA.CPL
Microsoft Corporation          8/29/2002 2:00:00 ??????     256000     C:\WINDOWS\SYSTEM32\NUSRMGR.CPL
Microsoft Corporation          8/29/2002 2:00:00 ??????     36864      C:\WINDOWS\SYSTEM32\ODBCCP32.CPL
Microsoft Corporation          8/29/2002 2:00:00 ??????     109056     C:\WINDOWS\SYSTEM32\POWERCFG.CPL
Apple Computer, Inc.           7/27/2003 7:05:54 ??????     295936     C:\WINDOWS\SYSTEM32\QuickTime.cpl
Microsoft Corporation          8/29/2002 2:00:00 ??????     268288     C:\WINDOWS\SYSTEM32\SYSDM.CPL
Microsoft Corporation          8/29/2002 2:00:00 ??????     28160      C:\WINDOWS\SYSTEM32\TELEPHON.CPL
Microsoft Corporation          8/29/2002 2:00:00 ??????     90112      C:\WINDOWS\SYSTEM32\TIMEDATE.CPL
Microsoft Corporation          5/26/2005 3:16:30 ??????     174360     C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation          8/29/2002 12:41:00 ??????     208896     C:\WINDOWS\SYSTEM32\DLLCACHE\joy.cpl
Intel Corporation              4/6/2003 9:14:30 ??????     94208      C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\igfxcpl.cpl

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder...
                     9/3/2002 6:00:00 ??????  HS 84         C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DESKTOP.INI
                     10/27/2005 1:51:54 ??????     1993       C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MiniMavis.lnk
UPX!                 2/15/2006 6:51:10 ??????     26112      C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rootz.exe

Checking files in %ALLUSERSPROFILE%\Application Data folder...
                     9/3/2002 5:50:46 ??????  HS 62         C:\Documents and Settings\All Users\Application Data\DESKTOP.INI

Checking files in %USERPROFILE%\Startup folder...
                     9/3/2002 6:00:00 ??????  HS 84         C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\DESKTOP.INI

Checking files in %USERPROFILE%\Application Data folder...
                     9/3/2002 5:50:46 ??????  HS 62         C:\Documents and Settings\Administrator\Application Data\DESKTOP.INI

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
 {750fdf0e-2a26-11d1-a3ea-080036587f03}  = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
 {09799AFB-AD67-11d1-ABCD-00C04FC30936}  = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
 {A470F8CF-A1E8-4f65-8335-227475AA5C46}  = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinRAR
 {B41DB860-8EE4-11D2-9906-E49FADC173CA}  = C:\Program Files\WinRAR\rarext.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Yahoo! Mail
 {5464D816-CF16-4784-B9F3-75C0DB52B499}  = C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{48F45200-91E6-11CE-8A4F-0080C81A28D4}
   = C:\Program Files\Trend Micro\Antivirus\Tmdshell.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
 Start Menu Pin  = %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinRAR
 {B41DB860-8EE4-11D2-9906-E49FADC173CA}  = C:\Program Files\WinRAR\rarext.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\{48F45200-91E6-11CE-8A4F-0080C81A28D4}
   = C:\Program Files\Trend Micro\Antivirus\Tmdshell.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
 {A470F8CF-A1E8-4f65-8335-227475AA5C46}  = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
 {750fdf0e-2a26-11d1-a3ea-080036587f03}  = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\QuickFinderMenu
 {C0E10002-0028-0004-C0E1-C0E1C0E1C0E1}  = c:\Program Files\WordPerfect Office 11\Programs\PFSE110.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
 {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}  = ntshrui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinRAR
 {B41DB860-8EE4-11D2-9906-E49FADC173CA}  = C:\Program Files\WinRAR\rarext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
  = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
  = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
  = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
  = %SystemRoot%\system32\SHELL32.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}
  =
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}
 DriveLetterAccess = C:\WINDOWS\system32\dla\tfswshx.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}
  =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4528BBE0-4E08-11D5-AD55-00010333D0AD}
  =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
 &Tip of the Day = %SystemRoot%\System32\shdocvw.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{FE54FA40-D68C-11d2-98FA-00C0F0318AFE}
 Real.com = C:\WINDOWS\System32\Shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
 {8E718888-423F-11D2-876E-00A0C9082467}  = &Radio : C:\WINDOWS\System32\msdxm.ocx
 {BA52B914-B692-46c4-B683-905236F6F655}  =  :

