Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijackthis Log: Please Help Diagnose


  • Please log in to reply
43 replies to this topic

#1 graveangel

graveangel

  • Members
  • 399 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Nottingham England Home to the Hood of Robin
  • Local time:05:21 PM

Posted 10 April 2006 - 06:27 PM

Hi im fairly new to the computer thing to be honest but pick things up quick. I recently bought a sony vaio laptop from a local paper, its about 2-3years old at a guess but from what i can tell is totally plagued with spyware and virus's. It is running incredably slow and some times crashes with a blue screen that displys shortly for about half a second or just freezes.Ive recently had several things download themselves onto the pc one called 'exsplorer' which is an internet shortcut to a web page,stored in several places and nomatter how many times i delete them they just reappear somtimes a pop up box comes up with italian writing,i think they are connected. Ive downloaded spybot and already have ad-aware se, microsoft anti-spyware, arovax shield and they are all up to date. The system also has ewido on it,but its not registered and cant be updated,but it doesnt appear to have been downloaded that long ago.
If anyone out there can please please help, i would be eternally greatful.

This is my scan from highjackthis,ive never used it before so if its wrong then i will post another one,or whatever else is needed!Please help,thank you!


Logfile of HijackThis v1.99.1
Scan saved at 23:21:12, on 10/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ntl\ntl Netguard\fws.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Visual IP InSight\UK\ARMon32a.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\SONY\vaio media music server\SSSvr.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Sony\HotKey Utility\HKserv.exe
C:\WINDOWS\system32\carpserv.exe
C:\WINDOWS\system32\bcmwltry.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\sony\photo server\appsrv\PhotoAppSrv.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
C:\Program Files\VoyagerTest\fts.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Sony\HotKey Utility\HKWnd.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Daily Weather Forecast\weather.exe
C:\Program Files\drag'n drop cd+dvd\BinFiles\DragDrop.exe
C:\Program Files\ntl\ntl Netguard\Rps.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\Common Files\sony shared\vaio media platform\SV_Httpd.exe
C:\Program Files\Common Files\Sony Shared\vaio media platform\sv_httpd.exe
C:\Program Files\Common Files\sony shared\vaio media platform\UPnPFramework.exe
C:\Program Files\Common Files\Sony Shared\vaio media platform\UPnPFramework.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Apoint\Apvfb.exe
C:\Program Files\Arovax Shield\ArovaxShield.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\PokerStars\PokerStars.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Chris Organ\Desktop\Hi Jack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchasst.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.whsmithonline.co.uk/redir.asp?page=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.microsoft.com/isapi/redir.dll?P...ie5update&O1=b1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Lee's Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: (no name) - {1F4D1A73-A7B1-AC44-C80B-D998CE66A5CD} - C:\WINDOWS\system32\vdxb.dll (file missing)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: PopKill Class - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\ntl\ntl Netguard\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\ntl\ntl Netguard\FBHR.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: IeCaptureBho Object - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [RemoveCpl] "RemoveCpl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] "ICO.EXE"
O4 - HKLM\..\Run: [HKSERV.EXE] "C:\Program Files\Sony\HotKey Utility\HKserv.exe"
O4 - HKLM\..\Run: [CARPService] "carpserv.exe"
O4 - HKLM\..\Run: [bcmwltry] "bcmwltry.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [ATIModeChange] "Ati2mdxx.exe"
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [DSLSTATEXE] "C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon"
O4 - HKLM\..\Run: [DSLAGENTEXE] "C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe"
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\VoyagerTest\fts.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [CmUsbAudio] RunDll32 cmcnfg2.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
O4 - HKLM\..\Run: [Drag'n Drop CD+DVD] C:\Program Files\drag'n drop cd+dvd\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [ntl Netguard] C:\Program Files\ntl\ntl Netguard\Rps.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [Arovax Shield] C:\Program Files\Arovax Shield\ArovaxShield.exe /h
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.whsmithonline.co.uk/redir.asp?page=home
O15 - Trusted Zone: www.archiviosex.net
O15 - Trusted Zone: www.skymasters.biz
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1137543401644
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\ntl\ntl Netguard\fws.exe
O23 - Service: Visual IP InSight Client (UK) (InverseLaunchIPI_WOL:WOLUK) - Visual Networks - C:\Program Files\Visual IP InSight\UK\LaunchIPI.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\SONY\vaio media music server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\vaio media platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\vaio media platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\sony\photo server\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\sony shared\vaio media platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\sony shared\vaio media platform\UPnPFramework.exe
....And on the 8th day God said, "When my children are intelligent, and create the Computer, for my sake may they never screw around with the registry or subscribe to AOL"Posted Image

BC AdBot (Login to Remove)

 


#2 Papakid

Papakid

    Guru at being a Newbie


  • Malware Response Team
  • 6,583 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:21 AM

Posted 16 April 2006 - 09:55 PM

Hi graveangel,

Sorry for the delay. Not a lot showing in your log for a badly infected machine, but enough and from your description there could be something hidden from HijackThis. I'm curious why, if you think the PC is badly infected and it's used, you don't reformat and make a fresh start to get it set up as you like it. We can clean up what we can, but i see no indication of a firewall and there is only one process running from Symantec (usually a viable Norton anti virus has several), so a PC that has been running for a while without that kind of protection could be too far gone.

Plus I'm not sure which programs you use and which are left over. Have you gone thru and uninstalled what you don't need or want?

The first order of business is to make sure you are adequately protected. The programs you have mentioned that are updated are good but are no substitute for a good antivirus. Have you been running your Symantec product, updating and running a full system scan? Do you have a system tray icon that allows you to turn Auto Protect on and off? Is your subsription current?

When you notice some improvement in speed you'll need to get a firewall installed. It could complicate matters at the moment, but I suggest downloading one so it will be ready to install. Here are some good free ones--I recommend Sygate or Outpost.

Kerio Personal Firewall
OutPost Firewall Free
ZoneAlarm
Sygate Personal Firewall

Understanding and Using Firewalls

The system also has ewido on it,but its not registered and cant be updated,but it doesnt appear to have been downloaded that long ago.

You don't have to register ewido to update, scan and clean with it. It's a very effective malware scanner I would like for you to use and you should be able to update it manually, instructions for which are included in the following instructions. If you still have problem with ewido, uninstall it, then follow the instructions to download and install again.

I'm not very familiar with Arovax Shield, but as I understand it from reading the description on its homepage, it could interfere with ewido and some others fixes I'm about to ask you to make. I suggest you set it to manual or disable it so it doesn't block repairs until we're thru.

-------------------

Download and install ewido security suite.
When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
- Launch Ewido by double-clicking the desktop icon.
- You may get a message that the database could not be found. This is normal-- click the OK button.
- The program will now go to the main screen.
- On the left hand side of the main screen click update.
- Click on Start update.
- The update will start and a progress bar will show the updates being installed.

If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates

Once the updates are installed close Ewido.

Reboot your computer into Safe Mode.

Open Ewido and do the following:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • If ewido detects an infected file click "Perform action on all infections"
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report.txt file to your desktop.
Now close ewido security suite.

Please post the contents of the report.txt file in your next post.

Now scan again with HijackThis andcheck the following if still there (ewido may have removed them):

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)

O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
O15 - Trusted Zone: www.archiviosex.net
O15 - Trusted Zone: www.skymasters.biz


Note: The entries in blue text are for Spybot Search & Destroy and SpywareDoctor and indicate a file is mising. I'm assuming you've uninstalled those apps and these are just orphaned reg entries. If not, you'll need to reinstall them.

If you've uninstalled the Google toolbar seperately from Google Desktop search, fix the following as well:

O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)


When done, close any other windows and click the Fix Checked button.

This process will clean out your Temp files and your Temporary Internet Files. Please do both steps:

Step 1:Delete Temp Files
To clean out your temp files, click on Start and then run, and type %temp% and press the ok button.

This should open up the temp directory that your machine uses. Please delete all files that are found there.

Step 2: Delete Temporary Internet Files
Now I want you to open up Internet Explorer, and click on the Tools menu and then Internet Options. At the General tab, which should be the first tab you are currently on, click on the Delete Files button and put a checkmark in Delete offline content. Then press the OK button. This may take quite a while, so do not be alarmed with how long it takes. When it is done, your Temporary Internet Files will now be deleted.

While still in safe mode I'd like for you to defragment your hard drive.

