Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Net.Worm.Win32.Kolabc.ixm


  • This topic is locked This topic is locked
28 replies to this topic

#1 jbandtbone

jbandtbone

  • Members
  • 90 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:42 AM

Posted 23 November 2011 - 12:56 AM

As said my zonealarm said that I had this "Net.Worm.Win32.Kolabc.ixm". This came up when I was backing up my pc with the backup utility on my machine to my WD Passport Elite external hard drive. ZA said it was on this drive. ZA quarantined it, then I deleted it from the WD drive and ZA. I thought I had removed it,but I'm not so sure. Afterwords I found out that I cannot update my Zonealarm anti-virus/anti-spyware. Keep getting a error: unable to connect to update server. My Explore browser has been hanging up alot, when I close it,it doesn't go away on the screen for awhile. But today I Got this phone call from some lady that was very hard to understand, but said she understood that I had been having alot of error reports sent to microsoft and that she wanted to help me. Freaked me out. Knew where I lived. So that is why I'm here to make sure that there is not something on my pc sending out my information to people out there. I hope that I've given enough info om this. Please help me. And thank you for being on the good side of the internet.

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by jbandt at 23:38:23 on 2011-11-22
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2398 [GMT -5:00]
.
AV: ZoneAlarm Extreme Security Antivirus *Enabled/Updated* {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Extreme Security Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\System32\svchost.exe -k eapsvcs
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\System32\svchost.exe -k dot3svc
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = localhost
uURLSearchHooks: N/A: {be89472c-b803-4d1d-9a9a-0a63660e0fe3} - c:\progra~1\copern~1\COPERN~1.DLL
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: ZoneAlarm Toolbar Registrar: {8a4a36c2-0535-4d2c-bd3d-496cb7eed6e3} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: ZoneAlarm Toolbar: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
EB: Copernic Agent Results: {6f480f82-c3a6-4d35-96f7-b297ad49fbe8} - c:\program files\copernic agent\CopernicAgentExt.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [DLCJCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCJtime.dll,_RunDLLEntry@16
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRunOnce: [RunNarrator] Narrator.exe
uPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-explorer: NoResolveTrack = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: 1stpeoplesbank.com\www
Trusted Zone: 1stpeoplesbankhb.com\www
Trusted Zone: bankofamerica.com\www
Trusted Zone: bleepingcomputer.com\www
Trusted Zone: earthcam.net\doliver
Trusted Zone: excite.com\registration
Trusted Zone: excite.com\www
Trusted Zone: grc.com\www
Trusted Zone: keithandschnars.com\www
Trusted Zone: live.com\bl145w.blu145.mail
Trusted Zone: live.com\login
Trusted Zone: live.com\mail
Trusted Zone: msn.com\www
Trusted Zone: netflix.com
Trusted Zone: netflix.com\movies
Trusted Zone: onlinecreditcenter6.com\www
Trusted Zone: sirius.com\www
Trusted Zone: state.fl.us\fdotnfuse.dot
Trusted Zone: techguy.org\www
Trusted Zone: virusvault.co.uk\www
Trusted Zone: yahoo.com\att.my
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://www.celartem.com/en/download/data/djvu_autoinstall/DjVuControl_en_US.cab
DPF: {15B782AF-55D8-11D1-B477-006097098764} - hxxp://download.macromedia.com/pub/shockwave/cabs/authorware/awswax70.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} - hxxps://fdotnfuse.dot.state.fl.us/Citrix/ICAWEB/en/ica32/wficat.cab
DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} - hxxps://support.microsoft.com/OAS/ActiveX/odc.cab
DPF: {321FB770-1FBE-4BFE-BDC1-6F622D4FA499} - hxxps://pbells.broadjump.com/wizlet/iw60/static/controls/WebflowActiveXInstaller_4-0-0.cab
DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} - hxxp://i.dell.com/images/global/js/scanner/SysProExe.cab
DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} - hxxp://moneycentral.msn.com/cabs/pmupd806.exe
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab
DPF: {46D8BEE7-0B27-4466-ABA2-A5F1E157971C} - hxxp://dvr.floridanexuspark.com/RemoteWeb.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/mcinsctl.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120083437937
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1121730826828
DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - hxxp://doliver.earthcam.net/viewer/AMC.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} - hxxp://www3.ca.com/securityadvisor/virusinfo/webscan.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {8D3314D6-5914-46C1-9F3D-9F14B6A305F1} - hxxp://www.mytpi.com/mytpi05/eval/ectuploader.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab
DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} - hxxp://hgtv1.view22.com/view22/app/view22rte.cab
DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://www.cvsphoto.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
DPF: {C237A80A-4C55-4C68-BAA9-CBE4408D12B2} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - hxxp://fdl.msn.com/zone/datafiles/heartbeat.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
DPF: {E7D2588A-7FB5-47DC-8830-832605661009} - hxxps://livewc01.custhelp.com/7550-b415h-quickenmedical/rnl/java/RntX.cab
DPF: {EF0DBA6F-43CE-4B26-9808-2AB38FA0DB29} - hxxp://fdl.msn.com/public/investor/v13/ticker.cab
DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} - hxxp://by107fd.bay107.hotmail.msn.com/activex/HMAtchmt.ocx
DPF: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} - hxxp://www.paslc.org/acgm/f2_acgm.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{23473EEF-A2C0-490E-A49D-93A5EB42419F} : DhcpNameServer = 192.168.1.254
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: copernicagent - {A979B6BD-E40B-4A07-ABDD-A62C64A4EBF6} - c:\progra~1\copern~1\COPERN~1.DLL
Handler: copernicagentcache - {AAC34CFD-274D-4A9D-B0DC-C74C05A67E1D} - c:\progra~1\copern~1\COPERN~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
LSA: Authentication Packages = msv1_0 relog_ap
.
============= SERVICES / DRIVERS ===============
.
R0 kl1;kl1;c:\windows\system32\drivers\kl1.sys [2011-11-22 128016]
R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2011-11-22 317072]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2011-11-22 528128]
R2 ISWKL;ZoneAlarm ForceField ISWKL;c:\program files\checkpoint\zaforcefield\ISWKL.sys [2010-8-27 26352]
R2 IswSvc;ZoneAlarm ForceField IswSvc;c:\program files\checkpoint\zaforcefield\ISWSVC.exe [2010-8-27 493032]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [2009-10-28 12184]
R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\western digital\wd drive manager\WDBtnMgrSvc.exe [2008-7-24 102400]
R3 icsak;icsak;c:\program files\checkpoint\zaforcefield\ak\icsak.sys [2010-8-27 35568]
R3 NmPar;Unusable Parallel Port;c:\windows\system32\drivers\NmPar.sys [2008-7-31 80512]
R3 nmserial;PCI Serial Port;c:\windows\system32\drivers\NmSerial.sys [2008-7-31 70016]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2011-11-21 244736]
S3 alcan5ln;Alcatel SpeedTouch™ USB ADSL RFC1483 Networking Driver (NDIS);c:\windows\system32\drivers\alcan5ln.sys [2006-3-16 36960]
S3 gupdate1c9c9186781a4fc;Google Update Service (gupdate1c9c9186781a4fc);c:\program files\google\update\GoogleUpdate.exe [2009-4-29 133104]
S3 McTskshd.exe;McAfee Task Scheduler;c:\progra~1\mcafee.com\agent\mctskshd.exe --> c:\progra~1\mcafee.com\agent\mctskshd.exe [?]
S3 mcupdmgr.exe;McAfee SecurityCenter Update Manager;c:\progra~1\mcafee.com\agent\mcupdmgr.exe --> c:\progra~1\mcafee.com\agent\mcupdmgr.exe [?]
S3 NDMSHLP;Device Monitor Helper Driver;c:\program files\common files\hhd software\device monitor\NDMSHLP.sys [2005-5-24 7632]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2004-8-12 14336]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2009-6-17 12648]
S3 SerMon;Serial Monitor Filter Driver;c:\program files\hhd software\free serial port monitor\sermon.sys [2005-5-24 18432]
S4 McDetect.exe;McAfee WSC Integration;c:\program files\mcafee.com\agent\mcdetect.exe --> c:\program files\mcafee.com\agent\mcdetect.exe [?]
.
=============== Created Last 30 ================
.
2011-11-23 03:09:22 128016 ----a-w- c:\windows\system32\drivers\kl1.sys
2011-11-23 03:08:52 1238528 ----a-w- c:\windows\system32\zpeng25.dll
2011-11-23 03:08:52 -------- d-----w- c:\windows\system32\ZoneLabs
2011-11-23 03:08:50 -------- d-----w- c:\program files\Zone Labs
2011-11-23 03:07:20 -------- d-----w- c:\windows\Internet Logs
2011-11-23 02:12:01 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2011-11-23 02:11:59 -------- d-----w- c:\documents and settings\jbandt\local settings\application data\Conduit
2011-11-21 15:40:20 417952 ------w- c:\windows\system32\FlashPlayerApp.exe
2011-11-21 15:36:08 -------- d-----w- c:\documents and settings\jbandt\Tracing
2011-11-21 15:34:26 -------- d-----w- c:\program files\Microsoft
2011-11-21 15:34:03 -------- d-----w- c:\program files\Windows Live SkyDrive
2011-11-21 15:29:54 -------- d-----w- c:\program files\common files\Windows Live
2011-11-21 15:13:44 53248 ------r- c:\documents and settings\jbandt\application data\microsoft\installer\{3ee9bcae-e9a9-45e5-9b1c-83a4d357e05c}\ARPPRODUCTICON.exe
2011-11-21 15:13:21 -------- d-----w- c:\documents and settings\jbandt\local settings\application data\Logishrd
2011-11-21 15:13:07 16400 ------w- c:\windows\system32\drivers\LNonPnP.sys
2011-11-21 15:03:53 -------- d-----w- c:\documents and settings\jbandt\application data\Logishrd
2011-11-21 14:29:51 -------- d-----w- c:\documents and settings\jbandt\local settings\application data\Sun
2011-11-21 14:20:23 -------- d-----w- c:\program files\AMD APP
2011-11-21 14:20:10 -------- d-----w- c:\program files\ATI
2011-10-26 02:21:48 56832 ------w- c:\windows\system32\OpenVideo.dll
2011-10-26 02:21:34 56832 ------w- c:\windows\system32\OVDecoder.dll
2011-10-26 02:20:42 13950464 ------w- c:\windows\system32\amdocl.dll
2011-10-26 02:19:50 44032 ------w- c:\windows\system32\OpenCL.dll
.
==================== Find3M ====================
.
2011-11-21 15:40:20 69792 ------w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-21 14:28:38 544656 ------w- c:\windows\system32\deployJava1.dll
2011-11-21 14:28:38 128000 ------w- c:\windows\system32\javacpl.cpl
2011-10-10 14:22:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41:20 611328 ------w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20:51 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-09-02 06:31:28 55064 ------w- c:\windows\system32\LMouFiltCoInst.dll
2011-09-02 06:31:28 39192 ------w- c:\windows\system32\drivers\LMouFilt.Sys
2011-09-02 06:31:20 41240 ------w- c:\windows\system32\drivers\LHidFilt.Sys
2011-09-02 06:31:20 1583896 ------w- c:\windows\system32\LkmdfCoInst.dll
2011-09-02 06:30:58 22040 ------w- c:\windows\system32\drivers\L8042Kbd.sys
2011-09-02 06:30:58 12184 ------w- c:\windows\system32\drivers\LBeepKE.sys
2011-08-31 21:00:50 22216 ------w- c:\windows\system32\drivers\mbam.sys
.
============= FINISH: 23:39:54.51 ===============

BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,701 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:42 AM

Posted 28 November 2011 - 01:00 AM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

Posted Image In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/428990 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

Posted Image If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS and GMER log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from one of the following links if you no longer have it available. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE


We also need a new log from the GMER anti-rootkit Scanner.

Please note that if you are running a 64-bit version of Windows you will not be able to run GMER and you may skip this step.