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
 MenuText  = Sun Java Console : C:\WINDOWS\System32\msjava.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{669B269B-0D4E-41FB-A3D8-FD67CA94F646}
 ButtonText  = ComcastHSI : http://www.comcast.net/
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{8828075D-D097-4055-AA02-2DBFA9D85E8A}
 ButtonText  = Support : http://www.comcastsupport.com/
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{97809617-3937-4F84-B335-9BB05EF1A8D4}
 ButtonText  = Help : http://online.comcast.net/help/
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
 ButtonText  = @shdoclc.dll,-866 :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
 ButtonText  = Real.com :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
 ButtonText  = Messenger : C:\Program Files\Messenger\MSMSGS.EXE

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
 Media Band = %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}
 File Search Explorer Band = %SystemRoot%\system32\SHELL32.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 IgfxTray C:\WINDOWS\System32\igfxtray.exe
 HotKeysCmds C:\WINDOWS\System32\hkcmd.exe
 IntelMeM C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
 dla C:\WINDOWS\system32\dla\tfswctrl.exe
 PCMService "C:\Program Files\Dell\Media Experience\PCMService.exe"
 QuickTime Task "C:\Program Files\QuickTime\qttask.exe" -atboottime
 TkBellExe "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
 mmtask c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
 Dell AIO Printer A920 "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
 pccguide.exe "C:\Program Files\Trend Micro\Antivirus\pccguide.exe"
 PCClient.exe "C:\Program Files\Trend Micro\Antivirus\PCClient.exe"
 TM Outbreak Agent "C:\Program Files\Trend Micro\Antivirus\TMOAgent.exe" /run
 tgcmd "C:\Program Files\support.com\bin\tgcmd.exe" /server
 UpdateManager "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
 Broadcom Wireless Manager UI C:\WINDOWS\System32\bcmntray
 ViewMgr C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
 Synchronization Agent "C:\Program Files\Sync Manager Demo\agent\syncagent.exe"
 ScanRegistry

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
 SchedulingAgent

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 Sonic RecordNow!
 DellSupport "C:\Program Files\Dell Support\DSAgnt.exe" /startup
 MSMSGS "C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
 NoDesktop 1


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
 {BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
 {6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
 {0DF44EAA-FF21-4412-828E-260A8728E7F1} =


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings
 Key e¶Mgøci¤1u¢Ç
 FileName0 C:\WINDOWS\System32\RSACi.rat

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings\.Default
 Allow_Unknowns 0
 PleaseMom 0
 Enabled 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings\.Default\http://www.rsac.org/ratingsv01.html
 l 0
 n 0
 s 0
 v 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings\PICSRules

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings\PICSRules\.Default

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
 dontdisplaylastusername 0
 legalnoticecaption
 legalnoticetext
 shutdownwithoutlogon 1
 undockwithoutlogon 1


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
 NoDriveTypeAutoRun 145
 NoRun 
 NoClose 
 NoLogOff 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
 DisableTaskmgr 1
 DisableRegistryTools 1


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
 PostBootReminder                {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
 CDBurn                          {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
 WebCheck                        {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
 SysTray                         {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
 UserInit = C:\WINDOWS\system32\userinit.exe,
 Shell  = Explorer.exe
 System  =

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
  = crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
  = cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
  = cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui
  = igfxsrvc.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
  = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
  = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
  = sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
  = WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
  = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
  = wlnotify.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
 Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
 AppInit_DLLs


»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.4.1 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 2/18/2007 10:57:54 ??????
what is the opposite of the neutral god guthix?

--------------------------------------------

[color=\"#33ff33\"]sucsessful[/color]. transactions,10mill ,rs2gp  recomended user

[color=\"#33ff33\"]sucsessful.[color=\"#000000\"] transaction, 106 account.trusted mills

----------------------------------------------------------------------



... everyone knows that ie is the ultimate browser for downloading mozilla.

get your ass on firefox if your not on it click here

[/color][/color]

Offline kittyasha

  • Full Member
  • ***
  • Posts: 107
  • Karma: +0/-0
    • View Profile
my computers screwed up
« Reply #7 on: February 19, 2006, 07:04:02 PM »
bump
what is the opposite of the neutral god guthix?

