Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Bho.m


  • This topic is locked This topic is locked
7 replies to this topic

#1 Poppi

Poppi

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:02:10 PM

Posted 21 July 2008 - 08:52 PM

Hello,
Shame on me for opening a trojan. I have been receiving pop-up notifications from AVG 8 stating that BHO.M has been executed through svchost.exe. I attempted to remove it from the registry to no avail. Please help.

I tried a kapersky scan however it failed; a recent full scan (post-infection) from AVG found and removed several threats - see log below the DSS log. I have to go now, my wife is yelling at me.

Thank you,
James

Deckard's System Scanner v20071014.68
Run by James on 2008-07-21 21:36:11
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
111: 2008-07-22 01:36:20 UTC - RP111 - Deckard's System Scanner Restore Point
110: 2008-07-21 01:20:45 UTC - RP110 - System Checkpoint
109: 2008-07-20 01:02:47 UTC - RP109 - System Checkpoint
108: 2008-07-18 20:04:25 UTC - RP108 - System Checkpoint
107: 2008-07-16 02:01:14 UTC - RP107 - System Checkpoint


-- First Restore Point --
1: 2008-05-28 02:24:55 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-07-21 21:40:00
Platform: Windows XP Service Pack 3 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Wireless-G Portable USB Adapter\WLService.exe
C:\Program Files\Wireless-G Portable USB Adapter\WUSB54GP.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgemc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\ViStart\ViStart.exe
C:\Program Files\Vista Sidebar\sidebar.exe
C:\Program Files\ViOrb\ViOrb.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files\TrueTransparency\TrueTransparency.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\James\Desktop\dss.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?wl=true
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {4AD3A71E-8ED4-40F5-9A81-69245BDCBB75} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\smax4.exe" /tray
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [ViStart] C:\Program Files\ViStart\ViStart.exe
O4 - HKCU\..\Run: [Vista Sidebar] C:\Program Files\Vista Sidebar\sidebar.exe
O4 - HKCU\..\Run: [ViOrb] C:\Program Files\ViOrb\ViOrb.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LClock] C:\Program Files\LClock\LClock.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [TrueTransparency] "C:\Program Files\TrueTransparency\TrueTransparency.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1211974707734
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: AtiExtEvent - C:\WINDOWS\system32\
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Nero BackItUp Scheduler 3 - Unknown owner - C:\Program Files\Nero\Nero8\Nero
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WUSB54GPSVC - GEMTEKS - C:\Program Files\Wireless-G Portable USB Adapter\WLService.exe


--
End of file - 12206 bytes

-- File Associations -----------------------------------------------------------

.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*
.js - jsfile - DefaultIcon - "C:\Program Files\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe",7
.js - jsfile - shell\open\command - "C:\Program Files\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe","%1"


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R2 atksgt - c:\windows\system32\drivers\atksgt.sys
R2 lirsgt - c:\windows\system32\drivers\lirsgt.sys
R3 GTNDIS5 (GTNDIS5 NDIS Protocol Driver) - c:\windows\system32\gtndis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
R3 pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
R3 pgfilter - c:\program files\peerguardian2\pgfilter.sys

S3 AEAudio (AE Audio Service) - c:\windows\system32\drivers\aeaudio.sys (file missing)
S3 ATIAVAIW (ATI T200 Unified AVStream service) - c:\windows\system32\drivers\atinavt2.sys <Not Verified; ATI Technologies Inc.; ATI AVStream>
S3 SenFiltService (SenFilt Service) - c:\windows\system32\drivers\senfilt.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Nero BackItUp Scheduler 3 - c:\program files\nero\nero8\nero backitup\nbservice.exe
R3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>

S4 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>


-- Device Manager: Disabled ----------------------------------------------------

Class GUID:
Description: SM Bus Controller
Device ID: PCI\VEN_10DE&DEV_0368&SUBSYS_82391043&REV_A2\3&2411E6FE&0&09
Manufacturer:
Name: SM Bus Controller
PNP Device ID: PCI\VEN_10DE&DEV_0368&SUBSYS_82391043&REV_A2\3&2411E6FE&0&09
Service:


-- Files created between 2008-06-21 and 2008-07-21 -----------------------------

2008-07-17 22:13:57 0 d-------- C:\Documents and Settings\All Users\Application Data\vsosdk
2008-07-17 20:45:26 47360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2008-07-17 20:45:26 0 d-------- C:\Documents and Settings\James\Application Data\Vso
2008-07-17 20:45:26 47360 --a------ C:\Documents and Settings\James\Application Data\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2008-07-17 20:45:20 217127 --a------ C:\WINDOWS\system32\drv43260.dll <Not Verified; RealNetworks, Inc.; RealVideo 9 (32-bit)>
2008-07-17 20:45:20 208935 --a------ C:\WINDOWS\system32\drv33260.dll <Not Verified; RealNetworks, Inc.; RealVideo 8 (32-bit)>
2008-07-17 20:45:19 626688 --a------ C:\WINDOWS\system32\vp7vfw.dll <Not Verified; On2.com; On2_VP70>
2008-07-17 20:45:19 176165 --a------ C:\WINDOWS\system32\drv23260.dll <Not Verified; RealNetworks, Inc.; RealVideo G2 (32-bit)>
2008-07-17 20:45:19 65602 --a------ C:\WINDOWS\system32\cook3260.dll <Not Verified; RealNetworks, Inc.; RealPlayer 10>
2008-07-17 20:45:18 0 d-------- C:\Program Files\VSO
2008-07-17 20:35:00 0 d-------- C:\Program Files\Avi2Dvd
2008-07-14 21:25:19 98304 --a------ C:\WINDOWS\system32\CmdLineExt.dll <Not Verified; Sony DADC Austria AG.; >
2008-07-14 21:22:59 0 d-------- C:\Documents and Settings\James\Application Data\InstallShield Installation Information
2008-07-08 09:50:57 271360 --a------ C:\WINDOWS\system32\drivers\atksgt.sys
2008-07-08 09:50:56 18048 --a------ C:\WINDOWS\system32\drivers\lirsgt.sys
2008-07-07 10:57:37 408576 --a------ C:\WINDOWS\system32\Smab.dll
2008-07-07 10:57:33 70656 --a------ C:\WINDOWS\system32\yv12vfw.dll <Not Verified; www.helixcommunity.org; Helix YV12 YUV Codec>
2008-07-07 10:57:33 27648 --a------ C:\WINDOWS\system32\AVSredirect.dll
2008-07-07 10:57:33 66560 --a------ C:\WINDOWS\MOTA113.exe
2008-07-07 10:57:32 70656 --a------ C:\WINDOWS\system32\i420vfw.dll <Not Verified; www.helixcommunity.org; Helix I420 YUV Codec>
2008-07-07 10:57:28 217073 --a------ C:\WINDOWS\meta4.exe
2008-07-07 10:57:28 0 d-------- C:\Program Files\AviSynth 2.5
2008-07-07 10:57:19 27648 ---hs---- C:\WINDOWS\system32\Smab0.dll
2008-07-07 10:57:19 31232 -r-hs---- C:\WINDOWS\system32\msfDX.dll <Not Verified; Hans Mayerl; msfDX.dll>
2008-07-07 10:57:19 163328 -r-hs---- C:\WINDOWS\system32\flvDX.dll <Not Verified; Gabest; FLV Splitter>
2008-07-07 10:57:16 0 d-------- C:\Program Files\eRightSoft
2008-07-07 08:18:40 0 d-------- C:\Documents and Settings\Cara\Application Data\Logitech
2008-07-06 21:00:59 0 d-------- C:\Documents and Settings\All Users\Application Data\LogiShrd
2008-07-06 21:00:37 0 d-------- C:\Documents and Settings\James\Application Data\Logitech
2008-07-06 20:58:27 0 d-------- C:\Program Files\Common Files\Logishrd
2008-07-06 20:58:26 0 d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2008-07-06 20:58:20 0 d-------- C:\Program Files\Logitech
2008-07-03 18:44:32 0 d-------- C:\Documents and Settings\James\Application Data\Google
2008-07-03 18:39:59 0 d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-07-03 18:39:55 0 d-------- C:\Program Files\Google
2008-07-01 22:33:11 0 d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-06-26 08:43:54 0 d-------- C:\Program Files\MSXML 4.0