START>All Programs>Accessories>System Tools> Disk Defragmenter.

Now reboot back into normal mode.

Perform an onlinescan with Panda: (please use this scanner instead of any other scanner!)
Panda Online
- Once you are on the Panda site click the Scan your PC button
- A new window will open...click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It may take a few minutes)
- When download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the Panda scan report together with a fresh HijackThis log

Now scan again with HijackThis and post a new log. There will likely be more to do. Don't forget to post the ewido and Panda scans also and let me know how the the machine is running.

The fate of all mankind, I see

Is in the hands of fools

--King Crimson


#3 graveangel

graveangel
  • Topic Starter

  • Members
  • 399 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Nottingham England Home to the Hood of Robin
  • Local time:05:21 PM

Posted 17 April 2006 - 11:34 PM

Hi Papakid,
massive thanks for getting back to me. Sorry i wasnt more informative in my original post,so i will just run through quickly to fill you in on what i should have before from your qustions. I cant re-install windows because i dont have a windows disk and also the laptop came with software which is handy to me.I have gone through and deleted software i dont want to the best of my knowledge so pretty much everything on there is what i want to keep. I do have a firewall running but its the windows own one,so im guessing its pretty rubbish? i have taken your advice and downloaded sygate firewall,but not installed it yet until you tell me to. I do have an anti-virus and as far as i can tell it is working,up to date(updates automatically every 3hours) and has real time virus protection,it recently informed me it blocked a trojan trying to download,not sure which though sorry.It is called ntl netguard and is supplied by my broadband supplier but can only be used by subscribers. I no longer have or use norton, it had an old trial version, i bought norton internet security 2006 not long ago but when i tried to install it it screwed up the system,i got it sorted but norton refuses to work if you have had an older version installed before,and from reading many peoples opinions on it,they are having the same problems even after downloading the norton uninstall software from there site,so ive decided to leave it,so can delete anything its left behind!
I ticked off all of the problems you told me to for hjt as ewido didnt delete any of them itself.

I followed your instructions in order and after 11hours of scanning and defragging,here are my logs, sorry but they were so long i had to spread them over FOUR posts so it continues after this one straight into the others (is there away to get them all on one post??):

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 23:16:00, 17/04/2006
+ Report-Checksum: 2ACC5571

+ Scan result:

:mozilla.32:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-1.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-1.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-1.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-1.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-10.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-10.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-10.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-10.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-10.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-10.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-10.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-10.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-10.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-10.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-10.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-10.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-10.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-10.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-10.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-10.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-10.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-11.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-11.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-11.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-11.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-11.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-11.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-11.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-11.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-11.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-11.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-11.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-11.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-11.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-11.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-11.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-11.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-11.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-11.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-12.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-13.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-14.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-2.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-2.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-2.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-2.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-2.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.138:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-2.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-2.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-2.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-2.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt -> TrackingCookie.Adbrite : Cleaned with backup

Edited by graveangel, 18 April 2006 - 12:02 AM.

....And on the 8th day God said, "When my children are intelligent, and create the Computer, for my sake may they never screw around with the registry or subscribe to AOL"Posted Image

#4 graveangel

graveangel
  • Topic Starter

  • Members
  • 399 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Nottingham England Home to the Hood of Robin
  • Local time:05:21 PM

Posted 17 April 2006 - 11:47 PM

:mozilla.15:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-23.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-23.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-23.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-23.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-23.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-23.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-23.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-23.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-23.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-24.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-24.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-24.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-24.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-24.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-24.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-24.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-24.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-24.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-25.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-25.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-25.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-25.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-25.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-25.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-25.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-25.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-25.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-25.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-25.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-26.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-26.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-26.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-26.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-26.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-26.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-26.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-26.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-27.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-27.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-27.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-27.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-27.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-27.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-27.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-27.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-27.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-28.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-28.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-28.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-28.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-28.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-28.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-28.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-28.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-28.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-28.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-29.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-29.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-29.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-29.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-29.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-29.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-29.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-29.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-29.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-29.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-30.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-30.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-30.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-30.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-30.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-30.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-30.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-30.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-30.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-30.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-31.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-31.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-31.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-31.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-31.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-31.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-31.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-31.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-31.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-31.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-32.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-32.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-32.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-32.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-32.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-32.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-32.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-32.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-32.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-32.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-33.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-33.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-33.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-33.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-33.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-33.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-33.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-33.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-33.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-33.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-34.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-34.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-34.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-34.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-34.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-34.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-34.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-34.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-34.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-34.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-35.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-35.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-35.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-35.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-35.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-35.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-35.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-35.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-35.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-35.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-37.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-37.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-37.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-37.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-37.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-37.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-37.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-37.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-37.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-37.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-37.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-37.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-37.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-37.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-37.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-38.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-38.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-38.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-38.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-38.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-38.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-38.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-38.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-38.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-38.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-38.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-38.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-38.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-38.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-38.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-39.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-40.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-41.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-42.txt -> TrackingCookie.Euroclick : Cleaned with backup

Edited by graveangel, 17 April 2006 - 11:55 PM.

....And on the 8th day God said, "When my children are intelligent, and create the Computer, for my sake may they never screw around with the registry or subscribe to AOL"Posted Image

#5 graveangel

graveangel
  • Topic Starter

  • Members
  • 399 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Nottingham England Home to the Hood of Robin
  • Local time:05:21 PM

Posted 17 April 2006 - 11:56 PM

:mozilla.13:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-43.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-45.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-45.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-45.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-45.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-45.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-45.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-45.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-45.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-45.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-46.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-46.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-46.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-46.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-46.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-46.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-46.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-46.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-46.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-46.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-46.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-46.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-46.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-46.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-46.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-46.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-5.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-5.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-5.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-5.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-5.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-5.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-5.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-5.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-5.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-5.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-5.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-5.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-5.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-5.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-6.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-6.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-6.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-6.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-6.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-6.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-6.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-6.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-6.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-6.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-6.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-6.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-6.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-6.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-7.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-7.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-7.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-7.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-7.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-7.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-7.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-7.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-7.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-7.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-7.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-7.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-7.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-7.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-8.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-8.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-8.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-8.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-8.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-8.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-8.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-8.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-8.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-8.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-8.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-8.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-8.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-8.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-9.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-9.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-9.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-9.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-9.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-9.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-9.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-9.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-9.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-9.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-9.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-9.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-9.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-9.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-9.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
C:\WINDOWS\system32\Міcrosoft.NET\wucrtupd.exe -> Downloader.PurityScan.w : Cleaned with backup


::Report End


-------------------------------
Panda Activescan
-------------------------------
Incident Status Location

Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\remote balm eggs ford\Dupe Dumb.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\remote balm eggs ford\mapi eggs.exe
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-1.txt[]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt[]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt[]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt[]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt[]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt[]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-2.txt[]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt[]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt[]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt[]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt[]
Spyware:Cookie/Bs.serving-sys Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt[]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-5.txt[]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-6.txt[]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies.txt[]
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris Organ\Application Data\spamgridbolt\Scr dupe time up.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris Organ\Application Data\spamgridbolt\tuquntgh.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Chris Organ\Application Data\spamgridbolt\WipeSkipLogo.exe
Adware:adware/tvmedia Not disinfected C:\Documents and Settings\Chris Organ\Application Data\tvmdmns.dll
Dialer:dialer.cos Not disinfected C:\Documents and Settings\Chris Organ\Favorites\exsplorer.lnk
Adware:adware/ipbill Not disinfected C:\dtemp2.exe
Adware:Adware/IST.ISTBar Not disinfected C:\Program Files\Daily Weather Forecast\weather.exe
Potentially unwanted tool:Application/FunWeb Not disinfected C:\RECYCLER\NPROTECT\00033745.DLL_
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\RECYCLER\NPROTECT\00033753.DLL_t
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\RECYCLER\NPROTECT\00033754.DLL_t
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\RECYCLER\NPROTECT\00033757.F3S_to
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\RECYCLER\NPROTECT\00033758.F3S_
Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00034182.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034184.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034185.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034189.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034208.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034214.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034225.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034229.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034236.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034239.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034265.MOZ[]
Spyware:Cookie/Belnk Not disinfected C:\RECYCLER\NPROTECT\00034286.MOZ[]
Spyware:Cookie/Belnk Not disinfected C:\RECYCLER\NPROTECT\00034586.MOZ[]
Spyware:Cookie/MediaTickets Not disinfected C:\RECYCLER\NPROTECT\00034628.MOZ[]
Spyware:Cookie/did-it Not disinfected C:\RECYCLER\NPROTECT\00034632.MOZ[]
Spyware:Cookie/did-it Not disinfected C:\RECYCLER\NPROTECT\00034636.MOZ[]
Spyware:Cookie/MediaTickets Not disinfected C:\RECYCLER\NPROTECT\00034639.MOZ[]
Spyware:Cookie/MediaTickets Not disinfected C:\RECYCLER\NPROTECT\00034643.MOZ[]
Spyware:Cookie/MediaTickets Not disinfected C:\RECYCLER\NPROTECT\00034645.MOZ[]
Spyware:Cookie/MediaTickets Not disinfected C:\RECYCLER\NPROTECT\00034710.MOZ[]
Spyware:Cookie/did-it Not disinfected C:\RECYCLER\NPROTECT\00034715.MOZ[]
Spyware:Cookie/did-it Not disinfected C:\RECYCLER\NPROTECT\00034725.MOZ[]
Adware:Adware/Lop Not disinfected C:\RECYCLER\NPROTECT\00035369.exe