Please first disable any CD emulation programs using the steps found in this topic:

Why we request you disable CD Emulation when receiving Malware Removal Advice


Then create another GMER log and post it as an attachment to the reply where you post your new DDS log. Instructions on how to properly create a GMER log can be found here:

How to create a GMER log


As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 jbandtbone

jbandtbone
  • Topic Starter

  • Members
  • 90 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:42 AM

Posted 28 November 2011 - 08:50 PM

As I said before my Zone Alarm said that I had the Net.Worm.Win32.Kolabc.ixm. It showed up while I was backing up my hard drive to a external drive. Also I had updated some programs from filehippo.com. Aterwards my internet browser has started to hang up at the beginning when I go to a web page and then remain on the screen after closing it so that I cannot see/or get back to my desktop. PC has also slowed down a little bit it seems. It is a little frustrating to keep restarting it. Also my Zone Alarm will not connect to the update server to update the anti-virus/anti-spyware definitions.

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by jbandt at 20:11:56 on 2011-11-28
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2614 [GMT -5:00]
.
AV: ZoneAlarm Extreme Security Antivirus *Disabled/Updated* {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Extreme Security Firewall *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\System32\svchost.exe -k eapsvcs
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\System32\svchost.exe -k dot3svc
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = localhost
uURLSearchHooks: N/A: {be89472c-b803-4d1d-9a9a-0a63660e0fe3} - c:\progra~1\copern~1\COPERN~1.DLL
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: ZoneAlarm Toolbar Registrar: {8a4a36c2-0535-4d2c-bd3d-496cb7eed6e3} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: ZoneAlarm Toolbar: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
EB: Copernic Agent Results: {6f480f82-c3a6-4d35-96f7-b297ad49fbe8} - c:\program files\copernic agent\CopernicAgentExt.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [DLCJCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCJtime.dll,_RunDLLEntry@16
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRunOnce: [RunNarrator] Narrator.exe
uPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-explorer: NoResolveTrack = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: 1stpeoplesbank.com\www
Trusted Zone: 1stpeoplesbankhb.com\www
Trusted Zone: bankofamerica.com\www
Trusted Zone: bleepingcomputer.com\www
Trusted Zone: earthcam.net\doliver
Trusted Zone: excite.com\registration
Trusted Zone: excite.com\www
Trusted Zone: grc.com\www
Trusted Zone: keithandschnars.com\www
Trusted Zone: live.com\bl145w.blu145.mail
Trusted Zone: live.com\login
Trusted Zone: live.com\mail
Trusted Zone: msn.com\www
Trusted Zone: netflix.com
Trusted Zone: netflix.com\movies
Trusted Zone: onlinecreditcenter6.com\www
Trusted Zone: sirius.com\www
Trusted Zone: state.fl.us\fdotnfuse.dot
Trusted Zone: techguy.org\www
Trusted Zone: virusvault.co.uk\www
Trusted Zone: yahoo.com\att.my
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://www.celartem.com/en/download/data/djvu_autoinstall/DjVuControl_en_US.cab
DPF: {15B782AF-55D8-11D1-B477-006097098764} - hxxp://download.macromedia.com/pub/shockwave/cabs/authorware/awswax70.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} - hxxps://fdotnfuse.dot.state.fl.us/Citrix/ICAWEB/en/ica32/wficat.cab
DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} - hxxps://support.microsoft.com/OAS/ActiveX/odc.cab
DPF: {321FB770-1FBE-4BFE-BDC1-6F622D4FA499} - hxxps://pbells.broadjump.com/wizlet/iw60/static/controls/WebflowActiveXInstaller_4-0-0.cab
DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} - hxxp://i.dell.com/images/global/js/scanner/SysProExe.cab
DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} - hxxp://moneycentral.msn.com/cabs/pmupd806.exe
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab
DPF: {46D8BEE7-0B27-4466-ABA2-A5F1E157971C} - hxxp://dvr.floridanexuspark.com/RemoteWeb.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/mcinsctl.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120083437937
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1121730826828
DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - hxxp://doliver.earthcam.net/viewer/AMC.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} - hxxp://www3.ca.com/securityadvisor/virusinfo/webscan.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {8D3314D6-5914-46C1-9F3D-9F14B6A305F1} - hxxp://www.mytpi.com/mytpi05/eval/ectuploader.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab
DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} - hxxp://hgtv1.view22.com/view22/app/view22rte.cab
DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://www.cvsphoto.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
DPF: {C237A80A-4C55-4C68-BAA9-CBE4408D12B2} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - hxxp://fdl.msn.com/zone/datafiles/heartbeat.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
DPF: {E7D2588A-7FB5-47DC-8830-832605661009} - hxxps://livewc01.custhelp.com/7550-b415h-quickenmedical/rnl/java/RntX.cab
DPF: {EF0DBA6F-43CE-4B26-9808-2AB38FA0DB29} - hxxp://fdl.msn.com/public/investor/v13/ticker.cab
DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} - hxxp://by107fd.bay107.hotmail.msn.com/activex/HMAtchmt.ocx
DPF: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} - hxxp://www.paslc.org/acgm/f2_acgm.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: copernicagent - {A979B6BD-E40B-4A07-ABDD-A62C64A4EBF6} - c:\progra~1\copern~1\COPERN~1.DLL
Handler: copernicagentcache - {AAC34CFD-274D-4A9D-B0DC-C74C05A67E1D} - c:\progra~1\copern~1\COPERN~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
LSA: Authentication Packages = msv1_0 relog_ap
.
============= SERVICES / DRIVERS ===============
.
R0 kl1;kl1;c:\windows\system32\drivers\kl1.sys [2011-11-22 128016]
R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2011-11-22 317072]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2011-11-22 528128]
R2 ISWKL;ZoneAlarm ForceField ISWKL;c:\program files\checkpoint\zaforcefield\ISWKL.sys [2010-8-27 26352]
R2 IswSvc;ZoneAlarm ForceField IswSvc;c:\program files\checkpoint\zaforcefield\ISWSVC.exe [2010-8-27 493032]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [2009-10-28 12184]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\western digital\wd drive manager\WDBtnMgrSvc.exe [2008-7-24 102400]
R3 icsak;icsak;c:\program files\checkpoint\zaforcefield\ak\icsak.sys [2010-8-27 35568]
R3 NmPar;Unusable Parallel Port;c:\windows\system32\drivers\NmPar.sys [2008-7-31 80512]
R3 nmserial;PCI Serial Port;c:\windows\system32\drivers\NmSerial.sys [2008-7-31 70016]
S2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2011-11-21 252064]
S3 alcan5ln;Alcatel SpeedTouch™ USB ADSL RFC1483 Networking Driver (NDIS);c:\windows\system32\drivers\alcan5ln.sys [2006-3-16 36960]
S3 gupdate1c9c9186781a4fc;Google Update Service (gupdate1c9c9186781a4fc);c:\program files\google\update\GoogleUpdate.exe [2009-4-29 133104]
S3 McTskshd.exe;McAfee Task Scheduler;c:\progra~1\mcafee.com\agent\mctskshd.exe --> c:\progra~1\mcafee.com\agent\mctskshd.exe [?]
S3 mcupdmgr.exe;McAfee SecurityCenter Update Manager;c:\progra~1\mcafee.com\agent\mcupdmgr.exe --> c:\progra~1\mcafee.com\agent\mcupdmgr.exe [?]
S3 NDMSHLP;Device Monitor Helper Driver;c:\program files\common files\hhd software\device monitor\NDMSHLP.sys [2005-5-24 7632]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2004-8-12 14336]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2009-6-17 12648]
S3 SerMon;Serial Monitor Filter Driver;c:\program files\hhd software\free serial port monitor\sermon.sys [2005-5-24 18432]
S4 McDetect.exe;McAfee WSC Integration;c:\program files\mcafee.com\agent\mcdetect.exe --> c:\program files\mcafee.com\agent\mcdetect.exe [?]
.
=============== Created Last 30 ================
.
2011-11-23 03:09:22 128016 ----a-w- c:\windows\system32\drivers\kl1.sys
2011-11-23 03:08:52 1238528 ----a-w- c:\windows\system32\zpeng25.dll
2011-11-23 03:08:52 -------- d-----w- c:\windows\system32\ZoneLabs
2011-11-23 03:08:50 -------- d-----w- c:\program files\Zone Labs
2011-11-23 03:07:20 -------- d-----w- c:\windows\Internet Logs
2011-11-23 02:12:01 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2011-11-23 02:11:59 -------- d-----w- c:\documents and settings\jbandt\local settings\application data\Conduit
2011-11-21 15:40:20 417952 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2011-11-21 15:36:08 -------- d-----w- c:\documents and settings\jbandt\Tracing
2011-11-21 15:34:26 -------- d-----w- c:\program files\Microsoft
2011-11-21 15:34:03 -------- d-----w- c:\program files\Windows Live SkyDrive
2011-11-21 15:29:54 -------- d-----w- c:\program files\common files\Windows Live
2011-11-21 15:13:44 53248 ------r- c:\documents and settings\jbandt\application data\microsoft\installer\{3ee9bcae-e9a9-45e5-9b1c-83a4d357e05c}\ARPPRODUCTICON.exe
2011-11-21 15:13:21 -------- d-----w- c:\documents and settings\jbandt\local settings\application data\Logishrd
2011-11-21 15:13:07 16400 ------w- c:\windows\system32\drivers\LNonPnP.sys
2011-11-21 15:03:53 -------- d-----w- c:\documents and settings\jbandt\application data\Logishrd
2011-11-21 14:29:51 -------- d-----w- c:\documents and settings\jbandt\local settings\application data\Sun
2011-11-21 14:20:23 -------- d-----w- c:\program files\AMD APP
2011-11-21 14:20:10 -------- d-----w- c:\program files\ATI
.
==================== Find3M ====================
.
2011-11-26 13:57:40 69792 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-21 14:28:38 544656 ------w- c:\windows\system32\deployJava1.dll
2011-11-21 14:28:38 128000 ------w- c:\windows\system32\javacpl.cpl
2011-10-26 02:21:48 56832 ------w- c:\windows\system32\OpenVideo.dll
2011-10-26 02:21:34 56832 ------w- c:\windows\system32\OVDecoder.dll
2011-10-26 02:20:42 13950464 ------w- c:\windows\system32\amdocl.dll
2011-10-26 02:19:50 44032 ------w- c:\windows\system32\OpenCL.dll
2011-10-10 14:22:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41:20 611328 ------w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20:51 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-09-02 06:31:28 55064 ------w- c:\windows\system32\LMouFiltCoInst.dll
2011-09-02 06:31:28 39192 ------w- c:\windows\system32\drivers\LMouFilt.Sys
2011-09-02 06:31:20 41240 ------w- c:\windows\system32\drivers\LHidFilt.Sys
2011-09-02 06:31:20 1583896 ------w- c:\windows\system32\LkmdfCoInst.dll
2011-09-02 06:30:58 22040 ------w- c:\windows\system32\drivers\L8042Kbd.sys
2011-09-02 06:30:58 12184 ------w- c:\windows\system32\drivers\LBeepKE.sys
2011-08-31 21:00:50 22216 ------w- c:\windows\system32\drivers\mbam.sys
.
============= FINISH: 20:13:32.18 ===============


Sorry if I've done anything wrong here attacing the logs I could not get back to the desktop to open them. thanks again for you time and help.

#4 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:06:42 AM

Posted 29 November 2011 - 08:51 PM

Hi,

Welcome to Bleeping Computer. My name is m0le and I will be helping you with your log.
  • Please subscribe to this topic, if you haven't already. Click the Watch This Topic button at the top on the right.

  • Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.

  • Please reply to this post so I know you are there.
The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then I will close the topic.

----------------------------------------------

There's nothing immediate in the logs so please run aswMBR to double check Gmer's findings

Please download aswMBR ( 511KB ) to your desktop.
  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.