-- Find3M Report ---------------------------------------------------------------

2008-07-21 21:40:42 0 d-------- C:\Documents and Settings\James\Application Data\uTorrent
2008-07-21 21:40:34 0 d-------- C:\Program Files\PeerGuardian2
2008-07-21 20:16:18 0 d-------- C:\Program Files\Mozilla Thunderbird
2008-07-21 20:02:07 0 d-------- C:\Program Files\ViStart
2008-07-17 20:45:49 63 --a------ C:\Documents and Settings\James\Application Data\vso_ts_preview.xml
2008-07-17 20:45:36 34 --a------ C:\Documents and Settings\James\Application Data\pcouffin.log
2008-07-17 20:45:26 1144 --a------ C:\Documents and Settings\James\Application Data\pcouffin.inf
2008-07-17 20:45:26 7887 --a------ C:\Documents and Settings\James\Application Data\pcouffin.cat
2008-07-14 19:36:14 0 d-------- C:\Program Files\Winamp
2008-07-14 19:35:41 0 d-------- C:\Documents and Settings\James\Application Data\Winamp
2008-07-11 18:08:53 0 d-------- C:\Documents and Settings\James\Application Data\Adobe
2008-07-11 14:13:35 0 d-------- C:\Program Files\Common Files\Adobe
2008-07-08 09:45:22 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-07-06 20:58:27 0 d-------- C:\Program Files\Common Files
2008-07-06 20:55:15 8 --a------ C:\WINDOWS\system32\nvModes.dat
2008-06-17 19:57:58 0 d-------- C:\Program Files\OpenAL
2008-06-14 20:16:37 0 d-------- C:\Program Files\Common Files\InstallShield
2008-06-10 16:08:57 0 d-------- C:\Program Files\Common Files\Ulead Systems
2008-06-10 16:08:19 0 d-------- C:\Program Files\Windows Media Components
2008-06-10 16:07:56 0 d-------- C:\Documents and Settings\James\Application Data\Ulead Systems
2008-06-10 16:06:49 0 d-------- C:\Program Files\Ulead Systems
2008-06-09 14:47:38 0 d-------- C:\Program Files\AC3Filter
2008-06-09 14:46:23 0 d-------- C:\Program Files\AC3File
2008-06-06 18:20:48 0 d-------- C:\Documents and Settings\James\Application Data\Ubisoft
2008-06-06 12:19:19 0 d-------- C:\Program Files\Xvid
2008-06-02 17:52:09 0 d-------- C:\Program Files\DAEMON Tools Lite
2008-06-01 22:52:53 218624 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-06-01 22:47:27 0 d-------- C:\Documents and Settings\James\Application Data\ViStart
2008-06-01 22:46:44 0 d-------- C:\Program Files\Vista Sidebar
2008-06-01 21:00:23 0 d-------- C:\Documents and Settings\James\Application Data\Styler
2008-06-01 21:00:08 0 d-------- C:\Program Files\WinFlip
2008-06-01 21:00:08 0 d-------- C:\Program Files\TrueTransparency
2008-06-01 21:00:07 0 d-------- C:\Program Files\VisualTooltip
2008-06-01 21:00:07 0 d-------- C:\Program Files\ViOrb
2008-06-01 21:00:06 0 d-------- C:\Program Files\Styler
2008-06-01 21:00:05 0 d-------- C:\Program Files\LClock
2008-06-01 09:22:31 0 d-------- C:\Documents and Settings\James\Application Data\Sun
2008-06-01 09:22:10 0 d-------- C:\Program Files\Java
2008-06-01 09:21:18 0 d-------- C:\Program Files\Common Files\Java
2008-05-31 16:28:22 0 d-------- C:\Program Files\Creative
2008-05-31 16:27:28 0 d-------- C:\Documents and Settings\James\Application Data\Creative
2008-05-30 16:36:56 0 d-------- C:\Program Files\Analog Devices
2008-05-30 15:30:11 0 d-------- C:\Program Files\Driver Cleaner Pro
2008-05-30 14:41:44 0 d-------- C:\Program Files\Bonjour
2008-05-30 14:32:10 0 d-------- C:\Documents and Settings\James\Application Data\Canon
2008-05-29 13:06:04 0 d-------- C:\Documents and Settings\James\Application Data\InstallShield
2008-05-28 17:44:36 0 d-------- C:\Program Files\Windows Live
2008-05-28 17:40:35 0 d-------- C:\Program Files\uTorrent
2008-05-28 17:25:43 0 d-------- C:\Documents and Settings\James\Application Data\Nero
2008-05-28 17:24:54 0 d-------- C:\Program Files\Common Files\Nero
2008-05-28 17:23:31 0 d-------- C:\Program Files\Nero
2008-05-28 17:09:24 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-05-28 17:09:19 0 d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-05-28 16:23:35 0 d-------- C:\Documents and Settings\James\Application Data\Mozilla
2008-05-28 16:23:33 0 d-------- C:\Documents and Settings\James\Application Data\Thunderbird
2008-05-28 16:22:57 0 d-------- C:\Program Files\Common Files\Macrovision Shared
2008-05-28 15:59:17 0 d-------- C:\Program Files\Wireless-G Portable USB Adapter
2008-05-28 15:55:02 0 d-------- C:\Documents and Settings\James\Application Data\ATI
2008-05-28 09:42:00 0 d-------- C:\Program Files\Messenger
2008-05-28 09:41:47 0 d-------- C:\Program Files\Movie Maker
2008-05-28 09:39:51 0 d-------- C:\Program Files\Windows NT
2008-05-28 09:15:51 0 d--h----- C:\Program Files\CanonBJ
2008-05-28 08:24:21 0 d-------- C:\Documents and Settings\James\Application Data\WinRAR
2008-05-28 07:48:09 0 d-------- C:\Documents and Settings\James\Application Data\Macromedia
2008-05-28 07:48:05 1169 --a------ C:\WINDOWS\mozver.dat
2008-05-28 07:46:19 0 d-------- C:\Program Files\Microsoft Works
2008-05-28 07:46:09 0 d-------- C:\Program Files\MSBuild
2008-05-28 07:45:17 0 d-------- C:\Program Files\Microsoft.NET
2008-05-28 07:43:57 0 d-------- C:\Program Files\Microsoft Visual Studio 8
2008-05-27 23:22:18 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-05-27 23:07:03 0 d-------- C:\Program Files\Windows Media Connect 2
2008-05-27 22:57:18 0 d-------- C:\Documents and Settings\James\Application Data\DAEMON Tools
2008-05-27 22:48:12 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-27 22:45:40 0 d-------- C:\Program Files\AVG
2008-05-27 22:24:45 0 d-------- C:\Documents and Settings\James\Application Data\Identities
2008-05-27 22:20:29 0 d-------- C:\Program Files\microsoft frontpage
2008-05-27 22:20:21 0 -rahs---- C:\MSDOS.SYS
2008-05-27 22:20:21 0 -rahs---- C:\IO.SYS
2008-05-27 22:20:21 0 --a------ C:\CONFIG.SYS
2008-05-27 22:20:21 0 --a------ C:\AUTOEXEC.BAT
2008-05-27 22:19:21 0 d--h----- C:\Program Files\WindowsUpdate
2008-05-27 22:18:28 0 d-------- C:\Program Files\Common Files\MSSoap
2008-05-27 22:17:54 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-05-27 22:17:19 0 d-------- C:\Program Files\Online Services
2008-05-27 22:17:10 0 d-------- C:\Program Files\MSN Gaming Zone
2008-05-27 18:06:47 0 d-------- C:\Program Files\Common Files\ODBC
2008-05-27 18:06:45 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-05-27 18:06:20 62 --ahs---- C:\Documents and Settings\James\Application Data\desktop.ini
2008-05-02 22:46:00 1630208 --a------ C:\WINDOWS\system32\nwiz.exe
2008-05-02 22:46:00 1019904 --a------ C:\WINDOWS\system32\nvwimg.dll
2008-05-02 22:46:00 1703936 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
2008-05-02 22:46:00 466944 --a------ C:\WINDOWS\system32\nvshell.dll
2008-05-02 22:46:00 1486848 --a------ C:\WINDOWS\system32\nview.dll
2008-05-02 22:46:00 1339392 --a------ C:\WINDOWS\system32\nvdspsch.exe
2008-05-02 22:46:00 442368 --a------ C:\WINDOWS\system32\nvappbar.exe
2008-05-02 22:46:00 425984 --a------ C:\WINDOWS\system32\keystone.exe
2008-04-27 10:35:28 180224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-04-27 10:33:36 765952 --a------ C:\WINDOWS\system32\xvidcore.dll


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4AD3A71E-8ED4-40F5-9A81-69245BDCBB75}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [25/03/2008 04:28 AM]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" []
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\smax4.exe" [10/04/2006 09:19 AM]
"nwiz"="nwiz.exe" [02/05/2008 10:46 PM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [02/05/2008 10:46 PM]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [02/05/2008 10:46 PM]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [01/03/2007 02:57 PM]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [20/09/2007 08:51 AM]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [24/08/2007 07:00 AM]
"CTxfiHlp"="CTXFIHLP.EXE" [11/08/2006 02:56 PM C:\WINDOWS\system32\CTXFIHLP.EXE]
"CTHelper"="CTHELPER.EXE" [11/08/2006 02:56 PM C:\WINDOWS\CTHELPER.EXE]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [03/07/2008 11:55 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/01/2008 10:16 PM]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [11/01/2008 07:54 PM]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [29/02/2008 03:12 AM C:\WINDOWS\KHALMNPR.Exe]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [18/09/2005 06:40 PM]
"ViStart"="C:\Program Files\ViStart\ViStart.exe" [26/11/2007 07:27 PM]
"Vista Sidebar"="C:\Program Files\Vista Sidebar\sidebar.exe" [20/11/2007 01:51 PM]
"ViOrb"="C:\Program Files\ViOrb\ViOrb.exe" [19/11/2007 01:01 PM]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [06/06/2008 11:30 AM]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [13/04/2008 08:12 PM]
"LClock"="C:\Program Files\LClock\LClock.exe" [20/09/2004 01:27 AM]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [23/10/2007 02:18 PM]
"TrueTransparency"="C:\Program Files\TrueTransparency\TrueTransparency.exe" [28/10/2007 04:44 PM]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [01/04/2008 05:39 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [13/04/2008 08:12 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [06/07/2008 8:58:43 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll 02/05/2008 02:42 AM 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jigsaw]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d55e8af1-30a1-11dd-9d2f-0018f82788c8}]
AutoRun\command- F:\autorun.exe