Logfile of HijackThis v1.99.1
Scan saved at 05:12:15, on 18/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ntl\ntl Netguard\fws.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Visual IP InSight\UK\ARMon32a.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\SONY\vaio media music server\SSSvr.exe
C:\Program Files\sony\photo server\appsrv\PhotoAppSrv.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Sony\HotKey Utility\HKserv.exe
C:\WINDOWS\system32\carpserv.exe
C:\WINDOWS\system32\bcmwltry.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\sony shared\vaio media platform\SV_Httpd.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
C:\Program Files\VoyagerTest\fts.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\drag'n drop cd+dvd\BinFiles\DragDrop.exe
C:\Program Files\ntl\ntl Netguard\Rps.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Common Files\sony shared\vaio media platform\UPnPFramework.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Sony Shared\vaio media platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\vaio media platform\UPnPFramework.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\Sony\HotKey Utility\HKWnd.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Apoint\Apvfb.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Arovax Shield\ArovaxShield.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Chris Organ\Desktop\Hi Jack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchasst.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.whsmithonline.co.uk/redir.asp?page=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Lee's Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: (no name) - {1F4D1A73-A7B1-AC44-C80B-D998CE66A5CD} - C:\WINDOWS\system32\vdxb.dll (file missing)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: PopKill Class - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\ntl\ntl Netguard\pkR.dll
O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\ntl\ntl Netguard\FBHR.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: IeCaptureBho Object - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll

Edited by graveangel, 17 April 2006 - 11:58 PM.

....And on the 8th day God said, "When my children are intelligent, and create the Computer, for my sake may they never screw around with the registry or subscribe to AOL"Posted Image

#6 graveangel

graveangel
  • Topic Starter

  • Members
  • 399 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Nottingham England Home to the Hood of Robin
  • Local time:05:21 PM

Posted 17 April 2006 - 11:59 PM

O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [RemoveCpl] "RemoveCpl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] "ICO.EXE"
O4 - HKLM\..\Run: [HKSERV.EXE] "C:\Program Files\Sony\HotKey Utility\HKserv.exe"
O4 - HKLM\..\Run: [CARPService] "carpserv.exe"
O4 - HKLM\..\Run: [bcmwltry] "bcmwltry.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [ATIModeChange] "Ati2mdxx.exe"
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [DSLSTATEXE] "C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon"
O4 - HKLM\..\Run: [DSLAGENTEXE] "C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe"
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\VoyagerTest\fts.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [CmUsbAudio] RunDll32 cmcnfg2.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Drag'n Drop CD+DVD] C:\Program Files\drag'n drop cd+dvd\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [ntl Netguard] C:\Program Files\ntl\ntl Netguard\Rps.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.whsmithonline.co.uk/redir.asp?page=home
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\ntl\ntl Netguard\fws.exe
O23 - Service: Visual IP InSight Client (UK) (InverseLaunchIPI_WOL:WOLUK) - Visual Networks - C:\Program Files\Visual IP InSight\UK\LaunchIPI.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\SONY\vaio media music server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\vaio media platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\vaio media platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\sony\photo server\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\sony shared\vaio media platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\sony shared\vaio media platform\UPnPFramework.exe


I really am so so sorry the logs are this long,but thank you so so much for your time on helping me with this, i really appeciate it.

If i could just ask a couple of things also, my start up is still a little slow,any suggestions what to stop loading at start up? and what is a 'kernal fault check',i stopped one installing using ms anti spyware when it noticed it trying to install a couple of weeks back?and should i delete my quarentined items in ewido?

The laptop after all scanning and defrag is running only a fraction quicker,guess its all that spyware panda picked up on.

Big Big Thanks again, i wait in desperation for your reply!
....And on the 8th day God said, "When my children are intelligent, and create the Computer, for my sake may they never screw around with the registry or subscribe to AOL"Posted Image

#7 Papakid

Papakid

    Guru at being a Newbie


  • Malware Response Team
  • 6,583 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:21 AM

Posted 18 April 2006 - 12:12 PM

Hi graveangel,

Don't worry about the logs being so long, I'm used to that, tho I must say i don't know if I've ever seen quite a collection of tracking cookies. Cookies are a very low level threat, and they should be cleaned out periodically, but they make people think they are more badly infected than they really are. However you do have some more serious cleaning up to do.

I'm not a big fan of security software installed by ISP's--it's better than nothing and some of it is pretty effective. But it's been my experience that there is not enough manual control over them when there is a problem so it makes it hard to troubleshoot. So I prefer stand alone solutions. Not enough information--for example, from what I can tell, you may have a firewall provided also. I'm going to say you are well enough protected for the time being unitl I get some more information, some of which I'm about to ask for. You have a couple of dialers that need to be removed ASAP so we'll deal with that first. I'll do my best to answer your other questions later (remind me :thumbsup: ).

You also have a file that appears to be bad but there is no information available on it to know for sure. I'll have you delete it, but with KillBox so it will be backed up in case it needs to be restored. The file may have already been deleted (sometimes HJT misinterprets this), so if you can't find it don't worry and skip the following instructions for scanning with jotti and submitting:

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Please create a folder called c:\submit. Now copy the following files into that directory:

C:\WINDOWS\system32\vdxb.dll

To copy the files simply navigate to the directory they are in and right click on the file name, and then click Copy. Now go back to the c:\submit folder. Right click the folder and select Paste.

Once the files are all copied zip the folder and rename submit.zip to graveangel.zip. If you are not sure how to send the files to a zip folder click the following link for a tutorial:
How to create and extract a ZIP File in Windows 95/98/2000

When the files are zipped click this link to go to the BC submisions page:
http://www.bleepingcomputer.com/submit-malware.php

1. Fill in the required fields and then click the Browse button.
2. Navigate to graveangel.zip and click the Send File button.
-------------------------
Also please click this link-->Jotti

When the jotti page has finished loading, click the browse button and navigate to the file I've just listed above, then click Submit. Please post back the results of the scan in your next post.

Scan again with HijackThis a check the following:

R3 - URLSearchHook: (no name) - {1F4D1A73-A7B1-AC44-C80B-D998CE66A5CD} - C:\WINDOWS\system32\vdxb.dll (file missing)

Click fix checked with all other windows closed.

Download KillBox from here:

KillBox

Unzip the folder to your desktop.

* Start Killbox.exe
* Select the Delete on Reboot option.
* Click on the All Files button.
* Copy the complete text in bold below to the clipboard by highlighting the filepaths and pressing Control + C:

C:\WINDOWS\system32\vdxb.dll
C:\Documents and Settings\Chris Organ\Application Data\tvmdmns.dll
C:\Documents and Settings\Chris Organ\Favorites\exsplorer.lnk
C:\dtemp2.exe


* Go to the File menu of Killbox, and choose Paste from Clipboard.
NOTE: You must use the file File menu--pasting by right-clicking the mouse will only enter one file.
* Click the Delete File button that is a red-and-white X. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).

If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.