Posted Image
m0le is a proud member of UNITE

#5 jbandtbone

jbandtbone
  • Topic Starter

  • Members
  • 90 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:42 AM

Posted 30 November 2011 - 05:32 AM

I do have the original Windows CD/DVD available.

aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-11-29 23:05:28
-----------------------------
23:05:28.437 OS Version: Windows 5.1.2600 Service Pack 3
23:05:28.437 Number of processors: 1 586 0x401
23:05:28.437 ComputerName: JBANDTBONE UserName: jbandt
23:05:29.625 Initialize success
23:09:57.328 AVAST engine defs: 11112902
23:16:39.234 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
23:16:39.234 Disk 0 Vendor: WDC_WD75 05.0 Size: 715404MB BusType: 3
23:16:39.250 Disk 0 MBR read successfully
23:16:39.265 Disk 0 MBR scan
23:16:39.312 Disk 0 unknown MBR code
23:16:39.328 Disk 0 scanning sectors +1465144065
23:16:39.406 Disk 0 scanning C:\WINDOWS\system32\drivers
23:17:04.421 Service scanning
23:17:05.640 Service vsdatant C:\WINDOWS\System32\vsdatant.sys **LOCKED** 32
23:17:06.156 Modules scanning
23:17:10.109 Disk 0 trace - called modules:
23:17:10.125 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
23:17:10.125 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b472298]
23:17:10.125 3 CLASSPNP.SYS[ba188fd7] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x8b463030]
23:17:11.500 AVAST engine scan C:\WINDOWS
23:17:52.781 AVAST engine scan C:\WINDOWS\system32
23:21:14.484 AVAST engine scan C:\WINDOWS\system32\drivers
23:21:59.390 AVAST engine scan C:\Documents and Settings\jbandt
00:30:17.281 AVAST engine scan C:\Documents and Settings\All Users
00:35:11.453 Scan finished successfully
05:27:55.765 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\jbandt\Desktop\MBR.dat"
05:27:55.781 The log file has been saved successfully to "C:\Documents and Settings\jbandt\Desktop\aswMBR.txt"

#6 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:06:42 AM

Posted 30 November 2011 - 05:40 PM

That looks fine. Please run MBAM and SAS next

Please download Posted Image Malwarebytes Anti-Malware and save it to your desktop.
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application or, if you are using Vista, right-click and select Run As Administrator on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
    If MBAM won't update then download and update MBAM on a clean computer then save the rules.ref folder to a memory stick. This file is found here: 'C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware' then transfer it across to the infected computer.
  • On the Scanner tab:
    • Make sure the "Perform Full Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. MBAM may make changes to your registry as part of its disinfection routine. If you're using other security programs that detect registry changes, they may alert you after scanning with MBAM. Please permit the program to allow the changes.


And

Download Superantispyware
  • Load Superantispyware and click the check for updates button.
  • Once the update is finished click the scan your computer button.
  • Check Perform Complete Scan and then next.
  • Superantispyware will now scan your computer and when its finished it will list all the infections it has found.
  • Make sure that they all have a check next to them and press next.
  • Click finish and you will be taken back to the main interface.
  • Click Preferences and then click the statistics/logs tab. Click the dated log and press view log and a text file will appear.
  • Copy and paste the log onto the forum.

Posted Image
m0le is a proud member of UNITE

#7 jbandtbone

jbandtbone
  • Topic Starter

  • Members
  • 90 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:42 AM

Posted 30 November 2011 - 10:44 PM

Sorry it took so long but the superantispyware completely froze my system a couple of times. Also I've noticed that when I close anything that I've opened recently thatwhen I close it the image stays on the screen ,but the application,file,etc. actually closes

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8280

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

11/30/2011 8:24:51 PM
mbam-log-2011-11-30 (20-24-51).txt

Scan type: Full scan (A:\|C:\|D:\|E:\|F:\|G:\|I:\|)
Objects scanned: 250092
Time elapsed: 1 hour(s), 53 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/30/2011 at 10:16 PM

Application Version : 5.0.1136

Core Rules Database Version : 8003
Trace Rules Database Version: 5815

Scan type : Complete Scan
Total Scan Time : 00:46:43

Operating System Information
Windows XP Home Edition 32-bit, Service Pack 3 (Build 5.01.2600)
Administrator

Memory items scanned : 456
Memory threats detected : 0
Registry items scanned : 40517
Registry threats detected : 2
File items scanned : 62653
File threats detected : 687