--------------------------------------------

[color=\"#33ff33\"]sucsessful[/color]. transactions,10mill ,rs2gp  recomended user

[color=\"#33ff33\"]sucsessful.[color=\"#000000\"] transaction, 106 account.trusted mills

----------------------------------------------------------------------



... everyone knows that ie is the ultimate browser for downloading mozilla.

get your ass on firefox if your not on it click here

[/color][/color]

Offline kittyasha

  • Full Member
  • ***
  • Posts: 107
  • Karma: +0/-0
    • View Profile
my computers screwed up
« Reply #8 on: February 19, 2006, 07:40:25 PM »
bump
what is the opposite of the neutral god guthix?

--------------------------------------------

[color=\"#33ff33\"]sucsessful[/color]. transactions,10mill ,rs2gp  recomended user

[color=\"#33ff33\"]sucsessful.[color=\"#000000\"] transaction, 106 account.trusted mills

----------------------------------------------------------------------



... everyone knows that ie is the ultimate browser for downloading mozilla.

get your ass on firefox if your not on it click here

[/color][/color]

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
my computers screwed up
« Reply #9 on: February 19, 2006, 08:31:27 PM »
Can you do the following please
*******************************************************
Open Notepad (START>>>RUN>>>type in notepad)
Hit OK
Copy the contents of the CODE box to notepad, not including the word "code"
Paste it too the empty notepad please
In Notepad click FILE>>SAVE AS
IMPORTANT>>>Change the Save as Type to All Files.
Name the file as fix.reg

Save this file to a folder, we'll need this later, don't run it yet
Ensure to to include REGEDIT4 and down in the code box
Code: [Select]
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=dword:00000000
"DisableRegistryTools"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDesktop"=-

**********************************************************
Because you mentioned Limewire, I would like you too do the following also
**********************************************************
When I ask you too download a zip file, make sure you choose SAVE TO DISK rather than Open
Can you open "MyComputer"
Double click to open Local Disk C: drive
Right click an empty spot  and left click NEW>>Folder
A new folder will be placed in the C: folder , name it BFU
So you now have C:\BFU

Please download Brute Force Uninstaller
Reminder, choose SAVE rather than OPEN
Then Extract (UNZIP) the contents to the (C:\BFU) folder you just made

[color=\"#CC0000\"]RIGHT CLICK HERE[/color]
 and choose "Save As" (in IE it's "Save Target As") in order to download  Alcra Remover.
Save it in the folder you made earlier (c:\BFU)
***********************************************************
== Download Hoster.zip  and unzip it too a folder of it's own
Open Hoster and click on the "Make Hosts Writeable" in the top right hand corner
Then click the "Backup Hosts File"
Then select the "Restore Original Hosts" button

Afterwards
==Download and Install
Windows Cleanup! 4.0

==Download and save to folder FxNetOpt.exe
by Symantec's

==Download the Killbox by Option^Explicit.
* Save it to a folder

==Download and then Install
Ewido anti-malware 3.5

When installing, under "Additional Options" Uncheck
 "Install background guard" and "Install scan via context menu".

From the main ewido screen, click on Update in the left menu, then click the Start update button.
After the update finishes (the status bar at the bottom will display "Update successful")
Close out Ewido for now, we'll need it later
If for some reason the Updater won't work can you manually download the
Updates from this link after you have Ewido installed
http://www.ewido.net/en/download/updates/

Please save these instructions to a Notepad file and save it to a folder that is accessible for reference
It's important as I need you too copy and paste some lines in safe mode to killbox

Double click on fix.reg and allow to add/merge to the registry

RESTART your Computer in SAFE MODE
You can do this by tapping the F8 key as the system is restarting, just before Windows loads
Choose Safe mode from the startup menu

In safe mode

Open the C:\BFU folder
Double click to run BFU.exe
Use the "Open Script file" button (the folder icon next to Scriptfile to execute)
Navigate to p2pnetwork.bfu in the C:\BFU folder
Right click p2pnetwork.bfu and choose Select
In Brute Force Uninstaller select Execute
Wait for the "complete script execution" box to pop up and press OK.
Press exit to terminate the BFU program.