Now find and delete the following folders using Windows Explorer/My Computer--if any problems deleting, try booting into Safe Mode and try again:

C:\Program Files\Daily Weather Forecast
C:\Documents and Settings\All Users\Application Data\remote balm eggs ford
C:\Documents and Settings\Chris Organ\Application Data\spamgridbolt


Download fl.zip.
Extract the contents to a new folder on your Desktop. NOTE: It must be unzipped to work properly.
Within the folder, locate & double-click fl.bat.
It should produce a report at c:\findlop.txt. Post the contents of the report in your next reply.

Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):
  • Go to Tools > Options.
  • Click Privacy in the menu on the left side of the Options window.
  • Click the Clear button located to the right of each option (History, Cookies, Cache).
  • Click OK to close the Options window
    Alternatively, you can clear all information stored while browsing by clicking Clear All.
    A confirmation dialog box will be shown before clearing the information.
*

Note that you will have to log back in to BC or any other site where that is required, so have your passwords saved before deleting all cookies.

Now open HijackThis.

If you still have the New Users Quickstart screen enabled, click Open Misc Tools Section.
If you just have the regular opening screen, click the Config... button then the Misc Tools button.

Now click the Open Uninstall Manager button, then the Save List button. Save the list somewhere convenient like My Documents and then the list will open in Notepad. Copy and Paste that list into your next reply to this post.

Scan again with HijackThis and post a new log.

Also please scan again with Panda and post that new log as well.

So in your next post I will need to see the following logs:

1. Jotti results if possible
2. c:\findlop.txt
3. Uninstall Manager list
4. HJT log
5. Panda log

A couple of other things. Norton is going to be a problem, as the Recycle bin is still protected by it and what you still have running could be where a lot of your slowdown comes from. Before we do anything there I need to know if you actually tried to use Norton's tool to remove it's own software or decided against it. And if you can remember what version was preinstalled. Was System Works on there?

Also you can empty ewido's quarantine of all those cookies, but leave in the following for a while until I can find out if it is a possible false positive that might need to be restored:

C:\WINDOWS\system32\Міcrosoft.NET\wucrtupd.exe -> Downloader.PurityScan.w

You're doing great so far. :flowers:

The fate of all mankind, I see

Is in the hands of fools

--King Crimson


#8 graveangel

graveangel
  • Topic Starter

  • Members
  • 399 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Nottingham England Home to the Hood of Robin
  • Local time:05:21 PM

Posted 18 April 2006 - 01:02 PM

Hi, ive come across a problem at the first hurdle here. I cant create a folder call ' c:\submit' as windows will not allow me to input the : sign into the name,i can create a folder called 'submit' though. Also, i can not find the file called C:\WINDOWS\system32\vdxb.dll ive even searched using the search tool but it aint there??????
I have made all hidden files visable using the instructions on bp's site
By the way just to let you know, my antivirus didnt come with a firewall, just using the one supplied with windows and i did use the norton removal tool from there site, but like many other people, it still leaves things behind, which does not allow you to install new norton software, i know this has happened to a lot of people. It was Norton antivirus 2004 as far as i know and system works i dont believe was on there.

Ive not done anything further yet until you get back to me concerning this system 32 file

Again, many thanks, it really is appreciated!

[b]REALLY SORRY, JUST NOTICED THAT IF I CANT FIND THE FILE YOU SAID NOT TO WORRY,LEAVE THE ZIP PART AND MOVE ONTO HJT. SORRY,COMPLETELY MISS READ THAT PART, PROBABLY CAUSE I WAS TIRED.I WILL CONTINUE WITH THE REST NOW! THANKS

Edited by graveangel, 18 April 2006 - 02:45 PM.

....And on the 8th day God said, "When my children are intelligent, and create the Computer, for my sake may they never screw around with the registry or subscribe to AOL"Posted Image

#9 graveangel

graveangel
  • Topic Starter

  • Members
  • 399 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Nottingham England Home to the Hood of Robin
  • Local time:05:21 PM

Posted 18 April 2006 - 08:29 PM

Ok think ive done all this right, the new panda scan revealed i have: 43-spyware,5-hacking tools and 1-dialer.

As mentioned in the post above the file 'system32\vdxb.dll' was not present anymore so when i did the killbox part that wasnt able to be deleted due to it no longer being on the system?
just to let you know,i am using firefox cause i understand,although its still prone to attacks,its not as open to them as explorer,should i use another one?
So here are the 4 logs you needed minus the jotti one as i wasnt able to use that,it continues over several posts again,sorry:


Volume in drive C is VAIO
Volume Serial Number is 98C1-CCF6

Directory of C:\Documents and Settings\Administrator\Application Data

05/01/2006 17:45 <DIR> Help
05/01/2006 17:45 <DIR> Identities
05/01/2006 17:45 <DIR> InterTrust
16/09/2003 10:56 <DIR> Real
05/01/2006 17:45 <DIR> Symantec
0 File(s) 0 bytes
5 Dir(s) 11,093,450,752 bytes free
Volume in drive C is VAIO
Volume Serial Number is 98C1-CCF6

Directory of C:\Documents and Settings\All Users\Application Data

16/11/2004 00:11 <DIR> Adobe
15/08/2004 15:16 <DIR> AOL
02/11/2005 22:12 11 DragToDiscUserNameF.txt
05/04/2006 15:52 <DIR> DVD Shrink
04/04/2005 00:38 <DIR> McAfee.com
10/07/2005 23:31 <DIR> Mess Owns Setup Trust
04/10/2003 18:12 <DIR> MSN6
17/09/2004 18:51 <DIR> Napster
21/08/2005 02:32 <DIR> ntl
06/03/2006 21:50 <DIR> pixelStorm
07/10/2003 23:34 <DIR> QuickTime
16/10/2005 17:42 <DIR> Samsung
29/03/2004 18:46 <DIR> SBSI
11/11/2003 16:35 <DIR> Sony Corporation
17/04/2006 18:49 <DIR> Spybot - Search & Destroy
06/01/2006 20:23 <DIR> Symantec
28/05/2005 01:38 <DIR> Trymedia
26/09/2004 17:53 <DIR> Ulead Systems
16/09/2003 11:11 <DIR> VAIO Media Platform
11/04/2004 12:05 <DIR> Viewpoint
10/09/2004 21:33 370 WhiteCap Prefs (jetAudio).txt
19/09/2004 15:54 385 WhiteCap Prefs (Windows Media Player).txt
07/02/2006 20:22 <DIR> Windows Genuine Advantage
12/12/2005 16:58 <DIR> Yahoo! Companion
3 File(s) 766 bytes
21 Dir(s) 11,093,385,216 bytes free
Volume in drive C is VAIO
Volume Serial Number is 98C1-CCF6

Directory of C:\Documents and Settings\Chris Organ\Application Data

08/10/2004 18:57 <DIR> 123 Free Solitaire
14/11/2003 01:43 <DIR> Adobe
14/12/2004 20:44 <DIR> AdobeUM
15/08/2004 15:16 <DIR> AOL
14/11/2003 01:43 <DIR> Autodesk
31/03/2004 21:34 <DIR> COWON
14/11/2003 01:43 <DIR> Drag'n Drop CD+DVD
30/05/2005 23:19 <DIR> funkitron
18/04/2006 21:28 <DIR> GamesVIP
16/01/2006 22:37 <DIR> Google
14/11/2003 01:43 <DIR> Help
14/11/2003 01:43 <DIR> Identities
14/03/2006 19:15 0 Install.dat
14/11/2003 01:43 <DIR> InterTrust
14/11/2003 01:43 <DIR> InterVideo
12/06/2005 17:36 <DIR> Lavasoft
24/03/2006 16:18 <DIR> liteping
14/11/2003 19:22 <DIR> Macromedia
04/04/2005 00:44 <DIR> McAfee.com Personal Firewall
26/06/2004 16:48 <DIR> Microsoft Games
30/07/2005 16:15 <DIR> MobileAction
04/09/2004 14:18 <DIR> Motive
31/08/2005 00:16 <DIR> Mozilla
14/11/2003 01:43 <DIR> MSN6
09/02/2006 20:43 <DIR> Musicmatch
21/08/2005 02:44 <DIR> ntl
24/07/2004 11:37 <DIR> Real
29/01/2005 23:47 <DIR> Roxio
27/11/2003 23:28 <DIR> Sony Corporation
28/02/2005 23:57 <DIR> Sun
14/11/2003 01:43 <DIR> Symantec
05/01/2005 17:32 <DIR> Talkback
26/02/2004 21:59 <DIR> Template
30/05/2004 12:30 <DIR> Ulead Systems
03/04/2006 17:18 <DIR> Webroot
03/04/2004 23:24 <DIR> XP Visual Tools
11/04/2004 12:05 <DIR> You've Got Pictures Screensaver
09/03/2006 00:15 <DIR> ??pPatch
1 File(s) 0 bytes
37 Dir(s) 11,093,385,216 bytes free
Volume in drive C is VAIO
Volume Serial Number is 98C1-CCF6