*Newly Created Service* - PGFILTER



-- End of Deckard's System Scanner: finished at 2008-07-21 21:41:25 ------------

"Scan ""Scan whole computer"" was finished."
"Infections found:;""13"""
"Infected objects removed or healed:;""13"""
"Not removed or healed:;""0"""
"Spyware found:;""2"""
"Spyware removed:;""2"""
"Not removed:;""0"""
"Warnings count:;""368"""
"Information count:;""0"""
"Scan started:;""July 18, 2008, 3:37:12 PM"""
"Scan finished:;""July 18, 2008, 5:22:30 PM (1 hour(s) 45 minute(s) 17 second(s))"""
"Total object scanned:;""1061397"""
"User who launched the scan:;""James"""

Infections
"File;""Infection"";""Result"""
"C:\WINDOWS\system32\iexp_f.dll;""Trojan horse BHO.M"";""Moved to Virus Vault"""
"C:\WINDOWS\BotDuHomo.exe;""Trojan horse BackDoor.Delf.BRW"";""Moved to Virus Vault"""
"C:\RECYCLER\S-1-5-21-1417001333-776561741-839522115-1004\Dc2.EXE:\SOFTWA~1.EXE;""Trojan horse Generic_c.NEQ"";""Moved to Virus Vault"""
"C:\RECYCLER\S-1-5-21-1417001333-776561741-839522115-1004\Dc2.EXE;""Trojan horse Generic_c.NEQ"";""Moved to Virus Vault"""

Spyware
"File;""Infection"";""Result"""
"C:\RECYCLER\S-1-5-21-1417001333-776561741-839522115-1004\Dc2.EXE:\ACROBA~1.EXE;""Potentially harmful program Crack.A"";""Moved to Virus Vault"""