Run FxNetOpt.exe by Symantec's and let it scan your drive

=Open Killbox.exe
Copy the file name below and paste it to the Full path of file to delete in Killbox

C:\rootz.exe
Then click the Red Circle with the White X
Allow to delete the file and make backup

Do the same with the rest of these
Don't worry about any file not found messages
==================================
C:\WINDOWS\SYSTEM32\camplugin.exe
C:\WINDOWS\SYSTEM32\mc-110-12-0000218.exe
C:\WINDOWS\SYSTEM32\mscache.sys
C:\WINDOWS\SYSTEM32\rootz.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rootz.exe
=================================

==Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
Set the program up as follows:
Click "Options..."
Move the arrow down to "Custom CleanUp!"
Put a check next to the following (Make sure nothing else is checked!):

    * Empty Recycle Bins
    * Delete Cookies
    * Delete Prefetch files
    * Cleanup! All Users

Click OK
Press the CleanUp! button to start the program.
When it's done, decline to log off or restart the computer

==Open Ewido anti-malware
Click on the Scanner button on the left menu
Select Complete System Scan
*If Ewido finds something it will prompt you with "Infected Object found"
Ensure the following are Selected
  *1. Perform Action = Remove
  *2. Create Encrypted Backup in Quarantine (Recommended)
  *3. Perform action with all infections
    Then click OK
When Ewido has finished it's scan click the "Save Report" button
Save the report to desktop
Exit Ewido
NOTE: When Ewido is running, don't open any other Windows

Can you again double click on fix.reg and allow to merge
Also run Hoster again and "Restore Original hosts"

Remain in safe mode, let's make sure some files and registry settings are gone
Run WPFind again in safe mode

Return to Normal mode

Post back all the following please
1. a fresh hijackthis log
2. the new log from WPFind
3. The whole report from Ewidos
« Last Edit: February 19, 2006, 08:32:33 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline kittyasha

  • Full Member
  • ***
  • Posts: 107
  • Karma: +0/-0
    • View Profile
my computers screwed up
« Reply #10 on: February 20, 2006, 04:10:31 PM »
hjt log
Logfile of HijackThis v1.99.1
Scan saved at 00:34:39 ??????, on 2/20/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\Antivirus\Tmntsrv.exe
C:\Program Files\Trend Micro\Antivirus\tmproxy.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Trend Micro\Antivirus\pccguide.exe
C:\Program Files\Trend Micro\Antivirus\PCClient.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Trend Micro\Antivirus\TMOAgent.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\System32\bcmntray.exe
C:\WINDOWS\System32\lexpps.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Standard\MiniMavis.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rootz.exe
C:\Program Files\support.com\bin\tgfix.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\rootz.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Antivirus\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Antivirus\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Antivirus\TMOAgent.exe" /run
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\System32\bcmntray
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [Synchronization Agent] "C:\Program Files\Sync Manager Demo\agent\syncagent.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: MiniMavis.lnk = C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Standard\MiniMavis.exe
O4 - Global Startup: rootz.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\Tmntsrv.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\tmproxy.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
what is the opposite of the neutral god guthix?

--------------------------------------------

[color=\"#33ff33\"]sucsessful[/color]. transactions,10mill ,rs2gp  recomended user

[color=\"#33ff33\"]sucsessful.[color=\"#000000\"] transaction, 106 account.trusted mills

----------------------------------------------------------------------



... everyone knows that ie is the ultimate browser for downloading mozilla.

get your ass on firefox if your not on it click here

[/color][/color]

Offline kittyasha

  • Full Member
  • ***
  • Posts: 107
  • Karma: +0/-0
    • View Profile
my computers screwed up
« Reply #11 on: February 20, 2006, 04:29:38 PM »
---------------------------------------------------------
 ewido anti-malware - Scan report
---------------------------------------------------------

 + Created on:            13:40:24 ??????, 2/19/2007
 + Report-Checksum:        32517087

 + Scan result:

    HKLM\SOFTWARE\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
    HKLM\SOFTWARE\KMiNT21 -> Adware.DesktopSpyAgent : Cleaned with backup
    HKLM\SOFTWARE\KMiNT21\GoldenKeylogger -> Adware.DesktopSpyAgent : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ISTbarISTbar -> Adware.ISTBar : Cleaned with backup
    HKLM\SOFTWARE\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
    C:\!KillBox\mc-110-12-0000218.exe -> Adware.Maxifiles : Cleaned with backup
    C:\data -> Downloader.IstBar.nh : Cleaned with backup
    :mozilla.12:C:\Documents and Settings\etsttttewraerrrrrrr\Application Data\Mozilla\Firefox\Profiles\jrc3tzdl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
    :mozilla.13:C:\Documents and Settings\etsttttewraerrrrrrr\Application Data\Mozilla\Firefox\Profiles\jrc3tzdl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
    :mozilla.14:C:\Documents and Settings\etsttttewraerrrrrrr\Application Data\Mozilla\Firefox\Profiles\jrc3tzdl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
    :mozilla.15:C:\Documents and Settings\etsttttewraerrrrrrr\Application Data\Mozilla\Firefox\Profiles\jrc3tzdl.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
    :mozilla.14:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
    :mozilla.33:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
    :mozilla.34:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
    :mozilla.36:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
    :mozilla.37:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
    :mozilla.38:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
    :mozilla.45:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
    :mozilla.46:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
    :mozilla.47:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
    :mozilla.48:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
    :mozilla.50:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
    :mozilla.67:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.68:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.69:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.70:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.71:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.72:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.73:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.74:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.75:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.76:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.77:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.86:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
    :mozilla.97:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
    :mozilla.98:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
    :mozilla.99:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
    :mozilla.100:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
    :mozilla.106:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup
    :mozilla.114:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
    :mozilla.115:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
    :mozilla.116:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
    :mozilla.117:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
    :mozilla.118:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
    :mozilla.119:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
    :mozilla.120:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
    :mozilla.130:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
    :mozilla.131:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
    :mozilla.132:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
    :mozilla.133:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
    :mozilla.134:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
    :mozilla.135:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
    :mozilla.136:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
    :mozilla.139:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
    :mozilla.140:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
    :mozilla.141:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
    :mozilla.142:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
    :mozilla.143:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
    :mozilla.157:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
    :mozilla.161:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
    :mozilla.162:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
    :mozilla.163:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\fuqcpis7.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
    :mozilla.20:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.21:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.22:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.23:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.24:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.25:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.26:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.27:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.28:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.29:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.30:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.31:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    :mozilla.33:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
    :mozilla.38:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
    :mozilla.39:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
    :mozilla.40:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
    :mozilla.41:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
    :mozilla.42:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
    :mozilla.43:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
    :mozilla.44:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
    :mozilla.45:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
    :mozilla.46:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
    :mozilla.47:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
    :mozilla.48:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
    :mozilla.66:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
    :mozilla.67:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
    :mozilla.68:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
    :mozilla.69:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
    :mozilla.70:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
    :mozilla.71:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
    :mozilla.72:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
    :mozilla.73:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
    :mozilla.74:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
    :mozilla.75:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
    :mozilla.76:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
    :mozilla.77:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
    :mozilla.81:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
    :mozilla.88:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
    :mozilla.95:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
    :mozilla.96:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
    :mozilla.97:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
    :mozilla.98:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
    :mozilla.99:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
    :mozilla.100:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
    :mozilla.106:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
    :mozilla.124:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
    :mozilla.126:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
    :mozilla.127:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
    :mozilla.128:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
    :mozilla.129:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
    :mozilla.131:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
    :mozilla.134:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
    :mozilla.135:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
    :mozilla.136:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
    :mozilla.137:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
    :mozilla.138:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
    :mozilla.142:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
    :mozilla.147:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
    :mozilla.149:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
    :mozilla.164:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
    :mozilla.165:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
    :mozilla.166:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
    :mozilla.177:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
    :mozilla.179:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
    :mozilla.191:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