Trojan.Agent/Gen
HKU\.DEFAULT\Software\ColdWare
HKU\S-1-5-18\Software\ColdWare

Adware.Tracking Cookie
C:\Documents and Settings\jbandt\Cookies\jbandt@112.2o7[2].txt [ /112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@247realmedia[1].txt [ /247realmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@247realmedia[2].txt [ /247realmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@247realmedia[3].txt [ /247realmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@a.intentmedia[2].txt [ /a.intentmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@a.websponsors[2].txt [ /a.websponsors ]
C:\Documents and Settings\jbandt\Cookies\jbandt@a1.interclick[1].txt [ /a1.interclick ]
C:\Documents and Settings\jbandt\Cookies\jbandt@account.live[2].txt [ /account.live ]
C:\Documents and Settings\jbandt\Cookies\jbandt@accountonline[1].txt [ /accountonline ]
C:\Documents and Settings\jbandt\Cookies\jbandt@actress.glowclick[1].txt [ /actress.glowclick ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ad.fed.adecn[1].txt [ /ad.fed.adecn ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ad.m5prod[2].txt [ /ad.m5prod ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ad.m5prod[3].txt [ /ad.m5prod ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ad.wsod[2].txt [ /ad.wsod ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ad.yieldmanager[2].txt [ /ad.yieldmanager ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ad.yieldmanager[3].txt [ /ad.yieldmanager ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ad.yieldmanager[4].txt [ /ad.yieldmanager ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ad.zanox[2].txt [ /ad.zanox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ad1.clickhype[1].txt [ /ad1.clickhype ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adbrite[1].txt [ /adbrite ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adbureau[1].txt [ /adbureau ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adecn[1].txt [ /adecn ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adecn[3].txt [ /adecn ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adinterax[2].txt [ /adinterax ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adknowledge[2].txt [ /adknowledge ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adlegend[2].txt [ /adlegend ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adlegend[3].txt [ /adlegend ]
C:\Documents and Settings\jbandt\Cookies\jbandt@admarketplace[1].txt [ /admarketplace ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.10click[1].txt [ /ads.10click ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.addynamix[2].txt [ /ads.addynamix ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.as4x.tmcs.ticketmaster[2].txt [ /ads.as4x.tmcs.ticketmaster ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.associatedcontent[2].txt [ /ads.associatedcontent ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.belointeractive[1].txt [ /ads.belointeractive ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.belointeractive[2].txt [ /ads.belointeractive ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.bleepingcomputer[2].txt [ /ads.bleepingcomputer ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.bleepingcomputer[3].txt [ /ads.bleepingcomputer ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.bootcampmedia[1].txt [ /ads.bootcampmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.bootcampmedia[3].txt [ /ads.bootcampmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.bridgetrack[2].txt [ /ads.bridgetrack ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.bridgetrack[3].txt [ /ads.bridgetrack ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.christianpost[2].txt [ /ads.christianpost ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.cnn[1].txt [ /ads.cnn ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.cpxadroit[2].txt [ /ads.cpxadroit ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.eham[2].txt [ /ads.eham ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.financialcontent[2].txt [ /ads.financialcontent ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.golf[1].txt [ /ads.golf ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.nba[1].txt [ /ads.nba ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.ncaa[1].txt [ /ads.ncaa ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.peoplespharmacy[1].txt [ /ads.peoplespharmacy ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.pgatour[1].txt [ /ads.pgatour ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.pga[1].txt [ /ads.pga ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.pga[2].txt [ /ads.pga ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.roiserver[2].txt [ /ads.roiserver ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.sun[1].txt [ /ads.sun ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.undertone[2].txt [ /ads.undertone ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.vertmarkets[2].txt [ /ads.vertmarkets ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ads.x10[1].txt [ /ads.x10 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adserver.adreactor[1].txt [ /adserver.adreactor ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adserver.adtechus[1].txt [ /adserver.adtechus ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adserver.adtechus[2].txt [ /adserver.adtechus ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adserver.ignitad[2].txt [ /adserver.ignitad ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adserver.marijuana[2].txt [ /adserver.marijuana ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adserver.pctools[2].txt [ /adserver.pctools ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adserving.autotrader[1].txt [ /adserving.autotrader ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adtech[1].txt [ /adtech ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adultfriendfinder[2].txt [ /adultfriendfinder ]
C:\Documents and Settings\jbandt\Cookies\jbandt@advertising[2].txt [ /advertising ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adviva[1].txt [ /adviva ]
C:\Documents and Settings\jbandt\Cookies\jbandt@adxpose[1].txt [ /adxpose ]
C:\Documents and Settings\jbandt\Cookies\jbandt@affiliate.gwmtracker[1].txt [ /affiliate.gwmtracker ]
C:\Documents and Settings\jbandt\Cookies\jbandt@affiliate.idgtracker[1].txt [ /affiliate.idgtracker ]
C:\Documents and Settings\jbandt\Cookies\jbandt@affiliate.oastracker[1].txt [ /affiliate.oastracker ]
C:\Documents and Settings\jbandt\Cookies\jbandt@affiliates.2plus2media[2].txt [ /affiliates.2plus2media ]
C:\Documents and Settings\jbandt\Cookies\jbandt@amazonmerchants.122.2o7[1].txt [ /amazonmerchants.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@amex-insights[2].txt [ /amex-insights ]
C:\Documents and Settings\jbandt\Cookies\jbandt@associatedcontent.112.2o7[1].txt [ /associatedcontent.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@asurioninsuranceservices.122.2o7[1].txt [ /asurioninsuranceservices.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@autoseekandsell[1].txt [ /autoseekandsell ]
C:\Documents and Settings\jbandt\Cookies\jbandt@beacon.dmsinsights[1].txt [ /beacon.dmsinsights ]
C:\Documents and Settings\jbandt\Cookies\jbandt@beacon.dmsinsights[2].txt [ /beacon.dmsinsights ]
C:\Documents and Settings\jbandt\Cookies\jbandt@bigleads.122.2o7[1].txt [ /bigleads.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@bizrate.co[1].txt [ /bizrate.co ]
C:\Documents and Settings\jbandt\Cookies\jbandt@bjwholesaleclub.112.2o7[1].txt [ /bjwholesaleclub.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@bluestreak[1].txt [ /bluestreak ]
C:\Documents and Settings\jbandt\Cookies\jbandt@brandonadvertising.112.2o7[1].txt [ /brandonadvertising.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@bridge1.admarketplace[1].txt [ /bridge1.admarketplace ]
C:\Documents and Settings\jbandt\Cookies\jbandt@burstbeacon[1].txt [ /burstbeacon ]
C:\Documents and Settings\jbandt\Cookies\jbandt@burstbeacon[2].txt [ /burstbeacon ]
C:\Documents and Settings\jbandt\Cookies\jbandt@burstnetads[2].txt [ /burstnetads ]
C:\Documents and Settings\jbandt\Cookies\jbandt@buycom.122.2o7[1].txt [ /buycom.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@bzresults.122.2o7[1].txt [ /bzresults.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@c.gigcount[1].txt [ /c.gigcount ]
C:\Documents and Settings\jbandt\Cookies\jbandt@cache.trafficmp[2].txt [ /cache.trafficmp ]
C:\Documents and Settings\jbandt\Cookies\jbandt@carfax.112.2o7[1].txt [ /carfax.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@cb.adbureau[2].txt [ /cb.adbureau ]
C:\Documents and Settings\jbandt\Cookies\jbandt@cdn.uc.atwola[2].txt [ /cdn.uc.atwola ]
C:\Documents and Settings\jbandt\Cookies\jbandt@cdn1.trafficmp[2].txt [ /cdn1.trafficmp ]
C:\Documents and Settings\jbandt\Cookies\jbandt@cdn4.specificclick[1].txt [ /cdn4.specificclick ]
C:\Documents and Settings\jbandt\Cookies\jbandt@cdnh.tremormedia[1].txt [ /cdnh.tremormedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@celi-usb-serial-converter-drivers.software.informer[2].txt [ /celi-usb-serial-converter-drivers.software.informer ]
C:\Documents and Settings\jbandt\Cookies\jbandt@chitika[2].txt [ /chitika ]
C:\Documents and Settings\jbandt\Cookies\jbandt@click.bsftransmit2[1].txt [ /click.bsftransmit2 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@click.bsftransmit2[2].txt [ /click.bsftransmit2 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@clickandsavegolf.stores.yahoo[1].txt [ /clickandsavegolf.stores.yahoo ]
C:\Documents and Settings\jbandt\Cookies\jbandt@clickbank[2].txt [ /clickbank ]
C:\Documents and Settings\jbandt\Cookies\jbandt@clickboothlnk[1].txt [ /clickboothlnk ]
C:\Documents and Settings\jbandt\Cookies\jbandt@clickshift[1].txt [ /clickshift ]
C:\Documents and Settings\jbandt\Cookies\jbandt@clicksor[1].txt [ /clicksor ]
C:\Documents and Settings\jbandt\Cookies\jbandt@clicksor[3].txt [ /clicksor ]
C:\Documents and Settings\jbandt\Cookies\jbandt@cmn.adbureau[2].txt [ /cmn.adbureau ]
C:\Documents and Settings\jbandt\Cookies\jbandt@cms.trafficmp[1].txt [ /cms.trafficmp ]
C:\Documents and Settings\jbandt\Cookies\jbandt@collective-media[1].txt [ /collective-media ]
C:\Documents and Settings\jbandt\Cookies\jbandt@collective-media[3].txt [ /collective-media ]
C:\Documents and Settings\jbandt\Cookies\jbandt@collector.thermstats[2].txt [ /collector.thermstats ]
C:\Documents and Settings\jbandt\Cookies\jbandt@comcast.112.2o7[1].txt [ /comcast.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@comparenetworks.112.2o7[1].txt [ /comparenetworks.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@content.yieldmanager[1].txt [ /content.yieldmanager ]
C:\Documents and Settings\jbandt\Cookies\jbandt@content.yieldmanager[2].txt [ /content.yieldmanager ]
C:\Documents and Settings\jbandt\Cookies\jbandt@content.yieldmanager[3].txt [ /content.yieldmanager ]
C:\Documents and Settings\jbandt\Cookies\jbandt@converse.112.2o7[1].txt [ /converse.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@costumediscounters[2].txt [ /costumediscounters ]
C:\Documents and Settings\jbandt\Cookies\jbandt@counter.hitslink[1].txt [ /counter.hitslink ]
C:\Documents and Settings\jbandt\Cookies\jbandt@counter.surfcounters[1].txt [ /counter.surfcounters ]
C:\Documents and Settings\jbandt\Cookies\jbandt@counter.surfcounters[2].txt [ /counter.surfcounters ]
C:\Documents and Settings\jbandt\Cookies\jbandt@counter2.hitslink[1].txt [ /counter2.hitslink ]
C:\Documents and Settings\jbandt\Cookies\jbandt@data.coremetrics[1].txt [ /data.coremetrics ]
C:\Documents and Settings\jbandt\Cookies\jbandt@dc.tremormedia[2].txt [ /dc.tremormedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@dealtime[2].txt [ /dealtime ]
C:\Documents and Settings\jbandt\Cookies\jbandt@demandwarecrocs.112.2o7[1].txt [ /demandwarecrocs.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@dfsdirectsales.122.2o7[1].txt [ /dfsdirectsales.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@discount-pool[2].txt [ /discount-pool ]
C:\Documents and Settings\jbandt\Cookies\jbandt@discountcontactlenses[2].txt [ /discountcontactlenses ]
C:\Documents and Settings\jbandt\Cookies\jbandt@discountgolfworld[2].txt [ /discountgolfworld ]
C:\Documents and Settings\jbandt\Cookies\jbandt@discountgolfworld[3].txt [ /discountgolfworld ]
C:\Documents and Settings\jbandt\Cookies\jbandt@discountsafetygear[1].txt [ /discountsafetygear ]
C:\Documents and Settings\jbandt\Cookies\jbandt@dmtracker[1].txt [ /dmtracker ]
C:\Documents and Settings\jbandt\Cookies\jbandt@dominionenterprises.112.2o7[1].txt [ /dominionenterprises.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@e-2dj6wfkyamc5klp.stats.esomniture[2].txt [ /e-2dj6wfkyamc5klp.stats.esomniture ]
C:\Documents and Settings\jbandt\Cookies\jbandt@e-2dj6whmigicpwco.stats.esomniture[2].txt [ /e-2dj6whmigicpwco.stats.esomniture ]
C:\Documents and Settings\jbandt\Cookies\jbandt@e-2dj6wjlywkajiko.stats.esomniture[2].txt [ /e-2dj6wjlywkajiko.stats.esomniture ]
C:\Documents and Settings\jbandt\Cookies\jbandt@e1.cdn.qnsr[1].txt [ /e1.cdn.qnsr ]
C:\Documents and Settings\jbandt\Cookies\jbandt@eas.apm.emediate[1].txt [ /eas.apm.emediate ]
C:\Documents and Settings\jbandt\Cookies\jbandt@edgeadx[2].txt [ /edgeadx ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg-airtran.hitbox[1].txt [ /ehg-airtran.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg-airtran.hitbox[2].txt [ /ehg-airtran.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg-airtran.hitbox[3].txt [ /ehg-airtran.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg-briggsandstratton.hitbox[2].txt [ /ehg-briggsandstratton.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg-emmiscommunications.hitbox[2].txt [ /ehg-emmiscommunications.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg-eset.hitbox[1].txt [ /ehg-eset.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg-eset.hitbox[2].txt [ /ehg-eset.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg-eset.hitbox[4].txt [ /ehg-eset.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg-findlaw.hitbox[2].txt [ /ehg-findlaw.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg-infospace.hitbox[1].txt [ /ehg-infospace.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg-lgusa.hitbox[2].txt [ /ehg-lgusa.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg-maximhealthcare.hitbox[2].txt [ /ehg-maximhealthcare.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg-ti.hitbox[1].txt [ /ehg-ti.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg-verizon.hitbox[1].txt [ /ehg-verizon.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg-verizon.hitbox[3].txt [ /ehg-verizon.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg-viacom.hitbox[2].txt [ /ehg-viacom.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg-websitebiz.hitbox[1].txt [ /ehg-websitebiz.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg-winnercomm.hitbox[2].txt [ /ehg-winnercomm.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ehg.hitbox[2].txt [ /ehg.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@elite-xpressions[2].txt [ /elite-xpressions ]