Directory of C:\Documents and Settings\Owner\Application Data

03/11/2004 00:26 <DIR> .
03/11/2004 00:26 <DIR> ..
03/11/2004 00:26 <DIR> Symantec
0 File(s) 0 bytes
3 Dir(s) 11,093,385,216 bytes free
Volume in drive C is VAIO
Volume Serial Number is 98C1-CCF6

Directory of C:\Documents and Settings\Default User\Application Data

16/09/2003 10:56 <DIR> .
16/09/2003 10:56 <DIR> ..
29/03/2004 19:24 62 desktop.ini
1 File(s) 62 bytes
2 Dir(s) 11,093,385,216 bytes free
Volume in drive C is VAIO
Volume Serial Number is 98C1-CCF6

Directory of C:\Documents and Settings\LocalService\Application Data

Volume in drive C is VAIO
Volume Serial Number is 98C1-CCF6

Directory of C:\Documents and Settings\NetworkService\Application Data

[TRACE] Enumerating jobs and queues
[TRACE] Activating job 'AEF75FE39184D5F7.job'
[TRACE] Printing all job properties

ApplicationName: 'c:\docume~1\chriso~1\applic~1\spamgr~1\SHOW DENT GPL.exe'
Parameters: ''
WorkingDirectory: ''
Comment: ''
Creator: 'Chris Organ'
Priority: NORMAL
MaxRunTime: 259200000 (3d 0:00:00)
IdleWait: 10
IdleDeadline: 60
MostRecentRun: 12/29/2005 0:00:00
NextRun: 04/18/2006 22:00:00
StartError: SCHED_E_ACCOUNT_INFORMATION_NOT_SET
ExitCode: 0
Status: SCHED_S_TASK_READY
ScheduledWorkItem Flags:
DeleteWhenDone = 0
Suspend = 0
StartOnlyIfIdle = 0
KillOnIdleEnd = 0
RestartOnIdleResume = 0
DontStartIfOnBatteries = 0
KillIfGoingOnBatteries = 0
RunOnlyIfLoggedOn = 1
SystemRequired = 0
Hidden = 1
TaskFlags: 0

1 Trigger

Trigger 0:
Type: Daily
DaysInterval: 1
StartDate: 10/10/1996
EndDate: 00/00/0000
StartTime: 00:00
MinutesDuration: 1440
MinutesInterval: 60
Flags:
HasEndDate = 0
KillAtDuration = 0
Disabled = 0


[TRACE] Activating job 'wrSpySweeperTrialSweep.job'
[TRACE] Printing all job properties

ApplicationName: 'C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe'
Parameters: '/ScheduleSweep=wrSpySweeperTrialSweep'
WorkingDirectory: 'C:\'
Comment: 'WhatToSweep=0,SweepFolders=1,SweepMemory=True,SweepCookies=True,SweepRegistry=True,SweepAllUsers=True,SweepSystemRestore=True,SweepCompressed=False,SweepRootKits=False,DirectDiskSweep=True,SweepFrequency=1,SweepTime=0,OnceHasRun=False'
Creator: 'Chris Organ'
Priority: NORMAL
MaxRunTime: 259200000 (3d 0:00:00)
IdleWait: 10
IdleDeadline: 60
MostRecentRun: 00/00/0000 0:00:00
NextRun: 04/24/2006 2:00:00
StartError: SCHED_S_TASK_HAS_NOT_RUN
ExitCode: 0
Status: SCHED_S_TASK_HAS_NOT_RUN
ScheduledWorkItem Flags:
DeleteWhenDone = 0
Suspend = 0
StartOnlyIfIdle = 0
KillOnIdleEnd = 0
RestartOnIdleResume = 0
DontStartIfOnBatteries = 1
KillIfGoingOnBatteries = 1
RunOnlyIfLoggedOn = 1
SystemRequired = 0
Hidden = 0
TaskFlags: 0

1 Trigger

Trigger 0:
Type: Weekly
WeeksInterval: 1
DaysOfTheWeek: .M.....
StartDate: 04/03/2006
EndDate: 04/03/2006
StartTime: 02:00
MinutesDuration: 0
MinutesInterval: 0
Flags:
HasEndDate = 0
KillAtDuration = 0
Disabled = 0


[TRACE] Activating job 'XoftSpy.job'
[TRACE] Printing all job properties

ApplicationName: 'C:\Program Files\XoftSpy\XoftSpy.exe'
Parameters: '-t'
WorkingDirectory: 'C:\Program Files\XoftSpy'
Comment: 'Runs XoftSpy at Scheduled Time.'
Creator: 'Chris Organ'
Priority: NORMAL
MaxRunTime: 259200000 (3d 0:00:00)
IdleWait: 10
IdleDeadline: 60
MostRecentRun: 00/00/0000 0:00:00
NextRun: 00/00/0000 0:00:00
StartError: SCHED_S_TASK_HAS_NOT_RUN
ExitCode: 0
Status: SCHED_S_TASK_NOT_SCHEDULED
ScheduledWorkItem Flags:
DeleteWhenDone = 0
Suspend = 0
StartOnlyIfIdle = 0
KillOnIdleEnd = 0
RestartOnIdleResume = 0
DontStartIfOnBatteries = 0
KillIfGoingOnBatteries = 0
RunOnlyIfLoggedOn = 1
SystemRequired = 0
Hidden = 0
TaskFlags: 0

No triggers
....And on the 8th day God said, "When my children are intelligent, and create the Computer, for my sake may they never screw around with the registry or subscribe to AOL"Posted Image

#10 graveangel

graveangel
  • Topic Starter

  • Members
  • 399 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Nottingham England Home to the Hood of Robin
  • Local time:05:21 PM

Posted 18 April 2006 - 08:36 PM

----------------------------------
uninstall manager list:
----------------------------------

123 Free Solitaire
Ad-Aware SE Personal
Adobe Acrobat 5.0
Adobe Reader 6.0.1
Alone in the Dark - The New Nightmare
Aluria LiteScanner
AOL Connectivity Services
Arovax Shield 1.2.346
ATI Control Panel
ATI Display Driver
AutoCAD 2002
Belkin Bluetooth Software
Belkin Wireless Setup utility
Bobble Puzzle 0.87
broadband medic
BT Voyager 105 ADSL Modem
BT Voyager Modem AOL Test
CleanUp!
Click to DVD 1.2
C-Media USB Audio
Drag'n Drop CD+DVD
DVD Shrink 3.2
Easy CD & DVD Creator 6
ewido anti-malware
GearDrivers
Google Desktop Search
Google Earth
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 1.99.1
HotKey Utility
IMSI Applications
InterVideo WinDVD 4
J2SE Runtime Environment 5.0 Update 6
jetAudio
LucasArts' Curse of Monkey Island
Macromedia Shockwave Player
Mario Forever v 2.16 !
Media Library Management Wizard
Memory Stick Formatter
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft AntiSpyware
Microsoft Data Access Components KB870669
Microsoft Office XP Media Content
Microsoft Office XP Professional with FrontPage
Microsoft Office XP Standard
Microsoft Windows Journal Viewer
Microsoft Works 7.0
Movie Maker Background Music Files
Movie Maker Sound Effects
Movie Maker Title Images
Mozilla Firefox (1.5.0.2)
MSN Messenger 7.5
MSN Toolbar
Music Visualizer Library 1.4.00
Musicmatch® Jukebox
ntl Netguard Security
OpenMG Limited Patch 3.2-03-02-21-08
OpenMG Limited Patch 3.2-03-03-18-01
OpenMG Limited Patch 3.2-03-04-14-02
OpenMG Secure Module 3.2
Panda ActiveScan
Personal License Update Wizard for Windows Media Player
Philips GoGear HDD Device Manager
PictureGear Studio 1.0
Poker Superstars Invitational
PokerStars
QuickTime
RealArcade
RealPlayer
Rogue Spear
Samsung PC Studio 2.1
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
SoftK56 Data Fax CARP
SonicStage 1.6.00
Sony DV Shared Library
Sony Notebook Setup
Sony USB Mouse
Sony Utilities DLL
SoundMAX
Tiscali
TweakNow RegCleaner Standard
Tweak-XP Pro v3
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB910437)
VAIO BrightColor Wallpaper
VAIO Clock Screen Saver
VAIO DeepSea Wallpaper
VAIO Edit Components LE
VAIO Media 2.5
VAIO Media Music Server 2.5
VAIO Media Photo Server 2.5
VAIO Media Platform 2.5
VAIO Media Redistribution 2.5
VAIO Media Setup 2.5
VAIO Online Registration (English)
Vampire - The Masquerade Bloodlines
Viewpoint Media Player
Visual IP InSight 4.3 (UK)
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Media Bonus Pack for Windows XP
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player Playlist Import to Excel Wizard
Windows Media Player Skin Importer
Windows Media Player Tray Control
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WinZip
World Clock
Yahoo! Toolbar


