Author Topic: Oh Darn!!! I have the Zlob trojan - HELP Please....  (Read 30880 times)

0 Members and 1 Guest are viewing this topic.

Offline Cherubs

  • Full Member
  • ***
  • Posts: 84
    • View Profile
Re: Oh Darn!!! I have the Zlob trojan - HELP Please....
« Reply #60 on: August 13, 2006, 10:57:56 PM »
Under "Reports"

    * Select "Automatically generate report after every scan"
    * DE-Select "Only if threats were found"
    * close ewido

Did you mean Corrine for me to tick the "only if threats were found" box, I wasn't sure what DE-Select meant

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 20795
  • "Stronger than the past, united in our goal."
    • View Profile
    • Security Garden
Re: Oh Darn!!! I have the Zlob trojan - HELP Please....
« Reply #61 on: August 13, 2006, 11:25:30 PM »
Yes, deselect that box, please.  I want to see what ewido has to report, even if it doesn't find anything.

Thanks. 

(P.S. With our time zone differences, it may be your tomorrow morning before I have a chance to take a close look at what you post.  However, its possible SpyDie or Winchester73 will be here first.)


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline SpiritWind

  • Full Member
  • ***
  • Posts: 81
    • View Profile
Limewire
« Reply #62 on: August 13, 2006, 11:35:56 PM »
 :D  Hi Cherubs :

      Dislike throwing "cold water" on Limewire, but back in Apr there was a thread on
      castlecops about Limewire containing a rootkit ; see :

     www.castlecops.com/postlite153185-limewire.html .

      Seems safer to use Shareaza from www.shareaza.com than Limewire !?
For the BEST in what counts in Life :

www.tacf.org

Offline Cherubs

  • Full Member
  • ***
  • Posts: 84
    • View Profile
Re: Oh Darn!!! I have the Zlob trojan - HELP Please....
« Reply #63 on: August 13, 2006, 11:39:06 PM »
Things are getting worse and I'm really starting to stress out (insert tearful icon) I now cant open my internet banking because of the java. I need to get this all sorted quickly as my ebay customers will not be happy!! I just dont know what to do next....

Offline Cherubs

  • Full Member
  • ***
  • Posts: 84
    • View Profile
Re: Oh Darn!!! I have the Zlob trojan - HELP Please....
« Reply #64 on: August 14, 2006, 12:32:25 AM »
It showed up nothing in the safe mode scan which I didn't think it would as I had already run a scan earlier that morning which found some medium threat objects.

Offline Cherubs

  • Full Member
  • ***
  • Posts: 84
    • View Profile
Re: Oh Darn!!! I have the Zlob trojan - HELP Please....
« Reply #65 on: August 14, 2006, 03:57:42 AM »
Just wanted to let you all know that my problems are all sorted now. Thanks to everyone that helped, its been a long week!!

I ended up ringing my computer shop and asking them what they thought, he said I'd done nearly everything possible (thanks to you guys!) We even tried downloading a program that had java on it (limewire) which also didn't work.

In the end I reloaded windows xp under the repair 2 mode, which kept all my settings and files etc. I cant believe its all back to normal now :D

Hugs and Thanks to everyone that took the time to help me  :flowers:

Offline Tarnak

  • Sr. Member
  • ****
  • Posts: 493
    • View Profile
Re: Oh Darn!!! I have the Zlob trojan - HELP Please....
« Reply #66 on: August 14, 2006, 04:29:23 AM »
 Glad you got it sorted  Cherubs  :hysterical:

  Since I spent about 4 hours preparing this post, I might as well post as a training exercise   :lol:


 I have been following this thread, and I suggest the following:
 
 


 1. Uninstall Java JRE 1.4..? (or 1.5..?) version  via  Add/Remove

programs.

 2.Reboot

 3.Ensure that all the Java directories that may be installed Java to in \

Progam  Files are deleted.

    ......Usually in C:\Program Files\Java

       .......see http://img1.yoxio.com/img/250695.gif
 

10kb - View Full Image

 4. You may have to delete this folder(Not sure)in this location:


   C:\Documents and Settings\<username>\Application Data\Sun




9kb - View Full Image

 5.Download and install the following utility
       
   see....http://support.microsoft.com/default.aspx?kbid=290301







   After it's installed run it. (I installed this utility in my C:\Program

Files)....(For others it my be a shortcut on your Start Menu).

   This utility will display a list of programs installed through Windows

Installer. If you find any entries for Java Runtime Environment in the

"Installed Products" listing, select it/them, then hit "Remove" and let the

cleanup utility do its thing.(Note: this utility merely cleans up Windows

Installer Registry data for the selected products; it does not perform a

full uninstall of the products.)

........http://img1.yoxio.com/img/250707.gif


27kb - View Full Image


 6.This might not be applicable.(Not in my case, probably not in you case

either) Look in the following folder:

        C:\WINDOWS\Downloaded Installations

  You should see one or more sub-folders wih names like:

  {XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX}

 In each sub-folder will be an .MSI file. For each .MSI file, right click

and bring up properties. Look at the Summary tab for indication for

indications that the MSI is an installer for Sun Java.
 If you find any Sun Java .MSIs, delete the sub-folder and the file (not

the main \Downloaded Installations folder).