C:\Documents and Settings\jbandt\Cookies\jbandt@enhance[2].txt [ /enhance ]
C:\Documents and Settings\jbandt\Cookies\jbandt@enhance[3].txt [ /enhance ]
C:\Documents and Settings\jbandt\Cookies\jbandt@eset.122.2o7[1].txt [ /eset.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@eventbrite.122.2o7[1].txt [ /eventbrite.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@evite.112.2o7[1].txt [ /evite.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ewstv.112.2o7[1].txt [ /ewstv.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@eyewonder[1].txt [ /eyewonder ]
C:\Documents and Settings\jbandt\Cookies\jbandt@farecastcom.122.2o7[1].txt [ /farecastcom.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@feed.validclick[1].txt [ /feed.validclick ]
C:\Documents and Settings\jbandt\Cookies\jbandt@finalmediaplayer[2].txt [ /finalmediaplayer ]
C:\Documents and Settings\jbandt\Cookies\jbandt@findlaw[1].txt [ /findlaw ]
C:\Documents and Settings\jbandt\Cookies\jbandt@findlegalforms[3].txt [ /findlegalforms ]
C:\Documents and Settings\jbandt\Cookies\jbandt@fls.doubleclick[2].txt [ /fls.doubleclick ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ge.112.2o7[1].txt [ /ge.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@geconsumerfinance.112.2o7[1].txt [ /geconsumerfinance.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@giftscom.122.2o7[1].txt [ /giftscom.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@golfdiscountsuperstore[2].txt [ /golfdiscountsuperstore ]
C:\Documents and Settings\jbandt\Cookies\jbandt@golfdiscount[2].txt [ /golfdiscount ]
C:\Documents and Settings\jbandt\Cookies\jbandt@golfrangefinderreviews[1].txt [ /golfrangefinderreviews ]
C:\Documents and Settings\jbandt\Cookies\jbandt@golfrangefinders[1].txt [ /golfrangefinders ]
C:\Documents and Settings\jbandt\Cookies\jbandt@gsicace.112.2o7[1].txt [ /gsicace.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@healthgrades.112.2o7[1].txt [ /healthgrades.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@healthwiseorg.112.2o7[1].txt [ /healthwiseorg.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@hearstdigital.122.2o7[1].txt [ /hearstdigital.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@hearstmagazines.112.2o7[1].txt [ /hearstmagazines.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@hg1.hitbox[1].txt [ /hg1.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@hitbox[2].txt [ /hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@hitbox[3].txt [ /hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@homeclick[2].txt [ /homeclick ]
C:\Documents and Settings\jbandt\Cookies\jbandt@homedecor.122.2o7[1].txt [ /homedecor.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@homelite[2].txt [ /homelite ]
C:\Documents and Settings\jbandt\Cookies\jbandt@homelite[3].txt [ /homelite ]
C:\Documents and Settings\jbandt\Cookies\jbandt@homesteadtechnologies.122.2o7[1].txt [ /homesteadtechnologies.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@homestore.122.2o7[1].txt [ /homestore.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@hypertracker[1].txt [ /hypertracker ]
C:\Documents and Settings\jbandt\Cookies\jbandt@hypertracker[2].txt [ /hypertracker ]
C:\Documents and Settings\jbandt\Cookies\jbandt@i4commerce.112.2o7[1].txt [ /i4commerce.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@iacas.adbureau[2].txt [ /iacas.adbureau ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ice.112.2o7[1].txt [ /ice.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ie-stat.bmmetrix[2].txt [ /ie-stat.bmmetrix ]
C:\Documents and Settings\jbandt\Cookies\jbandt@imrworldwide[1].txt [ /imrworldwide ]
C:\Documents and Settings\jbandt\Cookies\jbandt@in.getclicky[1].txt [ /in.getclicky ]
C:\Documents and Settings\jbandt\Cookies\jbandt@incentaclick[2].txt [ /incentaclick ]
C:\Documents and Settings\jbandt\Cookies\jbandt@indextools[2].txt [ /indextools ]
C:\Documents and Settings\jbandt\Cookies\jbandt@insightexpressai[1].txt [ /insightexpressai ]
C:\Documents and Settings\jbandt\Cookies\jbandt@insightexpressai[2].txt [ /insightexpressai ]
C:\Documents and Settings\jbandt\Cookies\jbandt@instantpeoplefinder[2].txt [ /instantpeoplefinder ]
C:\Documents and Settings\jbandt\Cookies\jbandt@interclick[1].txt [ /interclick ]
C:\Documents and Settings\jbandt\Cookies\jbandt@interclick[3].txt [ /interclick ]
C:\Documents and Settings\jbandt\Cookies\jbandt@invitemedia[1].txt [ /invitemedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@invitemedia[3].txt [ /invitemedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@irishtimesgroup.112.2o7[1].txt [ /irishtimesgroup.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@kaboose.112.2o7[1].txt [ /kaboose.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@kanoodle[2].txt [ /kanoodle ]
C:\Documents and Settings\jbandt\Cookies\jbandt@kaspersky.122.2o7[2].txt [ /kaspersky.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@lfstmedia[2].txt [ /lfstmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@lgelectronics.122.2o7[1].txt [ /lgelectronics.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@lgeus.122.2o7[1].txt [ /lgeus.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@libertymutual.112.2o7[1].txt [ /libertymutual.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@link.mercent[1].txt [ /link.mercent ]
C:\Documents and Settings\jbandt\Cookies\jbandt@link.mercent[3].txt [ /link.mercent ]
C:\Documents and Settings\jbandt\Cookies\jbandt@linksynergy[2].txt [ /linksynergy ]
C:\Documents and Settings\jbandt\Cookies\jbandt@livenation.122.2o7[1].txt [ /livenation.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@liveperson[3].txt [ /liveperson ]
C:\Documents and Settings\jbandt\Cookies\jbandt@liveperson[6].txt [ /liveperson ]
C:\Documents and Settings\jbandt\Cookies\jbandt@liveperson[7].txt [ /liveperson ]
C:\Documents and Settings\jbandt\Cookies\jbandt@lockedonmedia[2].txt [ /lockedonmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@lucidmedia[1].txt [ /lucidmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@lynxtrack[2].txt [ /lynxtrack ]
C:\Documents and Settings\jbandt\Cookies\jbandt@marketlive.122.2o7[1].txt [ /marketlive.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@marriottinternational.122.2o7[1].txt [ /marriottinternational.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@media.cardomain[1].txt [ /media.cardomain ]
C:\Documents and Settings\jbandt\Cookies\jbandt@media.legacy[1].txt [ /media.legacy ]
C:\Documents and Settings\jbandt\Cookies\jbandt@media.legacy[2].txt [ /media.legacy ]
C:\Documents and Settings\jbandt\Cookies\jbandt@media.mtvnservices[4].txt [ /media.mtvnservices ]
C:\Documents and Settings\jbandt\Cookies\jbandt@media.photobucket[1].txt [ /media.photobucket ]
C:\Documents and Settings\jbandt\Cookies\jbandt@media6degrees[1].txt [ /media6degrees ]
C:\Documents and Settings\jbandt\Cookies\jbandt@mediaforgews[2].txt [ /mediaforgews ]
C:\Documents and Settings\jbandt\Cookies\jbandt@mediaforge[1].txt [ /mediaforge ]
C:\Documents and Settings\jbandt\Cookies\jbandt@mediapromoter[2].txt [ /mediapromoter ]
C:\Documents and Settings\jbandt\Cookies\jbandt@mediastore.verizonwireless[1].txt [ /mediastore.verizonwireless ]
C:\Documents and Settings\jbandt\Cookies\jbandt@metroleap.rotator.hadj7.adjuggler[2].txt [ /metroleap.rotator.hadj7.adjuggler ]
C:\Documents and Settings\jbandt\Cookies\jbandt@microsoftinternetexplorer.112.2o7[1].txt [ /microsoftinternetexplorer.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@microsoftoffice.112.2o7[1].txt [ /microsoftoffice.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@microsoftsto.112.2o7[1].txt [ /microsoftsto.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@microsoftwindows.112.2o7[1].txt [ /microsoftwindows.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@microsoftwlcashback.112.2o7[1].txt [ /microsoftwlcashback.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@microsoftwllivemkt.112.2o7[1].txt [ /microsoftwllivemkt.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@microsoftwlsearchcrm.112.2o7[1].txt [ /microsoftwlsearchcrm.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@msnbc.112.2o7[2].txt [ /msnbc.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@msnportal.112.2o7[1].txt [ /msnportal.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@myaccount.bellsouth[1].txt [ /myaccount.bellsouth ]
C:\Documents and Settings\jbandt\Cookies\jbandt@myaccount.bellsouth[3].txt [ /myaccount.bellsouth ]
C:\Documents and Settings\jbandt\Cookies\jbandt@myaccount.verizonwireless[1].txt [ /myaccount.verizonwireless ]
C:\Documents and Settings\jbandt\Cookies\jbandt@myroitracking[1].txt [ /myroitracking ]
C:\Documents and Settings\jbandt\Cookies\jbandt@myroitracking[2].txt [ /myroitracking ]
C:\Documents and Settings\jbandt\Cookies\jbandt@myweather.112.2o7[1].txt [ /myweather.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@nextag[1].txt [ /nextag ]
C:\Documents and Settings\jbandt\Cookies\jbandt@nextag[2].txt [ /nextag ]
C:\Documents and Settings\jbandt\Cookies\jbandt@nikon.112.2o7[1].txt [ /nikon.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@nineteen47[1].txt [ /nineteen47 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@nxtscrn.adbureau[2].txt [ /nxtscrn.adbureau ]
C:\Documents and Settings\jbandt\Cookies\jbandt@oasn04.247realmedia[1].txt [ /oasn04.247realmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@oasn04.247realmedia[2].txt [ /oasn04.247realmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@oddcast[1].txt [ /oddcast ]
C:\Documents and Settings\jbandt\Cookies\jbandt@oddcast[2].txt [ /oddcast ]
C:\Documents and Settings\jbandt\Cookies\jbandt@onetoone.112.2o7[1].txt [ /onetoone.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@onrampadvertising[2].txt [ /onrampadvertising ]
C:\Documents and Settings\jbandt\Cookies\jbandt@optimize.indieclick[2].txt [ /optimize.indieclick ]
C:\Documents and Settings\jbandt\Cookies\jbandt@optimost[1].txt [ /optimost ]
C:\Documents and Settings\jbandt\Cookies\jbandt@palmbeachpost.stats[1].txt [ /palmbeachpost.stats ]
C:\Documents and Settings\jbandt\Cookies\jbandt@parade.122.2o7[1].txt [ /parade.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@partsearch.122.2o7[1].txt [ /partsearch.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@paypal.112.2o7[2].txt [ /paypal.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@perf.overture[1].txt [ /perf.overture ]
C:\Documents and Settings\jbandt\Cookies\jbandt@phg.hitbox[2].txt [ /phg.hitbox ]
C:\Documents and Settings\jbandt\Cookies\jbandt@pluckit.demandmedia[1].txt [ /pluckit.demandmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@poolsupplyworld.122.2o7[1].txt [ /poolsupplyworld.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@pornhub[2].txt [ /pornhub ]
C:\Documents and Settings\jbandt\Cookies\jbandt@premiumtv.122.2o7[1].txt [ /premiumtv.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@publishers.clickbooth[1].txt [ /publishers.clickbooth ]
C:\Documents and Settings\jbandt\Cookies\jbandt@qksrv[1].txt [ /qksrv ]
C:\Documents and Settings\jbandt\Cookies\jbandt@qnsr[2].txt [ /qnsr ]
C:\Documents and Settings\jbandt\Cookies\jbandt@questsoftware.112.2o7[1].txt [ /questsoftware.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@r.unicornmedia[1].txt [ /r.unicornmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@rbbt.buddymedia[2].txt [ /rbbt.buddymedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@rbbt.buddymedia[3].txt [ /rbbt.buddymedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@redvector.112.2o7[1].txt [ /redvector.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@reorder.discountcontactlenses[1].txt [ /reorder.discountcontactlenses ]
C:\Documents and Settings\jbandt\Cookies\jbandt@revenue[1].txt [ /revenue ]
C:\Documents and Settings\jbandt\Cookies\jbandt@revsci[1].txt [ /revsci ]
C:\Documents and Settings\jbandt\Cookies\jbandt@revsci[2].txt [ /revsci ]
C:\Documents and Settings\jbandt\Cookies\jbandt@revsci[3].txt [ /revsci ]
C:\Documents and Settings\jbandt\Cookies\jbandt@richmedia.yahoo[2].txt [ /richmedia.yahoo ]
C:\Documents and Settings\jbandt\Cookies\jbandt@roiservice[1].txt [ /roiservice ]
C:\Documents and Settings\jbandt\Cookies\jbandt@roiservice[3].txt [ /roiservice ]
C:\Documents and Settings\jbandt\Cookies\jbandt@rotator.hadj7.adjuggler[1].txt [ /rotator.hadj7.adjuggler ]
C:\Documents and Settings\jbandt\Cookies\jbandt@rstracking[2].txt [ /rstracking ]
C:\Documents and Settings\jbandt\Cookies\jbandt@ru4[1].txt [ /ru4 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@s.clickability[1].txt [ /s.clickability ]
C:\Documents and Settings\jbandt\Cookies\jbandt@s05.flagcounter[1].txt [ /s05.flagcounter ]
C:\Documents and Settings\jbandt\Cookies\jbandt@sales.liveperson[1].txt [ /sales.liveperson ]
C:\Documents and Settings\jbandt\Cookies\jbandt@sales.liveperson[2].txt [ /sales.liveperson ]
C:\Documents and Settings\jbandt\Cookies\jbandt@sales.liveperson[3].txt [ /sales.liveperson ]
C:\Documents and Settings\jbandt\Cookies\jbandt@sales.liveperson[4].txt [ /sales.liveperson ]
C:\Documents and Settings\jbandt\Cookies\jbandt@sales.liveperson[5].txt [ /sales.liveperson ]
C:\Documents and Settings\jbandt\Cookies\jbandt@sales.liveperson[6].txt [ /sales.liveperson ]
C:\Documents and Settings\jbandt\Cookies\jbandt@sales.liveperson[8].txt [ /sales.liveperson ]
C:\Documents and Settings\jbandt\Cookies\jbandt@samsclub.112.2o7[1].txt [ /samsclub.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@sdctrack.thomasnet[1].txt [ /sdctrack.thomasnet ]
C:\Documents and Settings\jbandt\Cookies\jbandt@sdctrack.thomasnet[3].txt [ /sdctrack.thomasnet ]
C:\Documents and Settings\jbandt\Cookies\jbandt@sears.112.2o7[1].txt [ /sears.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@sec1.liveperson[3].txt [ /sec1.liveperson ]
C:\Documents and Settings\jbandt\Cookies\jbandt@servedby.adxpower[1].txt [ /servedby.adxpower ]
C:\Documents and Settings\jbandt\Cookies\jbandt@server.iad.liveperson[1].txt [ /server.iad.liveperson ]
C:\Documents and Settings\jbandt\Cookies\jbandt@server.iad.liveperson[2].txt [ /server.iad.liveperson ]
C:\Documents and Settings\jbandt\Cookies\jbandt@server.iad.liveperson[3].txt [ /server.iad.liveperson ]
C:\Documents and Settings\jbandt\Cookies\jbandt@server.iad.liveperson[4].txt [ /server.iad.liveperson ]
C:\Documents and Settings\jbandt\Cookies\jbandt@server.iad.liveperson[6].txt [ /server.iad.liveperson ]