-------------------------------
Panda Activescan
-------------------------------


Incident Status Location

Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-1.txt[]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-15.txt[]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-16.txt[]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-17.txt[]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-18.txt[]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-19.txt[]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-2.txt[]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-20.txt[]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-21.txt[]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-22.txt[]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-36.txt[]
Spyware:Cookie/Bs.serving-sys Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-44.txt[]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-5.txt[]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Chris Organ\Application Data\Mozilla\Firefox\Profiles\puf0cv81.default\cookies-6.txt[]
Dialer:dialer.cos Not disinfected C:\Documents and Settings\Chris Organ\My Documents\exsplorer.lnk
Potentially unwanted tool:Application/FunWeb Not disinfected C:\RECYCLER\NPROTECT\00033745.DLL_
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\RECYCLER\NPROTECT\00033753.DLL_t
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\RECYCLER\NPROTECT\00033754.DLL_t
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\RECYCLER\NPROTECT\00033757.F3S_to
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\RECYCLER\NPROTECT\00033758.F3S_
Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00034182.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034184.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034185.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034189.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034208.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034214.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034225.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034229.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034236.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034239.MOZ[]
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\NPROTECT\00034265.MOZ[]
Spyware:Cookie/Belnk Not disinfected C:\RECYCLER\NPROTECT\00034286.MOZ[]
Spyware:Cookie/Belnk Not disinfected C:\RECYCLER\NPROTECT\00034586.MOZ[]
Spyware:Cookie/MediaTickets Not disinfected C:\RECYCLER\NPROTECT\00034628.MOZ[]
Spyware:Cookie/did-it Not disinfected C:\RECYCLER\NPROTECT\00034632.MOZ[]
Spyware:Cookie/did-it Not disinfected C:\RECYCLER\NPROTECT\00034636.MOZ[]
Spyware:Cookie/MediaTickets Not disinfected C:\RECYCLER\NPROTECT\00034639.MOZ[]
Spyware:Cookie/MediaTickets Not disinfected C:\RECYCLER\NPROTECT\00034643.MOZ[]
Spyware:Cookie/MediaTickets Not disinfected C:\RECYCLER\NPROTECT\00034645.MOZ[]
Spyware:Cookie/MediaTickets Not disinfected C:\RECYCLER\NPROTECT\00034710.MOZ[]
Spyware:Cookie/did-it Not disinfected C:\RECYCLER\NPROTECT\00034715.MOZ[]
Spyware:Cookie/did-it Not disinfected C:\RECYCLER\NPROTECT\00034725.MOZ[]
Adware:Adware/Lop Not disinfected C:\RECYCLER\NPROTECT\00035369.exe
Adware:Adware/IST.ISTBar Not disinfected C:\RECYCLER\S-1-5-21-2867655698-3773606717-3605103424-1005\Dc1\weather.exe
Adware:Adware/Lop Not disinfected C:\RECYCLER\S-1-5-21-2867655698-3773606717-3605103424-1005\Dc2\Dupe Dumb.exe
Adware:Adware/Lop Not disinfected C:\RECYCLER\S-1-5-21-2867655698-3773606717-3605103424-1005\Dc2\mapi eggs.exe
Adware:Adware/Lop Not disinfected C:\RECYCLER\S-1-5-21-2867655698-3773606717-3605103424-1005\Dc3\Scr dupe time up.exe
Adware:Adware/Lop Not disinfected C:\RECYCLER\S-1-5-21-2867655698-3773606717-3605103424-1005\Dc3\tuquntgh.exe
Adware:Adware/Lop Not disinfected C:\RECYCLER\S-1-5-21-2867655698-3773606717-3605103424-1005\Dc3\WipeSkipLogo.exe
....And on the 8th day God said, "When my children are intelligent, and create the Computer, for my sake may they never screw around with the registry or subscribe to AOL"Posted Image

#11 graveangel

graveangel
  • Topic Starter

  • Members
  • 399 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Nottingham England Home to the Hood of Robin
  • Local time:05:21 PM

Posted 18 April 2006 - 08:43 PM

Logfile of HijackThis v1.99.1
Scan saved at 02:10:19, on 19/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ntl\ntl Netguard\fws.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Sony\HotKey Utility\HKserv.exe
C:\WINDOWS\system32\carpserv.exe
C:\WINDOWS\system32\bcmwltry.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
C:\Program Files\VoyagerTest\fts.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\drag'n drop cd+dvd\BinFiles\DragDrop.exe
C:\Program Files\ntl\ntl Netguard\Rps.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Visual IP InSight\UK\ARMon32a.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Apoint\Apvfb.exe
C:\Program Files\SONY\vaio media music server\SSSvr.exe
C:\Program Files\sony\photo server\appsrv\PhotoAppSrv.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\sony shared\vaio media platform\SV_Httpd.exe
C:\Program Files\Common Files\sony shared\vaio media platform\UPnPFramework.exe
C:\Program Files\Common Files\Sony Shared\vaio media platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\vaio media platform\UPnPFramework.exe
C:\Program Files\Sony\HotKey Utility\HKWnd.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Chris Organ\Desktop\Hi Jack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchasst.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.whsmithonline.co.uk/redir.asp?page=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Lee's Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: PopKill Class - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\ntl\ntl Netguard\pkR.dll
O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\ntl\ntl Netguard\FBHR.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: IeCaptureBho Object - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [RemoveCpl] "RemoveCpl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] "ICO.EXE"
O4 - HKLM\..\Run: [HKSERV.EXE] "C:\Program Files\Sony\HotKey Utility\HKserv.exe"
O4 - HKLM\..\Run: [CARPService] "carpserv.exe"
O4 - HKLM\..\Run: [bcmwltry] "bcmwltry.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [ATIModeChange] "Ati2mdxx.exe"
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [DSLSTATEXE] "C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon"
O4 - HKLM\..\Run: [DSLAGENTEXE] "C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe"
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\VoyagerTest\fts.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [CmUsbAudio] RunDll32 cmcnfg2.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Drag'n Drop CD+DVD] C:\Program Files\drag'n drop cd+dvd\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [ntl Netguard] C:\Program Files\ntl\ntl Netguard\Rps.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.whsmithonline.co.uk/redir.asp?page=home
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\ntl\ntl Netguard\fws.exe
O23 - Service: Visual IP InSight Client (UK) (InverseLaunchIPI_WOL:WOLUK) - Visual Networks - C:\Program Files\Visual IP InSight\UK\LaunchIPI.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\SONY\vaio media music server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\vaio media platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\vaio media platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\sony\photo server\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\sony shared\vaio media platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\sony shared\vaio media platform\UPnPFramework.exe



Once again,massive thanks for all this.
....And on the 8th day God said, "When my children are intelligent, and create the Computer, for my sake may they never screw around with the registry or subscribe to AOL"Posted Image

#12 Papakid

Papakid

    Guru at being a Newbie


  • Malware Response Team
  • 6,583 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:21 AM

Posted 19 April 2006 - 11:31 AM

OK, to answer your question about Firefox, yes, it is more secure than IE and it's recommended to use it for everyday surfing and only use IE when that's required, such as to visit windows updates, online virus scanners that use ActiveX, etc. Those 43-spyware you mention are tracking cookies and you'll get them everytime you visit a site that has ads displayed by an ad server, doesn't matter what browser you use. Again these aren't real baddies, just minor privacy concerns.