    :mozilla.192:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
    :mozilla.203:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup
    :mozilla.204:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup
    :mozilla.278:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
    :mozilla.279:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
    :mozilla.280:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
    :mozilla.281:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
    :mozilla.282:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
    :mozilla.283:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
    :mozilla.284:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
    :mozilla.289:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
    :mozilla.290:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
    :mozilla.292:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
    :mozilla.293:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
    :mozilla.294:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
    :mozilla.295:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
    :mozilla.296:C:\Documents and Settings\HHHHHHHH\Application Data\Mozilla\Firefox\Profiles\5gghn3uz.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
    C:\Program Files\ISTbar -> Adware.ISTBar : Cleaned with backup
    C:\Program Files\ISTsvc -> Adware.ISTBar : Cleaned with backup
    :mozilla.33:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Atdmt : Error during cleaning
    :mozilla.34:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Advertising : Error during cleaning
    :mozilla.35:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Advertising : Error during cleaning
    :mozilla.36:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Advertising : Error during cleaning
    :mozilla.37:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Atdmt : Error during cleaning
    :mozilla.38:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Advertising : Error during cleaning
    :mozilla.39:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Bridgetrack : Error during cleaning
    :mozilla.40:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Bridgetrack : Error during cleaning
    :mozilla.41:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Bridgetrack : Error during cleaning
    :mozilla.42:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Bridgetrack : Error during cleaning
    :mozilla.44:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Overture : Error during cleaning
    :mozilla.45:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Overture : Error during cleaning
    :mozilla.46:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Doubleclick : Error during cleaning
    :mozilla.67:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Burstnet : Error during cleaning
    :mozilla.68:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Burstnet : Error during cleaning
    :mozilla.69:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Burstnet : Error during cleaning
    :mozilla.70:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tacoda : Error during cleaning
    :mozilla.71:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tacoda : Error during cleaning
    :mozilla.72:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tacoda : Error during cleaning
    :mozilla.73:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tacoda : Error during cleaning
    :mozilla.80:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Googleadservices : Error during cleaning
    :mozilla.94:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Mediaplex : Error during cleaning
    :mozilla.95:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Pointroll : Error during cleaning
    :mozilla.96:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Pointroll : Error during cleaning
    :mozilla.97:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Pointroll : Error during cleaning
    :mozilla.98:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Pointroll : Error during cleaning
    :mozilla.99:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Pointroll : Error during cleaning
    :mozilla.131:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Questionmarket : Error during cleaning
    :mozilla.151:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tribalfusion : Error during cleaning
    :mozilla.152:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tribalfusion : Error during cleaning
    :mozilla.153:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tribalfusion : Error during cleaning
    :mozilla.154:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tribalfusion : Error during cleaning
    :mozilla.155:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tribalfusion : Error during cleaning
    :mozilla.156:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tribalfusion : Error during cleaning
    :mozilla.157:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tribalfusion : Error during cleaning
    :mozilla.158:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tribalfusion : Error during cleaning
    :mozilla.159:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tribalfusion : Error during cleaning
    :mozilla.160:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tribalfusion : Error during cleaning
    :mozilla.173:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Googleadservices : Error during cleaning
    :mozilla.177:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Fastclick : Error during cleaning
    :mozilla.178:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Fastclick : Error during cleaning
    :mozilla.179:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Fastclick : Error during cleaning
    :mozilla.180:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Fastclick : Error during cleaning
    :mozilla.181:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Fastclick : Error during cleaning
    :mozilla.182:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Fastclick : Error during cleaning
    :mozilla.192:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.193:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.194:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.195:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.196:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.197:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.198:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.199:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.200:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.201:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.202:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.203:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.204:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.205:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.206:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.207:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.208:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.209:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.210:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.211:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.212:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.213:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.214:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.215:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Valueclick : Error during cleaning
    :mozilla.216:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Valueclick : Error during cleaning
    :mozilla.221:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning
    :mozilla.222:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning
    :mozilla.223:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning
    :mozilla.224:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning
    :mozilla.225:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning
    :mozilla.226:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Adserver : Error during cleaning
    :mozilla.227:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Adserver : Error during cleaning
    :mozilla.228:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Adserver : Error during cleaning
    :mozilla.229:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Adserver : Error during cleaning
    :mozilla.230:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Adserver : Error during cleaning
    :mozilla.231:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Adserver : Error during cleaning
    :mozilla.235:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning
    :mozilla.236:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning
    :mozilla.237:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning
    :mozilla.238:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning
    :mozilla.239:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning
    :mozilla.240:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning
    :mozilla.241:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning
    :mozilla.242:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning
    :mozilla.243:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning
    :mozilla.248:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Goclick : Error during cleaning
    :mozilla.249:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Goclick : Error during cleaning
    :mozilla.254:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Zedo : Error during cleaning
    :mozilla.255:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Zedo : Error during cleaning
    :mozilla.256:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Zedo : Error during cleaning
    :mozilla.257:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Googleadservices : Error during cleaning
    :mozilla.260:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning
    :mozilla.261:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning
    :mozilla.262:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning
    :mozilla.263:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Qksrv : Error during cleaning
    :mozilla.264:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Qksrv : Error during cleaning
    :mozilla.266:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Adtech : Error during cleaning
    :mozilla.267:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Adtech : Error during cleaning
    :mozilla.280:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Coremetrics : Error during cleaning
    :mozilla.286:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Liveperson : Error during cleaning
    :mozilla.287:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Liveperson : Error during cleaning
    :mozilla.288:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Liveperson : Error during cleaning
    :mozilla.306:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Overture : Error during cleaning
    :mozilla.309:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.2o7 : Error during cleaning
    :mozilla.323:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Revenue : Error during cleaning
    :mozilla.325:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tradedoubler : Error during cleaning
    :mozilla.327:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tradedoubler : Error during cleaning
    :mozilla.333:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tradedoubler : Error during cleaning
    :mozilla.334:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tradedoubler : Error during cleaning
    :mozilla.336:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Tradedoubler : Error during cleaning
    :mozilla.350:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Adrevolver : Error during cleaning
    :mozilla.354:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Adrevolver : Error during cleaning
    :mozilla.355:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Adrevolver : Error during cleaning
    :mozilla.356:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Adrevolver : Error during cleaning
    :mozilla.358:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Adrevolver : Error during cleaning
    :mozilla.359:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Adrevolver : Error during cleaning
    :mozilla.365:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning
    :mozilla.366:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning
    :mozilla.367:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning
    :mozilla.368:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning
    :mozilla.369:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning
    :mozilla.370:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning
    :mozilla.397:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Trafficmp : Error during cleaning
    :mozilla.398:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Trafficmp : Error during cleaning
    :mozilla.399:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Trafficmp : Error during cleaning
    :mozilla.400:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Trafficmp : Error during cleaning
    :mozilla.401:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Trafficmp : Error during cleaning
    :mozilla.402:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Trafficmp : Error during cleaning
    :mozilla.403:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Trafficmp : Error during cleaning
    :mozilla.404:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Trafficmp : Error during cleaning
    :mozilla.405:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Trafficmp : Error during cleaning
    :mozilla.420:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Falkag : Error during cleaning
    :mozilla.421:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Falkag : Error during cleaning
    :mozilla.422:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Falkag : Error during cleaning
    :mozilla.423:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Falkag : Error during cleaning
    :mozilla.424:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Falkag : Error during cleaning
    :mozilla.442:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Ru4 : Error during cleaning
    :mozilla.443:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Ru4 : Error during cleaning
    :mozilla.444:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Ru4 : Error during cleaning
    :mozilla.445:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Ru4 : Error during cleaning
    :mozilla.446:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Ru4 : Error during cleaning
    :mozilla.447:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Ru4 : Error during cleaning
    :mozilla.448:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Ru4 : Error during cleaning
    :mozilla.449:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Ru4 : Error during cleaning
    :mozilla.450:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Ru4 : Error during cleaning
    :mozilla.451:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Ru4 : Error during cleaning
    :mozilla.462:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Liveperson : Error during cleaning
    :mozilla.490:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning
    :mozilla.491:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning
    :mozilla.492:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning
    :mozilla.493:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning
    :mozilla.494:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning
    :mozilla.495:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning
    :mozilla.496:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning
    :mozilla.497:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning
    :mozilla.498:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning
    :mozilla.499:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning
    :mozilla.500:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning
    :mozilla.501:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Yadro : Error during cleaning
    :mozilla.502:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Yadro : Error during cleaning
    :mozilla.513:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Onestat : Error during cleaning
    :mozilla.514:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Onestat : Error during cleaning
    :mozilla.529:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Burstbeacon : Error during cleaning
    :mozilla.530:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Burstbeacon : Error during cleaning
    :mozilla.551:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Webtrendslive : Error during cleaning
    :mozilla.552:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Webtrendslive : Error during cleaning
    :mozilla.601:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning
    :mozilla.602:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning
    :mozilla.618:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Googleadservices : Error during cleaning
    :mozilla.625:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning
    :mozilla.626:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning
    :mozilla.635:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Googleadservices : Error during cleaning
    :mozilla.636:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Hitbox : Error during cleaning
    :mozilla.651:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Bluestreak : Error during cleaning
    :mozilla.692:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Googleadservices : Error during cleaning
    :mozilla.702:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> TrackingCookie.Googleadservices : Error during cleaning
    :mozilla.705:C:\Program Files\support.com\backup\Co\cookies.txt\128860_5b675ad37_/cookies.txt -> Track
what is the opposite of the neutral god guthix?