Warnings
"File;""Infection"";""Result"""
"D:\Documents and Settings\james\Cookies\james@tribalfusion[1].txt:\tribalfusion.com.dcc03271;""Found Tracking cookie.Tribalfusion"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@tribalfusion[1].txt;""Found Tracking cookie.Tribalfusion"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@tacoda[2].txt:\tacoda.net.ed9c50d1;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@tacoda[2].txt:\tacoda.net.e9f57f8;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@tacoda[2].txt:\tacoda.net.cd7ce44f;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@tacoda[2].txt:\tacoda.net.27341d57;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@tacoda[2].txt:\tacoda.net.c4fe2ebb;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@tacoda[2].txt:\tacoda.net.5935e89;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@tacoda[2].txt;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@statcounter[1].txt:\statcounter.com.c930bcd8;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@statcounter[1].txt;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@sextracker[1].txt:\sextracker.com.aafa528;""Found Tracking cookie.Sextracker"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@sextracker[1].txt;""Found Tracking cookie.Sextracker"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@serving-sys[2].txt:\serving-sys.com.c9034af6;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@serving-sys[2].txt:\serving-sys.com.6a1cf9e8;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@serving-sys[2].txt:\serving-sys.com.606c3d3b;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@serving-sys[2].txt:\serving-sys.com.4b416ef8;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@serving-sys[2].txt:\serving-sys.com.400f83f;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@serving-sys[2].txt:\serving-sys.com.255d6f2f;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@serving-sys[2].txt;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@realmedia[1].txt:\realmedia.com.b52d3543;""Found Tracking cookie.Realmedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@realmedia[1].txt:\realmedia.com.68087763;""Found Tracking cookie.Realmedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@realmedia[1].txt;""Found Tracking cookie.Realmedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@questionmarket[1].txt:\questionmarket.com.4dd5e426;""Found Tracking cookie.Questionmarket"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@questionmarket[1].txt:\questionmarket.com.3eb5a9f1;""Found Tracking cookie.Questionmarket"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@questionmarket[1].txt;""Found Tracking cookie.Questionmarket"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@overture[1].txt:\overture.com.8e32a996;""Found Tracking cookie.Overture"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@overture[1].txt;""Found Tracking cookie.Overture"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@msnportal.112.2o7[1].txt:\msnportal.112.2o7.net.7225be6f;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@msnportal.112.2o7[1].txt;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@mediaplex[1].txt:\mediaplex.com.f652b123;""Found Tracking cookie.Mediaplex"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@mediaplex[1].txt;""Found Tracking cookie.Mediaplex"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@m.webtrends[1].txt:\m.webtrends.com.b4ca7df0;""Found Tracking cookie.Webtrends"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@m.webtrends[1].txt;""Found Tracking cookie.Webtrends"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@doubleclick[1].txt:\doubleclick.net.bf396750;""Found Tracking cookie.Doubleclick"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@doubleclick[1].txt;""Found Tracking cookie.Doubleclick"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@casalemedia[2].txt:\casalemedia.com.987e6b46;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@casalemedia[2].txt:\casalemedia.com.837115b5;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@casalemedia[2].txt:\casalemedia.com.1773afc;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@casalemedia[2].txt:\casalemedia.com.80ad4799;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@casalemedia[2].txt;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@bs.serving-sys[1].txt:\bs.serving-sys.com.5bf1f00f;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@bs.serving-sys[1].txt;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@bluestreak[2].txt:\bluestreak.com.bf396750;""Found Tracking cookie.Bluestreak"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@bluestreak[2].txt;""Found Tracking cookie.Bluestreak"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@atdmt[2].txt:\atdmt.com.b3e33b5f;""Found Tracking cookie.Atdmt"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@atdmt[2].txt;""Found Tracking cookie.Atdmt"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@2o7[1].txt:\2o7.net.56064d56;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@2o7[1].txt:\2o7.net.484dbb69;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@2o7[1].txt:\2o7.net.363ae34d;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@2o7[1].txt:\2o7.net.1913101d;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@2o7[1].txt:\2o7.net.2ce4dba7;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Cookies\james@2o7[1].txt;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\zedo.com.ff8ec9c0;""Found Tracking cookie.Zedo"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\zedo.com.f462b69f;""Found Tracking cookie.Zedo"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\zedo.com.f1d14556;""Found Tracking cookie.Zedo"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\zedo.com.c1dd09f2;""Found Tracking cookie.Zedo"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\zedo.com.a5b6a132;""Found Tracking cookie.Zedo"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\zedo.com.14a38114;""Found Tracking cookie.Zedo"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\tribalfusion.com.dcc03271;""Found Tracking cookie.Tribalfusion"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\statse.webtrendslive.com.b4ca7df0;""Found Tracking cookie.Webtrendslive"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\statcounter.com.c372f651;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\statcounter.com.9317e332;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\statcounter.com.8232a5b9;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\statcounter.com.765a3604;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\statcounter.com.4e32e634;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\statcounter.com.15761e60;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\pro-market.net.bbf67f2d;""Found Tracking cookie.Pro-market"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\zedo.com.775ee79c;""Found Tracking cookie.Zedo"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\tacoda.net.e9f57f8;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\tacoda.net.d323296e;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\tacoda.net.c4fe2ebb;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\tacoda.net.a3218a37;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\tacoda.net.5935e89;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\tacoda.net.27341d57;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\statcounter.com.ebee9bfc;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\statcounter.com.e3437d5a;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\statcounter.com.d5c7c140;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\statcounter.com.c930bcd8;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\statcounter.com.3b10fd11;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\serving-sys.com.c9034af6;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\pro-market.net.1d1ba569;""Found Tracking cookie.Pro-market"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\perf.overture.com.610ef18d;""Found Tracking cookie.Overture"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\hitbox.com.bbf2a6e8;""Found Tracking cookie.Hitbox"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\serving-sys.com.6a1cf9e8;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\serving-sys.com.606c3d3b;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\serving-sys.com.400f83f;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\serving-sys.com.255d6f2f;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\questionmarket.com.4dd5e426;""Found Tracking cookie.Questionmarket"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\questionmarket.com.3eb5a9f1;""Found Tracking cookie.Questionmarket"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\msnportal.112.2o7.net.7225be6f;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\hitbox.com.2b95f8a3;""Found Tracking cookie.Hitbox"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\serving-sys.com.4b416ef8;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\revsci.net.f1b6b2e;""Found Tracking cookie.Revsci"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\revsci.net.e9dbeb91;""Found Tracking cookie.Revsci"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\revsci.net.ad03f175;""Found Tracking cookie.Revsci"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\revsci.net.55564293;""Found Tracking cookie.Revsci"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\revsci.net.44927ec;""Found Tracking cookie.Revsci"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\revsci.net.3f4566dd;""Found Tracking cookie.Revsci"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\revsci.net.2df99d79;""Found Tracking cookie.Revsci"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\realmedia.com.855b46d;""Found Tracking cookie.Realmedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\realmedia.com.68087763;""Found Tracking cookie.Realmedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\overture.com.e626e6be;""Found Tracking cookie.Overture"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\overture.com.8e32a996;""Found Tracking cookie.Overture"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\mediaplex.com.f652b123;""Found Tracking cookie.Mediaplex"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\fastclick.net.fac3d6f0;""Found Tracking cookie.Fastclick"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\fastclick.net.9b41aa53;""Found Tracking cookie.Fastclick"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\fastclick.net.8a6435e9;""Found Tracking cookie.Fastclick"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\fastclick.net.57e8da10;""Found Tracking cookie.Fastclick"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\advertising.com.b624fa46;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\doubleclick.net.bf396750;""Found Tracking cookie.Doubleclick"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\casalemedia.com.f31be13a;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\casalemedia.com.987e6b46;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\casalemedia.com.837115b5;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\casalemedia.com.80ad4799;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\casalemedia.com.6a12b080;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\casalemedia.com.5e43734d;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\casalemedia.com.3a28db8d;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\bs.serving-sys.com.5bf1f00f;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\casalemedia.com.1d158016;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\casalemedia.com.1773afc;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\burstnet.com.c4fe2ebb;""Found Tracking cookie.Burstnet"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\burstnet.com.27341d57;""Found Tracking cookie.Burstnet"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\bluestreak.com.bf396750;""Found Tracking cookie.Bluestreak"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\advertising.com.f62113d5;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\advertising.com.525a5fb9;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\advertising.com.300627d2;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\advertising.com.203aa218;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\advertising.com.1820df7a;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\atdmt.com.b3e33b5f;""Found Tracking cookie.Atdmt"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\adtech.de.a9245469;""Found Tracking cookie.Adtech"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\ad.yieldmanager.com.e762f029;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\ad.yieldmanager.com.b68f2b7b;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\ad.yieldmanager.com.b4be891c;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\ad.yieldmanager.com.ff92306;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\ad.yieldmanager.com.8a47878;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\ad.yieldmanager.com.830b6f08;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\ad.yieldmanager.com.557bf2b0;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\ad.yieldmanager.com.539b0606;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\adopt.euroclick.com.ffe11db7;""Found Tracking cookie.Euroclick"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\adopt.euroclick.com.fb764ef7;""Found Tracking cookie.Euroclick"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\adopt.euroclick.com.8b1bd7bc;""Found Tracking cookie.Euroclick"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\adopt.euroclick.com.891542da;""Found Tracking cookie.Euroclick"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\adopt.euroclick.com.6d7740f7;""Found Tracking cookie.Euroclick"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\adopt.euroclick.com.17044b51;""Found Tracking cookie.Euroclick"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.f57f2f12;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.f203d064;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.ecb56449;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.ec4774bb;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.e91b21fd;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.d3932de8;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\adbrite.com.e3b6fcdd;""Found Tracking cookie.Adbrite"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\adbrite.com.d5e309c2;""Found Tracking cookie.Adbrite"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\adbrite.com.71beeff9;""Found Tracking cookie.Adbrite"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\adbrite.com.557c9f74;""Found Tracking cookie.Adbrite"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.d2aa96c8;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.b1591954;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.a5c62fe;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.a577e925;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.937bd571;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.92b4d8ae;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.53eb9837;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.496d4cfc;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.484dbb69;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.4692d914;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.3b7e7590;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.365402;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.1e3121d;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\2o7.net.10220b76;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\247realmedia.com.ef906bac;""Found Tracking cookie.247realmedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\247realmedia.com.d90d45cf;""Found Tracking cookie.247realmedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\247realmedia.com.964cd308;""Found Tracking cookie.247realmedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\247realmedia.com.855b46d;""Found Tracking cookie.247realmedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt:\247realmedia.com.6c43ee6b;""Found Tracking cookie.247realmedia"";""Potentially dangerous object"""
"D:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\ufu42hnk.default\cookies.txt;""Found Tracking cookie.Atdmt"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@sextracker[1].txt:\sextracker.com.aafa528;""Found Tracking cookie.Sextracker"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@sextracker[1].txt:\sextracker.com.5f557e90;""Found Tracking cookie.Sextracker"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@sextracker[1].txt;""Found Tracking cookie.Sextracker"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@questionmarket[2].txt:\questionmarket.com.4dd5e426;""Found Tracking cookie.Questionmarket"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@questionmarket[2].txt:\questionmarket.com.3eb5a9f1;""Found Tracking cookie.Questionmarket"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@questionmarket[2].txt;""Found Tracking cookie.Questionmarket"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@msnportal.112.2o7[1].txt:\msnportal.112.2o7.net.7225be6f;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@msnportal.112.2o7[1].txt;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@m.webtrends[1].txt:\m.webtrends.com.b4ca7df0;""Found Tracking cookie.Webtrends"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@m.webtrends[1].txt;""Found Tracking cookie.Webtrends"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@doubleclick[1].txt:\doubleclick.net.bf396750;""Found Tracking cookie.Doubleclick"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@doubleclick[1].txt;""Found Tracking cookie.Doubleclick"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@casalemedia[1].txt:\casalemedia.com.f31be13a;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@casalemedia[1].txt:\casalemedia.com.987e6b46;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@casalemedia[1].txt:\casalemedia.com.80ad4799;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@casalemedia[1].txt:\casalemedia.com.3a28db8d;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@casalemedia[1].txt:\casalemedia.com.1773afc;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@casalemedia[1].txt;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@atdmt[2].txt:\atdmt.com.b3e33b5f;""Found Tracking cookie.Atdmt"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@atdmt[2].txt;""Found Tracking cookie.Atdmt"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@ad.yieldmanager[1].txt:\ad.yieldmanager.com.ff92306;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@ad.yieldmanager[1].txt:\ad.yieldmanager.com.e762f029;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@ad.yieldmanager[1].txt:\ad.yieldmanager.com.b68f2b7b;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@ad.yieldmanager[1].txt:\ad.yieldmanager.com.8a47878;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@ad.yieldmanager[1].txt:\ad.yieldmanager.com.539b0606;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Cookies\james@ad.yieldmanager[1].txt;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\zedo.com.ff8ec9c0;""Found Tracking cookie.Zedo"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\zedo.com.775ee79c;""Found Tracking cookie.Zedo"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\zedo.com.c1dd09f2;""Found Tracking cookie.Zedo"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\zedo.com.a5b6a132;""Found Tracking cookie.Zedo"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\tacoda.net.d323296e;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\zedo.com.14a38114;""Found Tracking cookie.Zedo"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\tribalfusion.com.dcc03271;""Found Tracking cookie.Tribalfusion"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\tacoda.net.e9f57f8;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\tacoda.net.c4fe2ebb;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\tribalfusion.com.9bc3e98f;""Found Tracking cookie.Tribalfusion"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\tribalfusion.com.8b22ad8c;""Found Tracking cookie.Tribalfusion"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\tribalfusion.com.7610f0e0;""Found Tracking cookie.Tribalfusion"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\tacoda.net.a3218a37;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\tacoda.net.5935e89;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\tacoda.net.27341d57;""Found Tracking cookie.Tacoda"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.da950bdf;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.da43512b;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.b7fcc930;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.99a2a926;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.8ec17;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.765a3604;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.6ddcb8a2;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.6600574d;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statse.webtrendslive.com.b4ca7df0;""Found Tracking cookie.Webtrendslive"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.e170e653;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.e0ebdba8;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.ce08b6c4;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.c930bcd8;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.c5a85c73;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.8ad3a83d;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.75de007;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.3238fbcf;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.261349dc;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\serving-sys.com.c9034af6;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.36271d69;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.2e044bae;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\statcounter.com.1d835b05;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\serving-sys.com.6a1cf9e8;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\serving-sys.com.606c3d3b;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\serving-sys.com.255d6f2f;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\searchportal.information.com.3a8d7204;""Found Tracking cookie.Information"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\msnportal.112.2o7.net.7225be6f;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\mediaplex.com.f652b123;""Found Tracking cookie.Mediaplex"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\revenue.net.bcf44ea1;""Found Tracking cookie.Revenue"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\overture.com.52ca467a;""Found Tracking cookie.Overture"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\mediaplex.com.dc30fb3c;""Found Tracking cookie.Mediaplex"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\serving-sys.com.4b416ef8;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\serving-sys.com.400f83f;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\revsci.net.f1b6b2e;""Found Tracking cookie.Revsci"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\revsci.net.e9dbeb91;""Found Tracking cookie.Revsci"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\revsci.net.d7f89994;""Found Tracking cookie.Revsci"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\revsci.net.44927ec;""Found Tracking cookie.Revsci"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\revsci.net.2df99d79;""Found Tracking cookie.Revsci"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\revsci.net.55564293;""Found Tracking cookie.Revsci"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\revsci.net.26b016c3;""Found Tracking cookie.Revsci"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\mediaplex.com.323e9a10;""Found Tracking cookie.Mediaplex"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\media.adrevolver.com.5fed601d;""Found Tracking cookie.Adrevolver"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\media.adrevolver.com.57f415b5;""Found Tracking cookie.Adrevolver"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\media.adrevolver.com.539b0606;""Found Tracking cookie.Adrevolver"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\media.adrevolver.com.2be00b0;""Found Tracking cookie.Adrevolver"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\m.webtrends.com.b4ca7df0;""Found Tracking cookie.Webtrends"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\fastclick.net.8dd1284a;""Found Tracking cookie.Fastclick"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\hitbox.com.bbf2a6e8;""Found Tracking cookie.Hitbox"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\hitbox.com.2b95f8a3;""Found Tracking cookie.Hitbox"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\fastclick.net.9b41aa53;""Found Tracking cookie.Fastclick"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\fastclick.net.6fd479aa;""Found Tracking cookie.Fastclick"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\fastclick.net.57e8da10;""Found Tracking cookie.Fastclick"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\burstnet.com.a3218a37;""Found Tracking cookie.Burstnet"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\fastclick.net.8a6435e9;""Found Tracking cookie.Fastclick"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\doubleclick.net.bf396750;""Found Tracking cookie.Doubleclick"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\adrevolver.com.f6cfcad4;""Found Tracking cookie.Adrevolver"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\adrevolver.com.b595d4db;""Found Tracking cookie.Adrevolver"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\burstnet.com.c4fe2ebb;""Found Tracking cookie.Burstnet"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\adrevolver.com.9b9d670a;""Found Tracking cookie.Adrevolver"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\adrevolver.com.4a719aa9;""Found Tracking cookie.Adrevolver"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\burstnet.com.27341d57;""Found Tracking cookie.Burstnet"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\bs.serving-sys.com.5bf1f00f;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\adopt.euroclick.com.891542da;""Found Tracking cookie.Euroclick"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\adopt.euroclick.com.6d7740f7;""Found Tracking cookie.Euroclick"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\ad.yieldmanager.com.ff92306;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\adopt.euroclick.com.fb764ef7;""Found Tracking cookie.Euroclick"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\adbrite.com.d5e309c2;""Found Tracking cookie.Adbrite"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\adbrite.com.71beeff9;""Found Tracking cookie.Adbrite"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\ad.yieldmanager.com.b68f2b7b;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\ad.yieldmanager.com.b4be891c;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\ad.yieldmanager.com.830b6f08;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\ad.yieldmanager.com.539b0606;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.ec4774bb;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.ca30b7c8;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.c03e4f6e;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.bfc1e5d3;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\adbrite.com.557c9f74;""Found Tracking cookie.Adbrite"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\ad.yieldmanager.com.557bf2b0;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.f1e9f3c1;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.940397cf;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.93af4fad;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\casalemedia.com.f31be13a;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\casalemedia.com.987e6b46;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\casalemedia.com.837115b5;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\casalemedia.com.80ad4799;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\casalemedia.com.6a12b080;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\casalemedia.com.5e43734d;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\casalemedia.com.3a28db8d;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\casalemedia.com.1d158016;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\casalemedia.com.1773afc;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\atdmt.com.b3e33b5f;""Found Tracking cookie.Atdmt"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\advertising.com.f62113d5;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\advertising.com.f2015b9;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\advertising.com.b624fa46;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\advertising.com.aad0e154;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\advertising.com.724f0b9b;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\advertising.com.525a5fb9;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\advertising.com.4a9f5b77;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\advertising.com.a6a7b9c3;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\advertising.com.2715ba2c;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\advertising.com.203aa218;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\advertising.com.1820df7a;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.c2246861;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.8777f6c6;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.8172ef48;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.7969262e;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.7919062b;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.7815c7ab;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.50ba3882;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.484dbb69;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.3a0e6e11;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.23a940be;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.1913101d;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\2o7.net.10220b76;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\247realmedia.com.964cd308;""Found Tracking cookie.247realmedia"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt:\247realmedia.com.855b46d;""Found Tracking cookie.247realmedia"";""Potentially dangerous object"""
"C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\d5vo6zte.default\cookies.txt;""Found Tracking cookie.Yieldmanager"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\statcounter.com.382e28f;""Found Tracking cookie.Statcounter"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\serving-sys.com.c9034af6;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\serving-sys.com.6a1cf9e8;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\serving-sys.com.606c3d3b;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\serving-sys.com.4b416ef8;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\serving-sys.com.400f83f;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\serving-sys.com.255d6f2f;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\questionmarket.com.4dd5e426;""Found Tracking cookie.Questionmarket"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\questionmarket.com.3eb5a9f1;""Found Tracking cookie.Questionmarket"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\overture.com.8e32a996;""Found Tracking cookie.Overture"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\mediaplex.com.f652b123;""Found Tracking cookie.Mediaplex"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\msnportal.112.2o7.net.7225be6f;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\hitbox.com.2b95f8a3;""Found Tracking cookie.Hitbox"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\doubleclick.net.bf396750;""Found Tracking cookie.Doubleclick"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\casalemedia.com.987e6b46;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\casalemedia.com.80ad4799;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\casalemedia.com.6a12b080;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\casalemedia.com.5e43734d;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\casalemedia.com.1773afc;""Found Tracking cookie.Casalemedia"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\bs.serving-sys.com.5bf1f00f;""Found Tracking cookie.Serving-sys"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\bluestreak.com.bf396750;""Found Tracking cookie.Bluestreak"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\atdmt.com.b3e33b5f;""Found Tracking cookie.Atdmt"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\advertising.com.f62113d5;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\advertising.com.b624fa46;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\advertising.com.525a5fb9;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\advertising.com.203aa218;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\advertising.com.1820df7a;""Found Tracking cookie.Advertising"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\adopt.euroclick.com.8b1bd7bc;""Found Tracking cookie.Euroclick"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\adopt.euroclick.com.891542da;""Found Tracking cookie.Euroclick"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\adopt.euroclick.com.6d7740f7;""Found Tracking cookie.Euroclick"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\adopt.euroclick.com.17044b51;""Found Tracking cookie.Euroclick"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\2o7.net.f203d064;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\2o7.net.b4218d8b;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt:\2o7.net.4692d914;""Found Tracking cookie.2o7"";""Potentially dangerous object"""
"C:\Documents and Settings\Cara\Application Data\Mozilla\Firefox\Profiles\9f2gbk3q.default\cookies.txt;""Found Tracking cookie.2o7"";""Potentially dangerous object"""