C:\Documents and Settings\jbandt\Cookies\jbandt@service.liveperson[1].txt [ /service.liveperson ]
C:\Documents and Settings\jbandt\Cookies\jbandt@shopping.112.2o7[1].txt [ /shopping.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@sigolfnation.buddymedia[1].txt [ /sigolfnation.buddymedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@smartadserver[1].txt [ /smartadserver ]
C:\Documents and Settings\jbandt\Cookies\jbandt@snapfish.112.2o7[2].txt [ /snapfish.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@socialmedia[1].txt [ /socialmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@socialmedia[2].txt [ /socialmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@specificclick[2].txt [ /specificclick ]
C:\Documents and Settings\jbandt\Cookies\jbandt@specificmedia[1].txt [ /specificmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@specificmedia[3].txt [ /specificmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@specificmedia[4].txt [ /specificmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@specificmedia[5].txt [ /specificmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@srv.clickfuse[1].txt [ /srv.clickfuse ]
C:\Documents and Settings\jbandt\Cookies\jbandt@stampscom.112.2o7[1].txt [ /stampscom.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@stat.onestat[2].txt [ /stat.onestat ]
C:\Documents and Settings\jbandt\Cookies\jbandt@states.flagcounter[1].txt [ /states.flagcounter ]
C:\Documents and Settings\jbandt\Cookies\jbandt@stats.clear-media[1].txt [ /stats.clear-media ]
C:\Documents and Settings\jbandt\Cookies\jbandt@stats.ebay[2].txt [ /stats.ebay ]
C:\Documents and Settings\jbandt\Cookies\jbandt@stats.gamestop[1].txt [ /stats.gamestop ]
C:\Documents and Settings\jbandt\Cookies\jbandt@stats.insurancetopquote[2].txt [ /stats.insurancetopquote ]
C:\Documents and Settings\jbandt\Cookies\jbandt@stats.manticoretechnology[2].txt [ /stats.manticoretechnology ]
C:\Documents and Settings\jbandt\Cookies\jbandt@stats.paypal[1].txt [ /stats.paypal ]
C:\Documents and Settings\jbandt\Cookies\jbandt@stats.paypal[3].txt [ /stats.paypal ]
C:\Documents and Settings\jbandt\Cookies\jbandt@statsadv.dadapro[1].txt [ /statsadv.dadapro ]
C:\Documents and Settings\jbandt\Cookies\jbandt@statsadv.dada[1].txt [ /statsadv.dada ]
C:\Documents and Settings\jbandt\Cookies\jbandt@statse.webtrendslive[1].txt [ /statse.webtrendslive ]
C:\Documents and Settings\jbandt\Cookies\jbandt@statse.webtrendslive[3].txt [ /statse.webtrendslive ]
C:\Documents and Settings\jbandt\Cookies\jbandt@stluciecountypropertyappraiser[1].txt [ /stluciecountypropertyappraiser ]
C:\Documents and Settings\jbandt\Cookies\jbandt@stpetersburgtimes.122.2o7[1].txt [ /stpetersburgtimes.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@superstats[1].txt [ /superstats ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tacoda[1].txt [ /tacoda ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tacoda[2].txt [ /tacoda ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tacoda[4].txt [ /tacoda ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tacoda[5].txt [ /tacoda ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tag.adknowledge[1].txt [ /tag.adknowledge ]
C:\Documents and Settings\jbandt\Cookies\jbandt@technoratimedia[1].txt [ /technoratimedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@technoratimedia[2].txt [ /technoratimedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@test.coremetrics[2].txt [ /test.coremetrics ]
C:\Documents and Settings\jbandt\Cookies\jbandt@testdata.coremetrics[1].txt [ /testdata.coremetrics ]
C:\Documents and Settings\jbandt\Cookies\jbandt@theclicker.today[1].txt [ /theclicker.today ]
C:\Documents and Settings\jbandt\Cookies\jbandt@thefind[2].txt [ /thefind ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tjx.112.2o7[1].txt [ /tjx.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@track.bestbuy[2].txt [ /track.bestbuy ]
C:\Documents and Settings\jbandt\Cookies\jbandt@track.wellsfargodealerservices[1].txt [ /track.wellsfargodealerservices ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tracker.opticsplanet[2].txt [ /tracker.opticsplanet ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tracker.roitesting[1].txt [ /tracker.roitesting ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tracking.admarketplace[1].txt [ /tracking.admarketplace ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tracking.dsmmadvantage[1].txt [ /tracking.dsmmadvantage ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tracking.feedperfect[2].txt [ /tracking.feedperfect ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tracking.foundry42[1].txt [ /tracking.foundry42 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tracking.foundry42[2].txt [ /tracking.foundry42 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tracking.hostgator[1].txt [ /tracking.hostgator ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tracking.keywordmax[1].txt [ /tracking.keywordmax ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tracking.maingateinc[2].txt [ /tracking.maingateinc ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tracking.realtor[1].txt [ /tracking.realtor ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tracking.z-tracking[1].txt [ /tracking.z-tracking ]
C:\Documents and Settings\jbandt\Cookies\jbandt@trackit.sitescout[1].txt [ /trackit.sitescout ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tradedoubler[2].txt [ /tradedoubler ]
C:\Documents and Settings\jbandt\Cookies\jbandt@traffic.buyservices[2].txt [ /traffic.buyservices ]
C:\Documents and Settings\jbandt\Cookies\jbandt@traffic.prod.cobaltgroup[1].txt [ /traffic.prod.cobaltgroup ]
C:\Documents and Settings\jbandt\Cookies\jbandt@traffic.prod.cobaltgroup[2].txt [ /traffic.prod.cobaltgroup ]
C:\Documents and Settings\jbandt\Cookies\jbandt@trafficrevenue[1].txt [ /trafficrevenue ]
C:\Documents and Settings\jbandt\Cookies\jbandt@trafficsafetystore[2].txt [ /trafficsafetystore ]
C:\Documents and Settings\jbandt\Cookies\jbandt@tripod[1].txt [ /tripod ]
C:\Documents and Settings\jbandt\Cookies\jbandt@truitionsirius.122.2o7[1].txt [ /truitionsirius.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@truitionxmradio.122.2o7[1].txt [ /truitionxmradio.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@trvlnet.adbureau[1].txt [ /trvlnet.adbureau ]
C:\Documents and Settings\jbandt\Cookies\jbandt@uol.realmedia[2].txt [ /uol.realmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@uscanteen[1].txt [ /uscanteen ]
C:\Documents and Settings\jbandt\Cookies\jbandt@viacom.adbureau[2].txt [ /viacom.adbureau ]
C:\Documents and Settings\jbandt\Cookies\jbandt@viacom.adbureau[3].txt [ /viacom.adbureau ]
C:\Documents and Settings\jbandt\Cookies\jbandt@vidego.multicastmedia[2].txt [ /vidego.multicastmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@videoegg.adbureau[2].txt [ /videoegg.adbureau ]
C:\Documents and Settings\jbandt\Cookies\jbandt@vitacost.122.2o7[1].txt [ /vitacost.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@volkswagen.122.2o7[1].txt [ /volkswagen.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@walmart.112.2o7[1].txt [ /walmart.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@warnerbros.112.2o7[1].txt [ /warnerbros.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@web4.realtracker[2].txt [ /web4.realtracker ]
C:\Documents and Settings\jbandt\Cookies\jbandt@wigandhatdiscounters[1].txt [ /wigandhatdiscounters ]
C:\Documents and Settings\jbandt\Cookies\jbandt@winzip.122.2o7[1].txt [ /winzip.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@wpni.112.2o7[1].txt [ /wpni.112.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.3dstats[1].txt [ /www.3dstats ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.accountonline[1].txt [ /www.accountonline ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.accountonline[2].txt [ /www.accountonline ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.accountonline[3].txt [ /www.accountonline ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.accountonline[4].txt [ /www.accountonline ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.adxtrack[1].txt [ /www.adxtrack ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.autoseekandsell[1].txt [ /www.autoseekandsell ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.burstbeacon[2].txt [ /www.burstbeacon ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.burstbeacon[3].txt [ /www.burstbeacon ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.clickmanage[2].txt [ /www.clickmanage ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.co2stats[2].txt [ /www.co2stats ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.costumediscounters[2].txt [ /www.costumediscounters ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.dealtime[2].txt [ /www.dealtime ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.discountgolfworld[2].txt [ /www.discountgolfworld ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.discountgolfworld[3].txt [ /www.discountgolfworld ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.ecardmedia[2].txt [ /www.ecardmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.ecoretrack[1].txt [ /www.ecoretrack ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.epitrack[1].txt [ /www.epitrack ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.findaflushot[1].txt [ /www.findaflushot ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.findlegalforms[1].txt [ /www.findlegalforms ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.googleadservices[1].txt [ /www.googleadservices ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.googleadservices[2].txt [ /www.googleadservices ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.googleadservices[3].txt [ /www.googleadservices ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.googleadservices[4].txt [ /www.googleadservices ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.googleadservices[5].txt [ /www.googleadservices ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.googleadservices[6].txt [ /www.googleadservices ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.googleadservices[8].txt [ /www.googleadservices ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.homeclick[2].txt [ /www.homeclick ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.incentaclick[2].txt [ /www.incentaclick ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.jartrack[1].txt [ /www.jartrack ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.nextag[1].txt [ /www.nextag ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.nineteen47[2].txt [ /www.nineteen47 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.peoplefinders[1].txt [ /www.peoplefinders ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.sellmeyourtraffic[1].txt [ /www.sellmeyourtraffic ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.sexmv[2].txt [ /www.sexmv ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.sexmv[3].txt [ /www.sexmv ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.stluciecountypropertyappraiser[2].txt [ /www.stluciecountypropertyappraiser ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.trafficrevenue[2].txt [ /www.trafficrevenue ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.trafficsafetystore[2].txt [ /www.trafficsafetystore ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.visitor-track[2].txt [ /www.visitor-track ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www.windowsmedia[2].txt [ /www.windowsmedia ]
C:\Documents and Settings\jbandt\Cookies\jbandt@www3.addfreestats[1].txt [ /www3.addfreestats ]
C:\Documents and Settings\jbandt\Cookies\jbandt@xiti[1].txt [ /xiti ]
C:\Documents and Settings\jbandt\Cookies\jbandt@xml.trafficengine[1].txt [ /xml.trafficengine ]
C:\Documents and Settings\jbandt\Cookies\jbandt@xpem.122.2o7[1].txt [ /xpem.122.2o7 ]
C:\Documents and Settings\jbandt\Cookies\jbandt@yadro[1].txt [ /yadro ]
C:\Documents and Settings\jbandt\Cookies\jbandt@yardagerangefinder[1].txt [ /yardagerangefinder ]
C:\Documents and Settings\jbandt\Cookies\jbandt@yieldmanager[1].txt [ /yieldmanager ]
C:\Documents and Settings\jbandt\Cookies\jbandt@yieldmanager[2].txt [ /yieldmanager ]
C:\Documents and Settings\jbandt\Cookies\jbandt@z.blogads[2].txt [ /z.blogads ]
C:\Documents and Settings\jbandt\Cookies\jbandt@zillow.adbureau[2].txt [ /zillow.adbureau ]
C:\Documents and Settings\jbandt\Cookies\T824UZX8.txt [ /eyewonder.com ]
C:\Documents and Settings\jbandt\Cookies\V1EL9U2F.txt [ /overture.com ]
C:\Documents and Settings\jbandt\Cookies\LPX164IB.txt [ /hitbox.com ]
C:\Documents and Settings\jbandt\Cookies\38364CHI.txt [ /accountonline.com ]
C:\Documents and Settings\jbandt\Cookies\GP6OYNYZ.txt [ /2o7.net ]
C:\Documents and Settings\jbandt\Cookies\YCAOAW6W.txt [ /atdmt.com ]
C:\Documents and Settings\jbandt\Cookies\C68VG26I.txt [ /citi.bridgetrack.com ]
C:\Documents and Settings\jbandt\Cookies\JIP1MEOE.txt [ /at.atwola.com ]
C:\Documents and Settings\jbandt\Cookies\QS9DX6R3.txt [ /a1.interclick.com ]
C:\Documents and Settings\jbandt\Cookies\TL22AQB6.txt [ /realmedia.com ]
C:\Documents and Settings\jbandt\Cookies\V7ZSPZW5.txt [ /ads.undertone.com ]
C:\Documents and Settings\jbandt\Cookies\98CB2JHF.txt [ /ads.bridgetrack.com ]
C:\Documents and Settings\jbandt\Cookies\V4NJPOH3.txt [ /media.adfrontiers.com ]
C:\Documents and Settings\jbandt\Cookies\7K8LXQ2D.txt [ /revsci.net ]
C:\Documents and Settings\jbandt\Cookies\3JOZGI93.txt [ /questionmarket.com ]
C:\Documents and Settings\jbandt\Cookies\Q019GSU2.txt [ /trafficmp.com ]
C:\Documents and Settings\jbandt\Cookies\P8BNV9LH.txt [ /dc.tremormedia.com ]
C:\Documents and Settings\jbandt\Cookies\00S83YR9.txt [ /getclicky.com ]
C:\Documents and Settings\jbandt\Cookies\9CMYFDMX.txt [ /collective-media.net ]
C:\Documents and Settings\jbandt\Cookies\R1BRU64A.txt [ /richmedia.yahoo.com ]
C:\Documents and Settings\jbandt\Cookies\MQBZYIAW.txt [ /serving-sys.com ]
C:\Documents and Settings\jbandt\Cookies\I32UQ1GT.txt [ /burstnet.com ]
C:\Documents and Settings\jbandt\Cookies\M8UM61YJ.txt [ /adinterax.com ]
C:\Documents and Settings\jbandt\Cookies\V05RX0GN.txt [ /tribalfusion.com ]
C:\Documents and Settings\jbandt\Cookies\HKUEX6C6.txt [ /kontera.com ]
C:\Documents and Settings\jbandt\Cookies\0ZWM0M82.txt [ /ad.wsod.com ]
C:\Documents and Settings\jbandt\Cookies\SGRTCYSS.txt [ /apmebf.com ]
C:\Documents and Settings\jbandt\Cookies\3JRUYMTW.txt [ /insightexpressai.com ]
C:\Documents and Settings\jbandt\Cookies\RZSY86E6.txt [ /media6degrees.com ]
C:\Documents and Settings\jbandt\Cookies\OVC76WV0.txt [ /edge.ru4.com ]
C:\Documents and Settings\jbandt\Cookies\CKG6RJQ1.txt [ /mediaplex.com ]
C:\Documents and Settings\jbandt\Cookies\6GVLV1V0.txt [ /sales.liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\XA13GXYG.txt [ /ru4.com ]