 7. Delete any folders named thusly in the root of C:
      (Note! This also might not be applicable)

  C:\{XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX}

 8. Reboot
   

 xxxx PLEASE NOTE!!!!   I am not an expert.......so please do not act on this

advice for the moment. Not until there is further input from the much  more

knowledgeable folk in these forums .



Offline Cherubs

  • Full Member
  • ***
  • Posts: 84
    • View Profile
Re: Oh Darn!!! I have the Zlob trojan - HELP Please....
« Reply #67 on: August 14, 2006, 05:32:35 AM »
WOW Tarnak you have done some research and thankyou very very much for doing all this for me - Mwah!!! I still cant believe after 7 days I have everything sorted and back to normal. I was starting to get quite teary this afternoon when my banking wouldn't open. I didn't know what I was going to do next.

 :rose:

Offline winchester73

  • Half a bubble off plumb
  • Administrator
  • Hero Member
  • *****
  • Posts: 7424
  • Liverpool FC - YNWA
    • View Profile
Re: Oh Darn!!! I have the Zlob trojan - HELP Please....
« Reply #68 on: August 14, 2006, 12:21:47 PM »
If you have the strength, post a fresh HJT log for examination ...

Glad things got sorted out.  Sorry it wasn't a quick solution.
Speak softly, but carry a big Winchester ... Winchester Arms Collectors Association member

Offline Cherubs

  • Full Member
  • ***
  • Posts: 84
    • View Profile
Re: Oh Darn!!! I have the Zlob trojan - HELP Please....
« Reply #69 on: August 14, 2006, 10:44:31 PM »
Morning Everyone, well things are running great but here are the results of this mornings ewido scan and this was after deleting these same ones on spybot just prior to running this one. Does this mean that spybot never got rid of them???

---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

 + Created at:   9:27:22 AM 15/08/2006

 + Scan result:   



C:\Documents and Settings\Owner\Cookies\owner@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
:mozilla.53:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\q0xcam27.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.45:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\q0xcam27.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.21:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\q0xcam27.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.29:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\q0xcam27.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.36:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\q0xcam27.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.70:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\q0xcam27.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.32:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\q0xcam27.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.33:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\q0xcam27.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.34:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\q0xcam27.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.35:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\q0xcam27.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.68:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\q0xcam27.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.69:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\q0xcam27.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.19:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\q0xcam27.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.20:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\q0xcam27.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
C:\Documents and Settings\Owner\Cookies\owner@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Owner\Cookies\owner@serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.74:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\q0xcam27.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.


::Report end


Offline Cherubs

  • Full Member
  • ***
  • Posts: 84
    • View Profile
Re: Oh Darn!!! I have the Zlob trojan - HELP Please....
« Reply #70 on: August 14, 2006, 10:49:57 PM »
Hijack log taken just now....

Logfile of HijackThis v1.99.1
Scan saved at 9:51:03 AM, on 15/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\system32\sistray.EXE
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMon.exe
C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DTskbr.exe
C:\Program Files\Middleware\CmSkype.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\tsnp2std.exe
C:\WINDOWS\vsnp2std.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ntvdm.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMemCrdMgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.ninemsn.com.au/0SEENAU/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ninemsn.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [PDUiP6000DMon] C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMon.exe
O4 - HKLM\..\Run: [PDUiP6000DTskbr] C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DTskbr.exe
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [CmSkype] "C:\Program Files\Middleware\CmSkype.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Event Minder Reminders.lnk = C:\HALLMARK\EMREMIND.EXE
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: ! Snipeville.Com - http://www.snipeville.com/ebay_add2.php
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edgesuite.net/dlmanager/versions/activex/dlm-activex-2.0.2.7.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-24.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://littlecherubs.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/download/scanner/wlscbase5059.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1131964732390
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O16 - DPF: {FE8400F2-C848-4379-989F-DF2ED39040BE} (Eyeball Instant Messaging Control) - http://www.rsvp.com.au/chat/RSVPChat.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: ,
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Canon PIXMA iP6000D Memory Card Manager (PDUiP6000DMemCrdMgr) - CANON INC. - C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMemCrdMgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe


Offline normmork

  • LandzDown Team
  • Hero Member
  • *****
  • Posts: 518
    • View Profile
Re: Oh Darn!!! I have the Zlob trojan - HELP Please....
« Reply #71 on: August 15, 2006, 07:56:45 PM »
To answer one of your questions this line
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

Starts
Windows Genuine Advantage Validation Tool

for more info see here
http://support.microsoft.com/?kbid=921914

Offline SpiritWind

  • Full Member
  • ***
  • Posts: 81
    • View Profile
Cookie "Remover"
« Reply #72 on: August 16, 2006, 02:18:54 AM »
 :D  Hi Cherubs :

      That's quite a "collection" of cookies Ewido found; do not know if you "save" any
      of your cookies, but if you do not, consider using antiSPYWARE Expert "ATribune"
      "ATF Cleaner" available from http://www.atribune.org/content/view/19/2/ .
       It can easily rid you of both IE AND Firefox cookies .
For the BEST in what counts in Life :

www.tacf.org