BC AdBot (Login to Remove)

 


#2 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:11:10 AM

Posted 07 August 2008 - 10:33 AM

Hello, Poppi.
:thumbsup: to BleepingComputer.com

My name is Billy O'Neal and I will be helping you. (Billy or Bill is fine, if you like.)
Please give me some time to look over your computer's log(s).
Please take note of the following:
  • In the meantime, please refrain from making any changes to your computer.
  • Also, even if things appear to be running better, there is no guarantee that everything is finished. Please continue to check this forum post in order to ensure we get your system completely clean. We do not want to clean you part-way up, only to have the system re-infect itself. :)
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Finally, please reply using the Posted Image button in the lower left hand corner of your screen.
Please run Deckard's System Scanner again, this time using these instructions:
(In the event you lost your copy, you can download a new one from here: Deckard's System Scanner)
  • Click on Start, click on Run
  • Copy and paste the following in the open window and then click OK:
    "%userprofile%\desktop\dss.exe" /config
  • This will open up DSS configuration
  • Click on Check All.
  • Click Scan.
    DSS will now run again.
  • Please post back both logs that open in notepad.
    Main.txt and Extra.txt
Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#3 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:11:10 AM

Posted 10 August 2008 - 05:14 PM

Hello, Poppi.
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please send me or another moderator a PM.

Everyone else please begin a new topic.

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#4 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:11:10 AM

Posted 10 August 2008 - 10:54 PM

Topic reopened. Please post your logs below :thumbsup:

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#5 Poppi

Poppi
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:02:10 PM

Posted 11 August 2008 - 08:32 AM

Apologies again for the delay...

MAIN.TXT:

Deckard's System Scanner v20071014.68
Run by James on 2008-08-11 09:27:49
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
128: 2008-08-11 13:28:01 UTC - RP128 - Deckard's System Scanner Restore Point
127: 2008-08-11 00:16:27 UTC - RP127 - System Checkpoint
126: 2008-08-09 23:26:15 UTC - RP126 - System Checkpoint
125: 2008-08-08 23:01:09 UTC - RP125 - System Checkpoint
124: 2008-08-07 21:25:14 UTC - RP124 - Installed Nero 7 Ultra Edition


-- First Restore Point --
1: 2008-05-28 02:24:55 UTC - RP1 - System Checkpoint


Performed disk cleanup.