C:\Documents and Settings\jbandt\Cookies\XOJ5TZZZ.txt [ /www.burstnet.com ]
C:\Documents and Settings\jbandt\Cookies\V65MN3LI.txt [ /fastclick.net ]
C:\Documents and Settings\jbandt\Cookies\WS16598Y.txt [ /adbrite.com ]
C:\Documents and Settings\jbandt\Cookies\5C4WSPXW.txt [ /sigolfnation.buddymedia.com ]
C:\Documents and Settings\jbandt\Cookies\28NX8G54.txt [ /interclick.com ]
C:\Documents and Settings\jbandt\Cookies\TIZ56RT5.txt [ /advertising.com ]
C:\Documents and Settings\jbandt\Cookies\N8YD2EAT.txt [ /webstats.aetna.com ]
C:\Documents and Settings\jbandt\Cookies\WU4RWVP0.txt [ /bs.serving-sys.com ]
C:\Documents and Settings\jbandt\Cookies\Z91YYPJL.txt [ /ads.pointroll.com ]
C:\Documents and Settings\jbandt\Cookies\GIQKUUI5.txt [ /bizrate.com ]
C:\Documents and Settings\jbandt\Cookies\KIA0XFE7.txt [ /nextag.com ]
C:\Documents and Settings\jbandt\Cookies\37NTVC4C.txt [ /doubleclick.net ]
C:\Documents and Settings\jbandt\Cookies\0ZMJZ2A3.txt [ /zedo.com ]
C:\Documents and Settings\jbandt\Cookies\XDJA3E37.txt [ /traveladvertising.com ]
C:\Documents and Settings\jbandt\Cookies\1ME4LDI3.txt [ /pointroll.com ]
C:\Documents and Settings\jbandt\Cookies\TZOVMASX.txt [ /statse.webtrendslive.com ]
C:\Documents and Settings\jbandt\Cookies\J0LVGKFB.txt [ /steelhousemedia.com ]
C:\Documents and Settings\jbandt\Cookies\AWH57OIS.txt [ /statcounter.com ]
C:\Documents and Settings\jbandt\Cookies\FONGBR6V.txt [ /azjmp.com ]
C:\Documents and Settings\jbandt\Cookies\X9UQMO6Z.txt [ /thefind.com ]
C:\Documents and Settings\jbandt\Cookies\N9HXA7AP.txt [ /casalemedia.com ]
C:\Documents and Settings\jbandt\Cookies\5Z7JDJGQ.txt [ /eas.apm.emediate.eu ]
C:\Documents and Settings\jbandt\Cookies\6UZIM3KT.txt [ /clickbank.net ]
C:\Documents and Settings\jbandt\Cookies\A9O6XC99.txt [ /legolas-media.com ]
C:\Documents and Settings\jbandt\Cookies\CJM11DMP.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\AQWVI7PH.txt [ /stat.dealtime.com ]
C:\Documents and Settings\jbandt\Cookies\R1KSM5TM.txt [ /tacoda.net ]
C:\Documents and Settings\jbandt\Cookies\4RHN8CK3.txt [ /adserver.adtechus.com ]
C:\Documents and Settings\jbandt\Cookies\J637BDR5.txt [ /tracking.callmeasurement.com ]
C:\Documents and Settings\jbandt\Cookies\jbandt@CATDPCGU.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\4PSV8D21.txt [ /cn.clickable.net ]
C:\Documents and Settings\jbandt\Cookies\CT2M8Z8Y.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\jbandt@shinystat[1].txt [ /shinystat.com ]
C:\Documents and Settings\jbandt\Cookies\VBTA0AHX.txt [ /yourmedia.tcpalm.com ]
C:\Documents and Settings\jbandt\Cookies\VDNDVEP0.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\TWJL2WGH.txt [ /lucidmedia.com ]
C:\Documents and Settings\jbandt\Cookies\jbandt@CAMYIUE9.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\YNK0G862.txt [ /statse.webtrendslive.com ]
C:\Documents and Settings\jbandt\Cookies\W01U4K39.txt [ /ihg.db.advertising.com ]
C:\Documents and Settings\jbandt\Cookies\jbandt@s5.shinystat[1].txt [ /s5.shinystat.com ]
C:\Documents and Settings\jbandt\Cookies\KSGUJ3DJ.txt [ /r1-ads.ace.advertising.com ]
C:\Documents and Settings\jbandt\Cookies\SJI75ULR.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\5NE0KOH8.txt [ /lfstmedia.com ]
C:\Documents and Settings\jbandt\Cookies\8DS395BQ.txt [ /peoplefinders.com ]
C:\Documents and Settings\jbandt\Cookies\E99XXD5U.txt [ /wstat.wibiya.com ]
C:\Documents and Settings\jbandt\Cookies\76CIK3P3.txt [ /andomedia.com ]
C:\Documents and Settings\jbandt\Cookies\1RNAFKSW.txt [ /ehg-infospace.hitbox.com ]
C:\Documents and Settings\jbandt\Cookies\T6ZFL9LN.txt [ /media2.legacy.com ]
C:\Documents and Settings\jbandt\Cookies\1JCCRYUU.txt [ /intermundomedia.com ]
C:\Documents and Settings\jbandt\Cookies\R15GRZKM.txt [ /ads.al.com ]
C:\Documents and Settings\jbandt\Cookies\BIRG60EB.txt [ /stats4.clicktracks.com ]
C:\Documents and Settings\jbandt\Cookies\Z763CVP1.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\2IEE4UIC.txt [ /click360.sitescout.com ]
C:\Documents and Settings\jbandt\Cookies\S27373IC.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\Z9KYVG0X.txt [ /c.atdmt.com ]
C:\Documents and Settings\jbandt\Cookies\HW5AYGCH.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\33BTL38P.txt [ /pro-market.net ]
C:\Documents and Settings\jbandt\Cookies\jbandt@CA1LGP9Q.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\SCRFO1NW.txt [ /tacoda.at.atwola.com ]
C:\Documents and Settings\jbandt\Cookies\DL0UNELH.txt [ /counter.inkfrog.com ]
C:\Documents and Settings\jbandt\Cookies\4EO9QER2.txt [ /content.yieldmanager.com ]
C:\Documents and Settings\jbandt\Cookies\H8YGC8L4.txt [ /ads.masslive.com ]
C:\Documents and Settings\jbandt\Cookies\LNGA2W5J.txt [ /adserver.zonemedia.com ]
C:\Documents and Settings\jbandt\Cookies\GUFG5J05.txt [ /mm.chitika.net ]
C:\Documents and Settings\jbandt\Cookies\JT033HM3.txt [ /www.googleadservices.com ]
C:\Documents and Settings\jbandt\Cookies\jbandt@CA4J28B9.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\IL2ZBLAM.txt [ /hpi.rotator.hadj7.adjuggler.net ]
C:\Documents and Settings\jbandt\Cookies\P0HFITDN.txt [ /mediabrandsww.com ]
C:\Documents and Settings\jbandt\Cookies\jbandt@CAL8ME2V.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\ITA3RTW0.txt [ /googleads.g.doubleclick.net ]
C:\Documents and Settings\jbandt\Cookies\NZPZ3Z6S.txt [ /ads.nola.com ]
C:\Documents and Settings\jbandt\Cookies\EBOSIKA6.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\NO7RMFGR.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\70H4P5VN.txt [ /webstat.com ]
C:\Documents and Settings\jbandt\Cookies\KO2J098S.txt [ /gsimedia.net ]
C:\Documents and Settings\jbandt\Cookies\OX7BDJ38.txt [ /e-2dj6whkyumc5eao.stats.esomniture.com ]
C:\Documents and Settings\jbandt\Cookies\JSQGO365.txt [ /www.stlucie.county-taxes.com ]
C:\Documents and Settings\jbandt\Cookies\JNDV66F4.txt [ /ads.nj.com ]
C:\Documents and Settings\jbandt\Cookies\jbandt@CAQE22IH.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\0F03KT11.txt [ /atwola.com ]
C:\Documents and Settings\jbandt\Cookies\Y41B34G0.txt [ /thefind.pgpartner.com ]
C:\Documents and Settings\jbandt\Cookies\WK680B9O.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\SR2YS67W.txt [ /ad.360yield.com ]
C:\Documents and Settings\jbandt\Cookies\0W8URIU7.txt [ /ads.pennlive.com ]
C:\Documents and Settings\jbandt\Cookies\A0SDQAFS.txt [ /js.pixelrevenue.com ]
C:\Documents and Settings\jbandt\Cookies\8T4WBNDZ.txt [ /ads.pubmatic.com ]
C:\Documents and Settings\jbandt\Cookies\42JOVVD4.txt [ /ads.mlive.com ]
C:\Documents and Settings\jbandt\Cookies\THPW66ZC.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\024NVOBZ.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\ZE8PWEYI.txt [ /ads.wncoutdoors.info ]
C:\Documents and Settings\jbandt\Cookies\5YODL94I.txt [ /static.getclicky.com ]
C:\Documents and Settings\jbandt\Cookies\119VJRFG.txt [ /ads.bleepingcomputer.com ]
C:\Documents and Settings\jbandt\Cookies\EICMBL0Q.txt [ /wolverineworldwide.112.2o7.net ]
C:\Documents and Settings\jbandt\Cookies\Q24B9PMO.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\MHPC598Q.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\KEFXQ8DZ.txt [ /solvemedia.com ]
C:\Documents and Settings\jbandt\Cookies\JQRJ2YEI.txt [ /oasn-en1.247realmedia.com ]
C:\Documents and Settings\jbandt\Cookies\369UWJHQ.txt [ /piratesofthelowcountry.eventbrite.com ]
C:\Documents and Settings\jbandt\Cookies\2V6POQBT.txt [ /hammacher.112.2o7.net ]
C:\Documents and Settings\jbandt\Cookies\RFQII4VV.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\R0GKBXEP.txt [ /e-2dj6wgkogkczgco.stats.esomniture.com ]
C:\Documents and Settings\jbandt\Cookies\jbandt@CAWQV13Q.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\977QSXQD.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\82KFS788.txt [ /ar.atwola.com ]
C:\Documents and Settings\jbandt\Cookies\N1TX0T32.txt [ /ad.yieldmanager.net ]
C:\Documents and Settings\jbandt\Cookies\BLXM23HP.txt [ /cebwa.122.2o7.net ]
C:\Documents and Settings\jbandt\Cookies\2TB3SJNT.txt [ /rotator.hadj7.adjuggler.net ]
C:\Documents and Settings\jbandt\Cookies\SKLZBG9O.txt [ /cbtracking738.nfmclix.com ]
C:\Documents and Settings\jbandt\Cookies\SMHX3MB2.txt [ /www.chrumedia.com ]
C:\Documents and Settings\jbandt\Cookies\C2BJFO60.txt [ /d.mediaforge.com ]
C:\Documents and Settings\jbandt\Cookies\1E15RZ0X.txt [ /banners.rrpub.com ]
C:\Documents and Settings\jbandt\Cookies\4LG8I7K5.txt [ /hotels.112.2o7.net ]
C:\Documents and Settings\jbandt\Cookies\8IJ3OZTW.txt [ /liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\Z6ZTF3OS.txt [ /discountonlineparts.com ]
C:\Documents and Settings\jbandt\Cookies\S59DXMHS.txt [ /ads.syracuse.com ]
C:\Documents and Settings\jbandt\Cookies\DLST0DVI.txt [ /reservediscounthotels.com ]
C:\Documents and Settings\jbandt\Cookies\OT3W2MV1.txt [ /amazon-adsystem.com ]
C:\Documents and Settings\jbandt\Cookies\ILU2G0CW.txt [ /h.atdmt.com ]
C:\Documents and Settings\jbandt\Cookies\51MJ9MI8.txt [ /gr.burstnet.com ]
C:\Documents and Settings\jbandt\Cookies\63AFN5RS.txt [ /content.yieldmanager.com ]
C:\Documents and Settings\jbandt\Cookies\56AI8Q9X.txt [ /ads.paperleaf.net ]
C:\Documents and Settings\jbandt\Cookies\7RPRBGAW.txt [ /akamai.interclickproxy.com ]
C:\Documents and Settings\jbandt\Cookies\SUZJC017.txt [ /ads.cleveland.com ]
C:\Documents and Settings\jbandt\Cookies\K1TEZWB7.txt [ /find.keywordblocks.com ]
C:\Documents and Settings\jbandt\Cookies\7BDDMUUT.txt [ /click.jve.net ]
C:\Documents and Settings\jbandt\Cookies\BK4T5BDR.txt [ /intheswim.122.2o7.net ]
C:\Documents and Settings\jbandt\Cookies\VDT18GA7.txt [ /invitemedia.com ]
C:\Documents and Settings\jbandt\Cookies\4P8TV9QV.txt [ /ad.doubleclick.net ]
C:\Documents and Settings\jbandt\Cookies\VTIPHPGO.txt [ /pmamedia.sitescout.com ]
C:\Documents and Settings\jbandt\Cookies\ED4CVVCX.txt [ /clickfuse.com ]
C:\Documents and Settings\jbandt\Cookies\MD0VS5B2.txt [ /euronetresponse.122.2o7.net ]
C:\Documents and Settings\jbandt\Cookies\MODAU9WM.txt [ /server.iad.liveperson.net ]
C:\Documents and Settings\jbandt\Cookies\VK0BB1FF.txt [ /ads.lycos.com ]
C:\DOCUMENTS AND SETTINGS\JBANDT\Cookies\jbandt@www.sander[2].txt [ Cookie:jbandt@www.sander.com/__media__/js/ ]
C:\DOCUMENTS AND SETTINGS\JBANDT\Cookies\jbandt@www.myspace[2].txt [ Cookie:jbandt@www.myspace.com/Insightexpress/ ]
C:\DOCUMENTS AND SETTINGS\JBANDT\Cookies\jbandt@www.adelixir[3].txt [ Cookie:jbandt@www.adelixir.com/NeROITrack/920 ]
C:\DOCUMENTS AND SETTINGS\JBANDT\Cookies\SWYB9M46.txt [ Cookie:jbandt@adsonar.com/adserving ]
C:\DOCUMENTS AND SETTINGS\JBANDT\Cookies\329J3YYH.txt [ Cookie:jbandt@google.com/adsense/support/ ]
2mdn.net [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
a.ads2.msads.net [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
ad.insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
adimages.scrippsnetworks.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
ads1.msn.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
ads2.msads.net [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
atdmt.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
b.ads1.msn.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
b.ads2.msads.net [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
bannerfarm.ace.advertising.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
bc.youporn.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
cdn4.specificclick.net [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
content.oddcast.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
core.insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
ec.atdmt.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
euroclick.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
files.streamsex.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
googleads.g.doubleclick.net [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
hs.interpolls.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
ia.media-imdb.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
ictv-ic-ec.indieclicktv.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
indieclick.3janecdn.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
interclick.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
m1.2mdn.net [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
media.mtvnservices.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
media.scanscout.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
media.scrippsnewspapers.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
media1.break.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
media1.clubpenguin.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
media5.wgt.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
mediaforgews.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
mediastore.verizonwireless.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
msnbcmedia.msn.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
msntest.serving-sys.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
multimedia.msn.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
naiadsystems.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
objects.tremormedia.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
piximedia.fr [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
s-sec.slutload-media.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
s0.2mdn.net [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
secure-uk.imrworldwide.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
secure-us.imrworldwide.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
serving-sys.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
sftrack.searchforce.net [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
spe.atdmt.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
speed.pointroll.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
static.2mdn.net [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
static.sexsearch.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
udn.specificclick.net [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
video.pornorama.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
vidii.hardsextube.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
wdw1.wdpromedia.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
wdw2.wdpromedia.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
www.dopetraffic.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
www.bleeptube.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
www.mofosex.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
www.naiadsystems.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
www.shemale-porn-galls.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]
www.shemalexxxmovs.com [ C:\DOCUMENTS AND SETTINGS\JBANDT\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\TSN9A4DC ]