Those five tools you mention are not hacking tools, but potentialy unwanted search tools that have been removed to your recycle bin anyway, so don't worry about that. They are essentially quarantined by Norton's NProtect and the probelm there is how to return your recyle bin to normal so all files there can be fully deleted. I'm still working on finding a solution for that but we want to get rid of the more serious problems first--the dialer, LOP and Purity Scan. Some of these are just remnants that needs to be cleaned up, but the dialer at least appears to be fairly tricky.

You'll need to print or save these instructions to Notepad, as you won't have access to them in safe mode.

Boot into safe mode and delete the following folders.

C:\Documents and Settings\All Users\Application Data\Mess Owns Setup Trust
C:\Documents and Settings\Chris Organ\Application Data\liteping


While you are in the C:\Documents and Settings\Chris Organ\Application Data folder I want you to look for this folder: ??pPatch. This most likely will not have the question marks, but will appear to be named AppPatch or something similar, but the A and p may look a little funny. This is probably a trick by Purity Scan, but to be sure I would like for you to find this folder, let me know what the real name is, and make a list of any files found inside and post back here. The easiest way to do this so that the exact spelling is copied, is to right click the file/folder, choose rename, then right click again to copy, then paste to a new notepad file. Just click away from the file instead of actually renaming it.

Now I want you to delete a schduled task put there by LOP.

Click on the Start button & select Run.
Type in tasks & click OK.
In the ensuing window, click on the Advanced menu (located above) & select View Hidden Tasks.

Right click and delete the following and any others that consist of 16 random upper case letters and numbers. It may or may not have the .job extension:

AEF75FE39184D5F7.job

If you have also uninstalled SpySweeper and XoftSpy--I don't see them in your Add/Remove list, you should also delete these:

wrSpySweeperTrialSweep.job
XoftSpy.job


Now open KillBox and delete the following according to the intructions provided earlier:

C:\Documents and Settings\Chris Organ\My Documents\exsplorer.lnk

Allow the machine to reboot back into normal mode.

Download Registry Search.

- Create a new folder on your desktop named Regsearch
- Extract regsearch.zip file to the newly created folder.
- Open the Regsearch folder and double click regsearch.exe to start the program.
- Use copy and paste to enter the following bold text to search for and click OK.

exsplorer
linkautomatici
redfunny
skymasters
archiviosex
sfonditalia
sgrunt
xbeta69
snprtz


- Notepad will be opened with text in it (the file will also be saved in the Regsearch folder as well).

Post this text in your next reply along with the new HijackThis log.

I have to go to work now, so that is enough for now--there will be more to do once you post back.

The fate of all mankind, I see

Is in the hands of fools

--King Crimson


#13 graveangel

graveangel
  • Topic Starter

  • Members
  • 399 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Nottingham England Home to the Hood of Robin
  • Local time:05:21 PM

Posted 19 April 2006 - 01:19 PM

Hi Papakid,hope all is ok!

Ive followed your instructions in your previous post and only a couple of things to tell you. I deleted the folders as you said, and deleted the AEF75FE39184D5F7.job thingy,it was the only one there that was showing,along with the "wrSpySweeperTrialSweep.job and XoftSpy.job" as like you said,they are no longer present running programmes.

As regards to the folder 'АрpPatch', that is its real name in the system and and looks exactly like that (this is the copy and paste) no strange letters. Also the АрpPatch folder is empty.

I did the Registry search, and the log came up.

I cannot thank you enough for this help,i hope work has gone well,big big thanks! :thumbsup:

Heres the registry log,hope its worked ok:

REGEDIT4

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.0.1

; Results at 19/04/2006 18:53:49 for strings:
; 'exsplorer
linkautomatici
redfunny
skymasters
archiviosex
sfonditalia
sgrunt
xbeta69
snprtz '
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


; End Of The Log...



Logfile of HijackThis v1.99.1
Scan saved at 19:15:18, on 19/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ntl\ntl Netguard\fws.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Sony\HotKey Utility\HKserv.exe
C:\WINDOWS\system32\carpserv.exe
C:\WINDOWS\system32\bcmwltry.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
C:\Program Files\VoyagerTest\fts.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\drag'n drop cd+dvd\BinFiles\DragDrop.exe
C:\Program Files\ntl\ntl Netguard\Rps.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Visual IP InSight\UK\ARMon32a.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Apoint\Apvfb.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\SONY\vaio media music server\SSSvr.exe
C:\Program Files\sony\photo server\appsrv\PhotoAppSrv.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\sony shared\vaio media platform\SV_Httpd.exe
C:\Program Files\Common Files\sony shared\vaio media platform\UPnPFramework.exe
C:\Program Files\Common Files\Sony Shared\vaio media platform\sv_httpd.exe
C:\Program Files\Sony\HotKey Utility\HKWnd.exe
C:\Program Files\Common Files\Sony Shared\vaio media platform\UPnPFramework.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Chris Organ\Desktop\Hi Jack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchasst.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.whsmithonline.co.uk/redir.asp?page=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Lee's Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: PopKill Class - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\ntl\ntl Netguard\pkR.dll
O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\ntl\ntl Netguard\FBHR.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: IeCaptureBho Object - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [RemoveCpl] "RemoveCpl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] "ICO.EXE"
O4 - HKLM\..\Run: [HKSERV.EXE] "C:\Program Files\Sony\HotKey Utility\HKserv.exe"
O4 - HKLM\..\Run: [CARPService] "carpserv.exe"
O4 - HKLM\..\Run: [bcmwltry] "bcmwltry.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [ATIModeChange] "Ati2mdxx.exe"
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [DSLSTATEXE] "C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon"
O4 - HKLM\..\Run: [DSLAGENTEXE] "C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe"
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\VoyagerTest\fts.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [CmUsbAudio] RunDll32 cmcnfg2.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Drag'n Drop CD+DVD] C:\Program Files\drag'n drop cd+dvd\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [ntl Netguard] C:\Program Files\ntl\ntl Netguard\Rps.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.whsmithonline.co.uk/redir.asp?page=home
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\ntl\ntl Netguard\fws.exe
O23 - Service: Visual IP InSight Client (UK) (InverseLaunchIPI_WOL:WOLUK) - Visual Networks - C:\Program Files\Visual IP InSight\UK\LaunchIPI.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\SONY\vaio media music server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\vaio media platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\vaio media platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\sony\photo server\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\sony shared\vaio media platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\sony shared\vaio media platform\UPnPFramework.exe

Edited by graveangel, 19 April 2006 - 07:42 PM.

....And on the 8th day God said, "When my children are intelligent, and create the Computer, for my sake may they never screw around with the registry or subscribe to AOL"Posted Image

#14 Papakid

Papakid

    Guru at being a Newbie


  • Malware Response Team
  • 6,583 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:21 AM

Posted 20 April 2006 - 11:51 AM

OK, your HJT log is clear of malware now. But LOP being hidden from HJT and some other malware files showing up in other logs has me a bit concerned. I think they are mostly harmless leftovers and you are in pretty good shape as far as being infection free goes and that the slowness is from other issues with software on the PC. But I want to do a few more scans for hidden infections and then concentrate on what the other issues might be when I'm satisfied you're all clear of malware.

The reason I'm having you hold off on installing a firewall is because of the problems you had with Symantec/Norton. Firewalls are fairly invasive programs and don't agree with particular systems and if you have a problem with Norton you could well have a problem with getting a good install of the firewall. We'll work on that next.

Before we get started on the scans there are a few files and folders in your appication data directories that you can clean out. These are from applications that are obviously no longer installed or were never installed. We're goin to leave Symantec's folders for now and some others may need to go, but some may be related to other software that is running that you want so just delete these and we'll look into the others in more detail later.

C:\Documents and Settings\All Users\Application Data\McAfee.com
C:\Documents and Settings\Chris Organ\Application Data\Install.dat
C:\Documents and Settings\Chris Organ\Application Data\McAfee.com Personal Firewall
C:\Documents and Settings\Chris Organ\Application Data\Webroot
C:\Documents and Settings\Chris Organ\Application Data\??pPatch

Download WinPFind!
  • Extract WinPFind.zip to your c:\ folder.
  • Reboot your computer into Safe Mode
  • Then open c:\WinPFind and double-click on WinPFind.exe.
  • When the program is open, click on the Start Scan button to start scanning your computer.
  • Be patient as this scan may take a while. When it is done, it will show a log and tell you the scan is completed.
  • Reboot your computer back to normal mode and and post the contents of c:\WinPFind\WinPFind.txt as a reply to this topic.
If you have any problems getting results with Pfind (there should be a long list), try Silent Runners as an altenative. But i don't need to see both.