-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-08-11 09:29:00
Platform: Windows XP Service Pack 3 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Wireless-G Portable USB Adapter\WLService.exe
C:\Program Files\Wireless-G Portable USB Adapter\WUSB54GP.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgemc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\ViStart\ViStart.exe
C:\Program Files\ViOrb\ViOrb.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe
C:\Program Files\Nero\Nero 7\Core\nero.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\James\Desktop\dss.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?wl=true
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {4AD3A71E-8ED4-40F5-9A81-69245BDCBB75} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\smax4.exe" /tray
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [ViStart] C:\Program Files\ViStart\ViStart.exe
O4 - HKCU\..\Run: [ViOrb] C:\Program Files\ViOrb\ViOrb.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: palmOne Registration.lnk = C:\Program Files\palmOne\register.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1211974707734
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: AtiExtEvent - C:\WINDOWS\system32\
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WUSB54GPSVC - GEMTEKS - C:\Program Files\Wireless-G Portable USB Adapter\WLService.exe


--
End of file - 12055 bytes

-- File Associations -----------------------------------------------------------

.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*
.js - jsfile - DefaultIcon - "C:\Program Files\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe",7
.js - jsfile - shell\open\command - "C:\Program Files\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe","%1"


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R2 atksgt - c:\windows\system32\drivers\atksgt.sys
R2 lirsgt - c:\windows\system32\drivers\lirsgt.sys
R3 GTNDIS5 (GTNDIS5 NDIS Protocol Driver) - c:\windows\system32\gtndis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
R3 pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
R3 pgfilter - c:\program files\peerguardian2\pgfilter.sys

S3 AEAudio (AE Audio Service) - c:\windows\system32\drivers\aeaudio.sys (file missing)
S3 ATIAVAIW (ATI T200 Unified AVStream service) - c:\windows\system32\drivers\atinavt2.sys <Not Verified; ATI Technologies Inc.; ATI AVStream>
S3 SenFiltService (SenFilt Service) - c:\windows\system32\drivers\senfilt.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>

S3 NBService - c:\program files\nero\nero 7\nero backitup\nbservice.exe
S4 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>


-- Device Manager: Disabled ----------------------------------------------------

Class GUID:
Description: SM Bus Controller
Device ID: PCI\VEN_10DE&DEV_0368&SUBSYS_82391043&REV_A2\3&2411E6FE&0&09
Manufacturer:
Name: SM Bus Controller
PNP Device ID: PCI\VEN_10DE&DEV_0368&SUBSYS_82391043&REV_A2\3&2411E6FE&0&09
Service:


-- Process Modules -------------------------------------------------------------

C:\WINDOWS\system32\winlogon.exe (pid 656)
2008-04-14 05:42:06 1259520 --a------ C:\WINDOWS\system32\setupapi.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:00 1478656 --a------ C:\WINDOWS\system32\msgina.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:06 14582784 --a------ C:\WINDOWS\system32\shell32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-06-01 22:52:53 218624 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 13:39:24 3385856 --a------ C:\WINDOWS\system32\xpsp2res.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>

C:\WINDOWS\system32\svchost.exe (pid 936)
2008-04-13 20:12:06 14582784 --a------ C:\WINDOWS\system32\shell32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-06-01 22:52:53 218624 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 13:39:24 3385856 --a------ C:\WINDOWS\system32\xpsp2res.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-14 05:42:06 1259520 --a------ C:\WINDOWS\system32\setupapi.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>

C:\WINDOWS\system32\svchost.exe (pid 1080)
2008-04-13 20:12:06 14582784 --a------ C:\WINDOWS\system32\shell32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-06-01 22:52:53 218624 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 13:39:24 3385856 --a------ C:\WINDOWS\system32\xpsp2res.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-14 05:42:06 1259520 --a------ C:\WINDOWS\system32\setupapi.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:02 2231808 --a------ C:\WINDOWS\system32\netshell.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:04 840704 --a------ C:\WINDOWS\system32\rasdlg.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>

C:\WINDOWS\system32\svchost.exe (pid 1936)
2008-04-13 20:12:06 14582784 --a------ C:\WINDOWS\system32\shell32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-06-01 22:52:53 218624 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-14 05:42:06 1259520 --a------ C:\WINDOWS\system32\setupapi.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 13:39:24 3385856 --a------ C:\WINDOWS\system32\xpsp2res.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-03-15 15:27:00 1134592 --a------ C:\WINDOWS\system32\CNCC160.DLL <Not Verified; CANON INC.; WIA Scanner Driver>
2006-05-29 09:31:50 135168 --a------ C:\WINDOWS\system32\CNCL160.DLL <Not Verified; Canon Inc.; Canon MP>

C:\WINDOWS\explorer.exe (pid 2960)
2008-04-13 20:12:06 14582784 --a------ C:\WINDOWS\system32\shell32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-06-01 22:52:53 218624 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 13:39:24 3385856 --a------ C:\WINDOWS\system32\xpsp2res.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-14 05:42:06 1259520 --a------ C:\WINDOWS\system32\setupapi.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:02 2231808 --a------ C:\WINDOWS\system32\netshell.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-23 00:16:30 358400 --a------ C:\WINDOWS\system32\webcheck.dll <Not Verified; Microsoft Corporation; Windows® Internet Explorer>
2008-04-13 20:12:08 113664 --a------ C:\WINDOWS\system32\stobject.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:11:50 38400 --a------ C:\WINDOWS\system32\batmeter.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-13 20:12:02 80896 --a------ C:\WINDOWS\system32\mydocs.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2002-09-15 19:01:04 7221 --a------ C:\Program Files\ViOrb\StartHook.dll
2005-03-08 08:23:04 233577 --a------ C:\Program Files\ViStart\MainHook.dll
2006-08-11 14:56:02 7168 --a------ C:\WINDOWS\system32\CTAGENT.DLL <Not Verified; Creative Technology Ltd; ctagent>

C:\WINDOWS\system32\rundll32.exe (pid 2780)
2008-04-13 20:12:06 14582784 --a------ C:\WINDOWS\system32\shell32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-06-01 22:52:53 218624 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-14 05:42:06 1259520 --a------ C:\WINDOWS\system32\setupapi.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>


-- Files created between 2008-07-11 and 2008-08-11 -----------------------------

2008-08-07 17:27:28 0 d-------- C:\Documents and Settings\James\Application Data\Ahead
2008-08-07 17:25:19 0 d-------- C:\Program Files\Nero
2008-08-07 17:25:19 0 d-------- C:\Program Files\Common Files\Ahead
2008-08-07 16:17:15 0 d-------- C:\Documents and Settings\Cara\Application Data\HotSync
2008-08-06 16:56:21 0 d-------- C:\Program Files\Common Files\Control Panels
2008-08-06 08:33:30 0 d-------- C:\Documents and Settings\James\Application Data\Leadertech
2008-08-06 08:32:18 0 d-------- C:\Documents and Settings\All Users\Application Data\HotSync
2008-08-06 08:31:34 0 d-------- C:\Program Files\palmOne
2008-08-06 08:30:59 0 d-------- C:\Documents and Settings\James\Application Data\HotSync
2008-08-06 08:30:40 0 d-------- C:\WINDOWS\Downloaded Installations
2008-08-06 08:11:10 0 d-------- C:\Documents and Settings\James\Application Data\vlc
2008-08-06 07:54:43 0 d-------- C:\Program Files\VideoLAN
2008-07-18 14:34:32 586240 --a------ C:\WINDOWS\WLXPGSS.SCR <Not Verified; Microsoft Corporation; Windows Live Photo Gallery>
2008-07-17 22:13:57 0 d-------- C:\Documents and Settings\All Users\Application Data\vsosdk
2008-07-17 20:45:26 47360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2008-07-17 20:45:26 0 d-------- C:\Documents and Settings\James\Application Data\Vso
2008-07-17 20:45:26 47360 --a------ C:\Documents and Settings\James\Application Data\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2008-07-17 20:45:20 217127 --a------ C:\WINDOWS\system32\drv43260.dll <Not Verified; RealNetworks, Inc.; RealVideo 9 (32-bit)>
2008-07-17 20:45:20 208935 --a------ C:\WINDOWS\system32\drv33260.dll <Not Verified; RealNetworks, Inc.; RealVideo 8 (32-bit)>
2008-07-17 20:45:19 626688 --a------ C:\WINDOWS\system32\vp7vfw.dll <Not Verified; On2.com; On2_VP70>
2008-07-17 20:45:19 176165 --a------ C:\WINDOWS\system32\drv23260.dll <Not Verified; RealNetworks, Inc.; RealVideo G2 (32-bit)>
2008-07-17 20:45:19 65602 --a------ C:\WINDOWS\system32\cook3260.dll <Not Verified; RealNetworks, Inc.; RealPlayer 10>
2008-07-17 20:45:18 0 d-------- C:\Program Files\VSO
2008-07-17 20:35:00 0 d-------- C:\Program Files\Avi2Dvd
2008-07-14 21:25:19 98304 --a------ C:\WINDOWS\system32\CmdLineExt.dll <Not Verified; Sony DADC Austria AG.; >
2008-07-14 21:22:59 0 d-------- C:\Documents and Settings\James\Application Data\InstallShield Installation Information