Adware.CouponBar
C:\WINDOWS\CPNPRT2.CID
C:\WINDOWS\SYSTEM32\CPNPRT2.CID

Trojan.Agent/Gen-PEC
C:\WINDOWS\PEV.EXE

#8 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:06:42 AM

Posted 01 December 2011 - 06:49 PM

There's traces but nothing nasty. Please scan with ESET which should find anything else left over

I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Under scan settings, check Posted Image and check Remove found threats
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • Copy and paste the resulting log in your next reply
If no log is generated that means nothing was found. Please let me know if this happens.
Posted Image
m0le is a proud member of UNITE

#9 jbandtbone

jbandtbone
  • Topic Starter

  • Members
  • 90 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:42 AM

Posted 02 December 2011 - 05:42 PM

It took most of the night to run. It had one hit but,when I click on the finish button no log came up. And I didn't write it down first. There was no file or logs button prior to clicking on finish or afterwards. Should I run it again?

#10 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:06:42 AM

Posted 03 December 2011 - 11:28 AM

It can take a long while but I'm not sure running it again is worthwhile. If it ran to completion then it has already quarantined anything it found.

How is the machine running?
Posted Image
m0le is a proud member of UNITE

#11 jbandtbone

jbandtbone
  • Topic Starter

  • Members
  • 90 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:42 AM

Posted 03 December 2011 - 01:42 PM

It still is not clearing the screen when I close out anything that I've opened. Zone Alarm still will not connect to the server to update the anti-virus /spy-ware files, but I'm almost ready to take it off my machine, to much stuff goes undetected. Other than that it seem to be doing alright.

do you recommend any anti-virus program?

#12 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:06:42 AM

Posted 03 December 2011 - 06:06 PM

Yes, let's clear up and see how the machine reacts when ZA is removed. As for antiviruses, yes, there are recommendations below for that as well as other bits and pieces in the final instructions.

Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean
TFC only cleans temp folders. TFC will not clean URL history, prefetch, or cookies. Depending on how often someone cleans their temp folders, their system hardware, and how many accounts are present, it can take anywhere from a few seconds to a minute or more. TFC will completely clear all temp files where other temp file cleaners may fail. TFC requires a reboot immediately after running. Be sure to save any unsaved work before running TFC.

TFC (Temp File Cleaner) will clear out all temp folders for all user accounts (temp, IE temp, java, FF, Opera, Chrome, Safari), including Administrator, All Users, LocalService, NetworkService, and any other accounts in the user folder.


Now

Please Download Flash Cookie Killer by Bobbie Flekman and save it to your Desktop

==========

:exclame: Warning :exclame:

Steps (1-3) will delete all existing highscores and game settings for flash games. Steps (4-8) might prevent the ability to save highscores in some games all together.

==========

  • Double click Posted Image from your desktop

  • Check "Everything but Adobe Site Settings"

  • Mouse click "Make it so!"
    Posted Image

  • Now go to the Adobe Flash Player Settings Manager

  • In the "Website Storage Settings" choose the "Delete All Sites" tab then "Confirm"
    Posted Image

  • Next in the "Global Storage Settings" uncheck "Allow third-party Flash content to store on your computer"
    Posted Image

  • Finally in the "Global Privacy Settings" choose "Always Deny" then "Confirm"
    Posted Image

  • You have now successfully deleted cookies stored and changed the Flash Players default settings to prevent access in the future.


Then

To Clear the Java Runtime Environment (JRE) cache, do this:
  • Click Start > Settings > Control Panel.
  • Double-click the Java icon. If you don't see it, go to Other options in the left panel or change to Classic View
    -The Java Control Panel appears.
  • Click "Settings" under Temporary Internet Files.
    -The Temporary Files Settings dialog box appears.
  • Click "Delete Files".
    -The Delete Temporary Files dialog box appears.
    -There are three options on this window to clear the cache.
    • Delete Files
    • Applications and applets
    • Trace and log files
  • Click "OK" on Delete Temporary Files window.
    -Note: This deletes all the Downloaded Applications and Applets from the cache.
  • Click "OK" on Temporary Files Settings window.
  • Close the Java Control Panel.
You can also view these instructions along with screenshots here.


Then we can say...

You're clean. Good stuff! :thumbup2:

Let's do some clearing up

If you used DeFogger now is the time to enable your CD emulation software again.

Uninstall ComboFix

Remove Combofix now that we're done with it.
  • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
    (For Vista/Windows 7 please click Start -> All Programs -> Accessories -> Run)
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between "Combofix" and "/")
  • Please follow the prompts to uninstall Combofix.
  • You will then receive a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
This will uninstall Combofix and anything associated with it.


We Need to Clean Up our Mess
Download and Run OTC

We will now remove the tools we used during this fix using OTC.

  • Download OTC by OldTimer and save it to your desktop.
  • Double click Posted Image icon to start the program. If you are using Vista, please right-click and choose run as administrator
  • Then Click the big Posted Image button.
  • You will get a prompt saying "Being Cleanup Process". Please select Yes.
  • Restart your computer when prompted.
If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.
------------------------------------------------------------------------------------------------------------------------

Here's some advice on how you can keep your PC clean


Use and update your AntiVirus Software

You must have a good antivirus. There are plenty to choose from but I personally recommend the free options of Avast and Avira Antivir - though if you choose Avira you should make sure that you uncheck the box offering to install the Ask toolbar. If you want to purchase a security program then I recommend any of the following: AVG, Norton, McAfee, Kaspersky and ESET Nod32.

It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out. If you use a commercial antivirus program you must make sure you keep renewing your subscription. Otherwise, once your subscription runs out, you may not be able to update the programs virus definitions.


Make sure your applications have all of their updates

Use this next program to check for updates for programs already on your system. Download Security Check by screen317 from here or here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically, make sure that updates on any that are flagged are carried out as soon as possible

It is also possible for other programs on your computer to have security vulnerability that can allow malware to infect you. Therefore, it is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Install an AntiSpyware Program

A highly recommended AntiSpyware program is SuperAntiSpyware. You can download the free Home Version. or the Pro version for a 15 day trial period.

Installing this or another recommended program will provide spyware & hijacker protection on your computer alongside your virus protection. You should scan your computer with an AntiSpyware program on a regular basis just as you would an antivirus software.


Finally, here's a treasure trove of antivirus, antimalware and antispyware resources


That's it, happy surfing!

Cheers.

m0le
Posted Image
m0le is a proud member of UNITE

#13 jbandtbone

jbandtbone
  • Topic Starter

  • Members
  • 90 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:42 AM

Posted 03 December 2011 - 11:36 PM

It seems to be working fine now that I've got rid of ZA.They had been trying to get me to update to a newer version. And I found the ESET log. I'll post so you can see. Thanks

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=ea3c0edfb390564a8009b83a48c9ca5d
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-12-02 05:08:16
# local_time=2011-12-02 12:08:16 (-0500, Eastern Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 105991774 105991774 0 0
# compatibility_mode=768 16777215 100 0 103272051 103272051 0 0
# compatibility_mode=1024 16777215 100 0 88054844 88054844 0 0
# compatibility_mode=2560 16777215 100 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# compatibility_mode=9217 16776537 100 77 0 38796212 0 0
# scanned=160508
# found=1
# cleaned=1
# scan_time=17965
C:\Documents and Settings\jbandt\Application Data\Sun\Java\Deployment\cache\6.0\19\55730493-32b44479 Java/TrojanDownloader.OpenStream.NCK trojan (deleted - quarantined) 00000000000000000000000000000000 C

#14 jbandtbone

jbandtbone
  • Topic Starter

  • Members
  • 90 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:42 AM

Posted 03 December 2011 - 11:59 PM

AHHHHHHHH spoke to soon. It is still showing the web page that I am using when I try to close it or try to minimize it.

#15 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:06:42 AM

Posted 04 December 2011 - 05:55 PM

I've got a few IE problems across the board at the moment.

Can you do the following to reset IE8's settings and then let me know if you are still experiencing problems.

Close Internet Explorer. Go to start > Control Panel > internet options.
  • Under General tab press Delete... then make sure all the sections are checked and click Delete.
  • Under Advanced tab click Restore advanced settings
  • Make sure under Security tab the Default is selected.
  • Also under Privacy tab the Default is selected.
  • Under privacy click on sites then on Remove All and confirm.
    (If the users use SpywareBlaster they should re-enable restrictions)


There are some useful troubleshooting tips here

If that doesn't help and the other steps aren't providing the answer then you can reset IE8.

The factory reset guide here
Posted Image
m0le is a proud member of UNITE




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users