--------------------------------------------

[color=\"#33ff33\"]sucsessful[/color]. transactions,10mill ,rs2gp  recomended user

[color=\"#33ff33\"]sucsessful.[color=\"#000000\"] transaction, 106 account.trusted mills

----------------------------------------------------------------------



... everyone knows that ie is the ultimate browser for downloading mozilla.

get your ass on firefox if your not on it click here

[/color][/color]

Offline kittyasha

  • Full Member
  • ***
  • Posts: 107
  • Karma: +0/-0
    • View Profile
my computers screwed up
« Reply #12 on: February 20, 2006, 07:35:05 PM »
bump
what is the opposite of the neutral god guthix?

--------------------------------------------

[color=\"#33ff33\"]sucsessful[/color]. transactions,10mill ,rs2gp  recomended user

[color=\"#33ff33\"]sucsessful.[color=\"#000000\"] transaction, 106 account.trusted mills

----------------------------------------------------------------------



... everyone knows that ie is the ultimate browser for downloading mozilla.

get your ass on firefox if your not on it click here

[/color][/color]

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
my computers screwed up
« Reply #13 on: February 20, 2006, 07:42:51 PM »
You didn't post the bottom part of the Ewido log and you didn't post the new WPfind log
Can you post those please,
Were you able to do everything I asked of you in my last reply???
Additionally, is your clock on the computer set right?
Can you recheck and ensure you have the date and time set correctly, including year!
« Last Edit: February 20, 2006, 07:43:39 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline kittyasha

  • Full Member
  • ***
  • Posts: 107
  • Karma: +0/-0
    • View Profile
my computers screwed up
« Reply #14 on: February 20, 2006, 10:51:34 PM »
i couldnt merge fix.reg to the registry
what is the opposite of the neutral god guthix?

--------------------------------------------

[color=\"#33ff33\"]sucsessful[/color]. transactions,10mill ,rs2gp  recomended user

[color=\"#33ff33\"]sucsessful.[color=\"#000000\"] transaction, 106 account.trusted mills

----------------------------------------------------------------------



... everyone knows that ie is the ultimate browser for downloading mozilla.

get your ass on firefox if your not on it click here

[/color][/color]

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
my computers screwed up
« Reply #15 on: February 20, 2006, 11:03:30 PM »
Make sure you copied fix.reg as posted above

Can you do the following please
If you can, access this folder
C:\Program Files\support.com
Delete all the Backup folders

Copy these instructions too a Notepad file saved to a folder
Close down your browser

Do a "System scan only" with Hijackthis and put a check next to these entries:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\rootz.exe
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - Global Startup: rootz.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1


After you have ticked the above entry, close All other open windows
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis

Open Killbox.exe
In the killbox program, select the radio button
Delete on Reboot
Copy the file names below to the clipboard by highlighting them and pressing the 2 key combination on your keyboard
Control + C

Killbox files to highlight between dotted lines

==================================
C:\rootz.exe
C:\WINDOWS\SYSTEM32\camplugin.exe
C:\WINDOWS\SYSTEM32\mc-110-12-0000218.exe
C:\WINDOWS\SYSTEM32\mscache.sys
C:\WINDOWS\SYSTEM32\rootz.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rootz.exe


===================================================
*Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
*Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

If your computer doesn't restart
RESTART manually

Back in Windows
Don't open a browser yet, instead, double click on fix.reg and allow to add/merge to the registry
Reboot the computer again

Back in Windows
I need you to do the following

Post a fresh hijackthis log
I additionally want to see the bottom part of the Ewido log
Could you also run WPFInd again, it can be ran in normal mode
After you click START SCAN, don't open or close any windows until the log appears

I won't reply back until I see what I asked for so read the instructions carefully
« Last Edit: February 20, 2006, 11:03:52 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
my computers screwed up
« Reply #16 on: March 05, 2006, 04:59:11 PM »
Since the user has not returned, this topic is locked

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here