-- Find3M Report ---------------------------------------------------------------

2008-08-11 09:29:21 0 d-------- C:\Program Files\PeerGuardian2
2008-08-11 09:22:33 0 d-------- C:\Program Files\Mozilla Thunderbird
2008-08-11 09:21:28 0 d-------- C:\Program Files\ViStart
2008-08-08 15:56:11 0 d-------- C:\Documents and Settings\James\Application Data\uTorrent
2008-08-07 17:25:19 0 d-------- C:\Program Files\Common Files
2008-08-07 09:27:05 668 --a------ C:\Documents and Settings\James\Application Data\vso_ts_preview.xml
2008-08-06 17:05:15 0 d-------- C:\Documents and Settings\James\Application Data\Adobe
2008-08-06 16:55:57 0 d-------- C:\Program Files\Common Files\Adobe
2008-07-29 12:57:17 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-07-29 11:51:29 0 d-------- C:\Program Files\Java
2008-07-17 20:45:36 34 --a------ C:\Documents and Settings\James\Application Data\pcouffin.log
2008-07-17 20:45:26 1144 --a------ C:\Documents and Settings\James\Application Data\pcouffin.inf
2008-07-17 20:45:26 7887 --a------ C:\Documents and Settings\James\Application Data\pcouffin.cat
2008-07-17 20:36:18 0 d-------- C:\Program Files\AviSynth 2.5
2008-07-14 19:36:14 0 d-------- C:\Program Files\Winamp
2008-07-14 19:35:41 0 d-------- C:\Documents and Settings\James\Application Data\Winamp
2008-07-07 10:57:16 0 d-------- C:\Program Files\eRightSoft
2008-07-06 21:00:37 0 d-------- C:\Documents and Settings\James\Application Data\Logitech
2008-07-06 20:58:56 0 d-------- C:\Program Files\Common Files\Logishrd
2008-07-06 20:58:20 0 d-------- C:\Program Files\Logitech
2008-07-06 20:55:15 8 --a------ C:\WINDOWS\system32\nvModes.dat
2008-07-03 18:44:32 0 d-------- C:\Documents and Settings\James\Application Data\Google
2008-07-03 18:40:37 0 d-------- C:\Program Files\Google
2008-06-26 08:43:54 0 d-------- C:\Program Files\MSXML 4.0
2008-06-17 19:57:58 0 d-------- C:\Program Files\OpenAL
2008-06-14 20:16:37 0 d-------- C:\Program Files\Common Files\InstallShield
2008-06-01 22:52:53 218624 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-28 07:48:05 1169 --a------ C:\WINDOWS\mozver.dat
2008-05-27 23:22:18 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-05-27 22:48:12 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-27 22:20:21 0 -rahs---- C:\MSDOS.SYS
2008-05-27 22:20:21 0 -rahs---- C:\IO.SYS
2008-05-27 22:20:21 0 --a------ C:\CONFIG.SYS
2008-05-27 22:20:21 0 --a------ C:\AUTOEXEC.BAT
2008-05-27 22:17:54 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-05-27 18:06:20 62 --ahs---- C:\Documents and Settings\James\Application Data\desktop.ini


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4AD3A71E-8ED4-40F5-9A81-69245BDCBB75}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [10/06/2008 04:27 AM]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" []
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\smax4.exe" [10/04/2006 09:19 AM]
"nwiz"="nwiz.exe" [02/05/2008 10:46 PM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [02/05/2008 10:46 PM]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [02/05/2008 10:46 PM]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" []
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [24/08/2007 07:00 AM]
"CTxfiHlp"="CTXFIHLP.EXE" [11/08/2006 02:56 PM C:\WINDOWS\system32\CTXFIHLP.EXE]
"CTHelper"="CTHELPER.EXE" [11/08/2006 02:56 PM C:\WINDOWS\CTHELPER.EXE]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [03/07/2008 11:55 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/01/2008 10:16 PM]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [11/01/2008 07:54 PM]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [29/02/2008 03:12 AM C:\WINDOWS\KHALMNPR.Exe]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [12/01/2006 03:40 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [18/09/2005 06:40 PM]
"ViStart"="C:\Program Files\ViStart\ViStart.exe" [26/11/2007 07:27 PM]
"ViOrb"="C:\Program Files\ViOrb\ViOrb.exe" [19/11/2007 01:01 PM]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [06/06/2008 11:30 AM]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [13/04/2008 08:12 PM]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" []
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [01/04/2008 05:39 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [13/04/2008 08:12 PM]

C:\Documents and Settings\James\Start Menu\Programs\Startup\
palmOne Registration.lnk - C:\Program Files\palmOne\register.exe [19/09/2005 1:20:36 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HOTSYNCSHORTCUTNAME.lnk - C:\Program Files\palmOne\Hotsync.exe [09/06/2004 2:27:34 PM]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [06/07/2008 8:58:43 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll 02/05/2008 02:42 AM 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jigsaw]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc

*Newly Created Service* - PGFILTER



-- End of Deckard's System Scanner: finished at 2008-08-11 09:29:53 ------------

EXTRA.TXT:

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Home Edition (build 2600) SP 3.0
Architecture: X86; Language: English

CPU 0: AMD Athlon™ 64 X2 Dual Core Processor 4200+
Percentage of Memory in Use: 19%
Physical Memory (total/avail): 3582.42 MiB / 2897.13 MiB
Pagefile Memory (total/avail): 5464.45 MiB / 4923.29 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1899.2 MiB

C: is Fixed (NTFS) - 232.88 GiB total, 87.11 GiB free.
D: is Fixed (NTFS) - 74.52 GiB total, 14.35 GiB free.
E: is CDROM (No Media)
F: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - WDC WD2500JB-16FUA0 - 232.88 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 232.88 GiB - C:

\\.\PHYSICALDRIVE1 - WDC WD800BB-55HEA0 - 74.53 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 74.52 GiB - D:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\James\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=MAIN
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\James
LOGONSERVER=\\MAIN
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\Common Files\Ulead Systems\MPEG
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 75 Stepping 2, AuthenticAMD
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=4b02
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\James\LOCALS~1\Temp
TMP=C:\DOCUME~1\James\LOCALS~1\Temp
USERDOMAIN=MAIN
USERNAME=James
USERPROFILE=C:\Documents and Settings\James
windir=C:\WINDOWS
__COMPAT_LAYER=EnableNXShowUI


-- User Profiles ---------------------------------------------------------------

James (admin)
Cara (admin)
Administrator (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
--> C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
--> C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
--> C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
--> C:\WINDOWS\UNNeroVision.exe /UNINSTALL
--> C:\WINDOWS\UNRecode.exe /UNINSTALL
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7B9AE66C-2A8F-4FB2-85D7-416AFFAE8408}\setup.exe" -l0x9
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0044-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-00BA-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0114-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0117-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
AC3File (remove only) --> C:\Program Files\AC3File\uninstall.exe
AC3Filter (remove only) --> C:\Program Files\AC3Filter\uninstall.exe
Adobe Acrobat 8.1.2 Professional --> msiexec /I {AC76BA86-1033-F400-7760-000000000003}
Adobe Acrobat 8.1.2 Security Update 1 (KB403742) -->
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742) --> MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
Adobe Anchor Service CS3 --> MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3 --> MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3 --> MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting --> MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe Camera Raw 4.0 --> MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps --> MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color - Photoshop Specific --> MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings --> C:\Program Files\Common Files\Adobe\Installers\6c8e2cb4fd241c55406016127a6ab2e\Setup.exe
Adobe Color Common Settings --> MsiExec.exe /I{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}
Adobe Color EU Extra Settings --> MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
Adobe Color JA Extra Settings --> MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Recommended Settings --> MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
Adobe Default Language CS3 --> MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3 --> MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe Dreamweaver CS3 --> C:\Program Files\Common Files\Adobe\Installers\435a6af7459cb02a9c1138113a26e93\Setup.exe
Adobe Dreamweaver CS3 --> MsiExec.exe /I{F01D5ED5-D53A-4468-B428-149DC2CB3110}
Adobe ExtendScript Toolkit 2 --> C:\Program Files\Common Files\Adobe\Installers\3e054d2218e7aa282c2369d939e58ff\Setup.exe
Adobe ExtendScript Toolkit 2 --> MsiExec.exe /I{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}
Adobe Extension Manager CS3 --> MsiExec.exe /I{2A539CD9-0F75-4875-9A32-E06DD93C4114}
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Fonts All --> MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3 --> MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe InDesign CS3 --> C:\Program Files\Common Files\Adobe\Installers\05ba3a63f36684fe0c5dde2ebe6f8f5\Setup.exe
Adobe InDesign CS3 --> MsiExec.exe /I{CB3F8375-B600-4B9F-83C9-238ED1E583FD}
Adobe InDesign CS3 Icon Handler --> MsiExec.exe /I{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}
Adobe Linguistics CS3 --> MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe PDF Library Files --> MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop CS3 --> C:\Program Files\Common Files\Adobe\Installers\2ac78060bc5856b0c1cf873bb919b58\Setup.exe
Adobe Photoshop CS3 --> MsiExec.exe /I{0046FA01-C5B9-4985-BACB-398DC480FC05}
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Reader 8.1.2 Security Update 1 (KB403742) -->
Adobe Setup --> MsiExec.exe /I{3A12C952-61D5-4C3B-B68B-8CFBE47E22F1}
Adobe Setup --> MsiExec.exe /I{56B8B892-317E-4FDE-9E4D-44B189848A27}
Adobe Setup --> MsiExec.exe /I{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}
Adobe Setup --> MsiExec.exe /I{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}
Adobe Setup --> MsiExec.exe /I{D1BB4446-AE9C-4256-9A7F-4D46604D2462}
Adobe SING CS3 --> MsiExec.exe /I{3F9B2FD2-1C83-4401-9967-C3636638E958}
Adobe Stock Photos CS3 --> MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support --> MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3 --> MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client --> MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe WinSoft Linguistics Plugin --> MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3 --> MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
Anno 1701 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A2433A63-5F5D-40E5-B529-9123C2B3E734}\Setup.exe" -l0x9 -removeonly
µTorrent --> "C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
AVG Free 8.0 --> C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Avi2Dvd 0.4.5 beta --> C:\Program Files\Avi2Dvd\uninst.exe
AviSynth 2.5 --> "C:\Program Files\AviSynth 2.5\Uninstall.exe"
Canon MP160 --> "C:\WINDOWS\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP160\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP160 /L0x0009
CDDRV_Installer --> MsiExec.exe /I{0C826C5B-B131-423A-A229-C71B3CACCD6A}
ConvertXtoDVD 3.1.1.32 --> "C:\Program Files\VSO\ConvertX\3\unins000.exe"
Creative Audio Console --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7B9AE66C-2A8F-4FB2-85D7-416AFFAE8408}\setup.exe" -l0x9 /remove
DH Driver Cleaner Professional Edition --> C:\Program Files\Driver Cleaner Pro\Uninstall.exe
Google Earth --> MsiExec.exe /I{97C0EA4A-1A0B-4C53-ACEB-49984DA79C90}
Google Updater --> "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
GRID --> "C:\Program Files\InstallShield Installation Information\{5A0B7BA5-4682-4273-81C2-69B17E649103}\setup.exe" -runfromtemp -l0x0009 -removeonly
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Java™ 6 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}
Java™ 6 Update 7 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
KhalInstallWrapper --> MsiExec.exe /I{3101CB58-3482-4D21-AF1A-7057FC935355}
Logitech SetPoint --> C:\Program Files\InstallShield Installation Information\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}\setup.exe -runfromtemp -l0x0009 -removeonly
Medieval II Total War --> C:\Program Files\InstallShield Installation Information\{C0698BDA-0D29-40EE-8570-A31106DF9AB1}\setup.exe -runfromtemp -l0x0009 -removeonly
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 --> "C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
Microsoft Office Access MUI (English) 2007 --> MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Enterprise 2007 --> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007 --> MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007 --> MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007 --> MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007 --> MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007 --> MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007 --> MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007 --> MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007 --> MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007 --> MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007 --> MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007 --> MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft SQL Server 2005 Compact Edition [ENU] --> MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual J# .NET Redistributable Package 1.1 --> MsiExec.exe /X{1A655D51-1423-48A3-B748-8F5A0BE294C8}
Mozilla Firefox (2.0.0.16) --> C:\PROGRA~1\Mozilla Firefox\uninstall\helper.exe
Mozilla Thunderbird (2.0.0.16) --> C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
Need for Speed™ ProStreet --> MsiExec.exe /X{CC419DDC-E0F0-4013-B25A-6FA036516F0D}
Need for Speed™ ProStreet Demo --> MsiExec.exe /X{6E384346-CD1C-4A00-9885-BC8E6A50ECB5}
Nero 7 Ultra Edition --> MsiExec.exe /I{235BBFC6-D863-4066-A01A-3BD504C31033}
neroxml --> MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NVIDIA Drivers --> C:\WINDOWS\system32\nvuninst.exe UninstallGUI
Oblivion --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{35CB6715-41F8-4F99-8881-6FC75BF054B0}\setup.exe" -l0x9 -removeonly
Oblivion mod manager 1.1.9 --> "C:\games\Bethesda Softworks\Oblivion\obmm\uninstall\unins000.exe"
OpenAL --> "C:\Program Files\OpenAL\OalinstGridRelease.exe" /U
palmOne --> MsiExec.exe /X{FF24F097-D090-41D2-8E9C-BAFEBBFD938C}
PDF Settings --> MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
PeerGuardian 2.0 --> "C:\Program Files\PeerGuardian2\unins000.exe"
Security Update for Excel 2007 (KB946974) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {85E83E2E-AF9B-439B-B4F9-EB9B7EF6A00E}
Security Update for Microsoft Office Publisher 2007 (KB950114) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
Security Update for Microsoft Office system 2007 (KB951808) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {8F375E11-4FD6-4B89-9E2B-A76D48B51E00}
Security Update for Microsoft Office Word 2007 (KB950113) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {AD72BABE-C733-4FCF-9674-4314466191B9}
Security Update for Office 2007 (KB947801) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {02B5A17B-01BE-4BA6-95F1-1CBB46EBC76E}
Sid Meier's Pirates! --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{1632FD86-1BA4-4FC4-8B25-A8C655D63F68} /l1033
Sid Meier's Railroads! --> C:\Documents and Settings\James\Application Data\InstallShield Installation Information\{EE3FBD3C-782E-4A90-9507-0ECFE1FECCE4}\setup.exe -runfromtemp -l0x0009 -removeonly
SoundMAX --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\setup.exe" -l0x9 -removeonly
SUPER © Version 2008.bld.30 (Mar 22, 2008) --> C:\PROGRA~1\ERIGHT~1\SUPER\Setup.exe /remove /q0
Ulead CD & DVD PictureShow 4 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F6199F9-9BED-4B43-9E5C-8495086EE714}\setup.exe" -l0x9
Unofficial Oblivion Patch v3.0.0 --> "C:\games\Bethesda Softworks\Oblivion\Unofficial Oblivion Patch\unins000.exe"
Unofficial Shivering Isles Patch v1.2.0 --> "C:\games\Bethesda Softworks\Oblivion\Unofficial Shivering Isles Patch\unins000.exe"
Update for Microsoft Office Outlook 2007 (KB952142) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
Update for Office 2007 (KB946691) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
Update for Outlook 2007 Junk Email Filter (kb953463) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {1B78D541-9FF1-4330-ADD8-CED14F0C1E8E}
VCRedistSetup --> MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
VideoLAN VLC media player 0.8.5 --> C:\Program Files\VideoLAN\VLC\uninstall.exe
Vista Transformation Pack 8.0 --> C:\WINDOWS\system32\viwc.exe
Winamp --> "C:\Program Files\Winamp\UninstWA.exe"
Windows Live installer --> MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Messenger --> MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Photo Gallery --> MsiExec.exe /X{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}
Windows Live Sign-in Assistant --> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Media Encoder 9 Series --> msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Windows Media Encoder 9 Series --> MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows XP Service Pack 3 --> "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
Wireless-G Portable USB Adapter --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{97B9314B-134D-482B-A32E-1E6123BE0F64}\setup.exe" -l0x9
Xvid 1.1.3 final uninstall --> "C:\Program Files\Xvid\unins000.exe"


-- Application Event Log -------------------------------------------------------

Event Record #/Type2037 / Error
Event Submitted/Written: 08/11/2008 09:29:03 AM
Event ID/Source: 11 / crypt32
Event Description:
Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: The data is invalid.

Event Record #/Type2016 / Error
Event Submitted/Written: 08/07/2008 05:28:50 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application explorer.exe, version 6.0.2900.5512, faulting module unknown, version 0.0.0.0, fault address 0x04f81568.
Processing media-specific event for [explorer.exe!ws!]

Event Record #/Type1985 / Success
Event Submitted/Written: 08/07/2008 08:51:12 AM
Event ID/Source: 12001 / usnjsvc
Event Description:
The Messenger Sharing USN Journal Reader service started successfully.

Event Record #/Type1953 / Success
Event Submitted/Written: 08/06/2008 07:48:30 AM
Event ID/Source: 12001 / usnjsvc
Event Description:
The Messenger Sharing USN Journal Reader service started successfully.

Event Record #/Type1937 / Success
Event Submitted/Written: 08/05/2008 07:55:23 PM
Event ID/Source: 12001 / usnjsvc
Event Description:
The Messenger Sharing USN Journal Reader service started successfully.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type7854 / Warning
Event Submitted/Written: 08/11/2008 09:20:01 AM
Event ID/Source: 1003 / Dhcp
Event Description:
Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 0018F82788C8. The following
error occurred:
%%1223.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.

Event Record #/Type7853 / Warning
Event Submitted/Written: 08/11/2008 09:20:01 AM
Event ID/Source: 1003 / Dhcp
Event Description:
Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 0018F82788C8. The following
error occurred:
%%1223.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.

Event Record #/Type7852 / Warning
Event Submitted/Written: 08/11/2008 09:19:56 AM
Event ID/Source: 1003 / Dhcp
Event Description:
Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 0018F82788C8. The following
error occurred:
%%1223.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.

Event Record #/Type7820 / Error
Event Submitted/Written: 08/10/2008 06:08:06 PM
Event ID/Source: 1002 / Dhcp
Event Description:
The IP address lease 192.168.2.10 for the Network Card with network address 0018F82788C8 has been
denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).

Event Record #/Type7795 / Warning
Event Submitted/Written: 08/10/2008 00:01:40 PM
Event ID/Source: 1003 / Dhcp
Event Description:
Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 0018F82788C8. The following
error occurred:
%%1223.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.



-- End of Deckard's System Scanner: finished at 2008-08-11 09:29:53 ------------

#6 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:11:10 AM

Posted 11 August 2008 - 10:04 AM

Hello, Poppi.
We need to run ComboFix.In your next reply, please include the following:
  • ComboFix.txt

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#7 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:11:10 AM

Posted 14 August 2008 - 04:08 PM

Hello Poppi.

Are you still here?

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#8 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:11:10 AM

Posted 16 August 2008 - 07:18 AM

Hello, Poppi.
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please send me or another moderator a PM.

Everyone else please begin a new topic.

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users