Download Silentrunners from this page:

http://www.silentrunners.org/sr_scriptuse.html

Read over the instructions on that page.

Run the SilentRunners.vbs file. If your antivirus has a script blocker, you will get a warning asking if you want to allow SilentRunners.vbs to run. It might say something like "Malicious Script Warning". This script is not malicious so you are safe in allowing it to run.

When it has finished it will produce a Startup Programs text file. Copy and paste that text file here in your next reply.

Download and Save Blacklite to your desktop.
F-Secure Blacklight: http://www.f-secure.com/blacklight/try.shtml
*Double-click blbeta.exe then accept the agreement.
*Leave [X]scan through windows explorer checked,
*Click Scan then Next.
*When the scan is complete you'll see a list of all items found. Don't choose rename yet! I want to see the log first, because legit items such as "wbemtest.exe" can also be present.
*There will be also a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers).

Please perform this online scan: Kaspersky Webscan
1. Read the Requirements and Privacy statement, then select "Accept"
2. A dialogue box will appearing asking "Do you want to install this software?" Name: kavwebscan_unicode.cab
NOTE: If you are running XP SP2, you may need to click on the Information Bar to allow the ActiveX to install and may need to repeat step 1.
3. Select "Install" to download the ActiveX controls that allows ActiveScan to run.
4. If running MSAS beta you may receive an alert that an IE ActiveX program requires your approval. Click "Allow"
5. When the download is complete it will say ready, click "Next"
6. Click "Scan Settings" and check the option to use the EXTENDED DATABASE, then click "OK"
7. Select a target to scan: Click on "My Computer"
8. When the scan is complete choose to save the results as "Save as Text"
9. Post the Kaspersky scan results in your next reply

If any problems with these instructions be sure to let me know. More long logs to post :thumbsup: but we should know if you are free from malware as much as that is possible after this.

The fate of all mankind, I see

Is in the hands of fools

--King Crimson


#15 graveangel

graveangel
  • Topic Starter

  • Members
  • 399 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Nottingham England Home to the Hood of Robin
  • Local time:05:21 PM

Posted 21 April 2006 - 11:52 AM

Hi Papakid,the scans worked ok. I had a problem at first installing winpfind,i dowloaded it, but winzip said it had a file missing(winzip its self that is) and wouldnt unzip it,it worked fine before when unzipping so dont know if we deleted a file earlier, i got winpfind installed after i went to the winzip website and downloaded winzip 10,it was ok after that! I also noticed on the virus scan on kaspersky that on the 'E' drive (which is the memory stick) it has found two virus items,these are accessable and i can delete them,is it ok to just go in and do that?

Again,its over a couple of logs,thanks papakid your a star for this!

Here is the winpfind log:

WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP Current Build: Service Pack 2 Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...
UPX! 20/02/2005 01:39:32 4918270 C:\Program Files\Firefox Setup 1.0.exe
aspack 05/07/2005 00:04:34 2788240 C:\Program Files\PokerStarsInstallPM.exe

Checking %WinDir% folder...

Checking %System% folder...
PEC2 29/08/2002 13:00:00 41397 C:\WINDOWS\SYSTEM32\dfrg.msc
UPX! 25/10/2004 22:12:42 372736 C:\WINDOWS\SYSTEM32\Iftvmk38wbr.dll
PTech 14/02/2006 09:20:14 550120 C:\WINDOWS\SYSTEM32\LegitCheckControl.dll
PECompact2 06/04/2006 20:48:38 5143456 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 06/04/2006 20:48:38 5143456 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 04/08/2004 00:56:38 708096 C:\WINDOWS\SYSTEM32\ntdll.dll
Umonitor 04/08/2004 00:56:46 657920 C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync 29/08/2002 13:00:00 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu

Checking %System%\Drivers folder and sub-folders...
aspack 20/01/2006 15:40:42 R 783984 C:\WINDOWS\SYSTEM32\drivers\css-dvp.sys
PTech 03/08/2004 22:41:38 1309184 C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys

Items found in C:\WINDOWS\SYSTEM32\drivers\etc\hosts


Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
20/04/2006 18:47:12 S 2048 C:\WINDOWS\bootstat.dat
20/04/2006 17:41:52 H 54156 C:\WINDOWS\QTFont.qfn
18/04/2006 18:41:30 HS 19456 C:\WINDOWS\system32\Thumbs.db
23/03/2006 00:17:30 S 14054 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB908531.cat
23/03/2006 07:15:38 S 10925 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB911562.cat
13/03/2006 16:45:34 S 7898 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB911565.cat
17/03/2006 10:24:26 S 12455 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB911567.cat
30/03/2006 11:03:56 S 22339 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB912812.cat
20/04/2006 18:47:02 H 8192 C:\WINDOWS\system32\config\DEFAULT.LOG
20/04/2006 18:47:28 H 1024 C:\WINDOWS\system32\config\SAM.LOG
20/04/2006 18:47:14 H 16384 C:\WINDOWS\system32\config\SECURITY.LOG
20/04/2006 18:54:28 H 98304 C:\WINDOWS\system32\config\SOFTWARE.LOG
20/04/2006 18:47:20 H 1093632 C:\WINDOWS\system32\config\SYSTEM.LOG
13/04/2006 00:57:48 H 1024 C:\WINDOWS\system32\config\systemprofile\NTUSER.DAT.LOG
30/03/2006 03:14:04 HS 388 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\26ba4517-175b-4129-b3b3-bd2e04ebe075
30/03/2006 03:14:04 HS 24 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\Preferred
27/03/2006 18:25:42 HS 388 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\520ee588-df92-4ce0-9d78-a5b6cb746cd8
27/03/2006 18:25:42 HS 24 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\Preferred
20/04/2006 18:46:04 H 6 C:\WINDOWS\Tasks\SA.DAT

Checking for CPL files...
Microsoft Corporation 04/08/2004 00:56:58 68608 C:\WINDOWS\SYSTEM32\access.cpl
Microsoft Corporation 04/08/2004 00:56:58 549888 C:\WINDOWS\SYSTEM32\appwiz.cpl
Belkiin Corporation 13/01/2003 11:25:58 364544 C:\WINDOWS\SYSTEM32\bcmwlcpl.cpl
Broadcom Corporation 01/10/2004 15:40:16 266299 C:\WINDOWS\SYSTEM32\btcpl.cpl
Microsoft Corporation 04/08/2004 00:56:58 110592 C:\WINDOWS\SYSTEM32\bthprops.cpl
Microsoft Corporation 04/08/2004 00:56:58 135168 C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation 04/08/2004 00:56:58 80384 C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation 04/08/2004 00:56:58 155136 C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Microsoft Corporation 04/08/2004 00:56:58 358400 C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation 04/08/2004 00:56:58 129536 C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation 04/08/2004 00:56:58 380416 C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation 04/08/2004 00:56:58 68608 C:\WINDOWS\SYSTEM32\joy.cpl
Sun Microsystems, Inc. 10/11/2005 14:03:50 49265 C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation 29/08/2002 13:00:00 187904 C:\WINDOWS\SYSTEM32\main.cpl
Microsoft Corporation 04/08/2004 00:56:58 618496 C:\WINDOWS\SYSTEM32\mmsys.cpl
Microsoft Corporation 29/08/2002 13:00:00 35840 C:\WINDOWS\SYSTEM32\ncpa.cpl
Microsoft Corporation 04/08/2004 00:56:58 25600 C:\WINDOWS\SYSTEM32\netsetup.cpl
Microsoft Corporation 04/08/2004 00:56:58 257024 C:\WINDOWS\SYSTEM32\nusrmgr.cpl
Microsoft Corporation 04/08/2004 00:56:58 32768 C:\WINDOWS\SYSTEM32\odbccp32.cpl
Autodesk, Inc. 23/04/2001 01:35:46 454718 C:\WINDOWS\SYSTEM32\plotman.cpl
Microsoft Corporation 04/08/2004 00:56:58 114688 C:\WINDOWS\SYSTEM32\powercfg.cpl
Apple Computer, Inc. 06/01/2004 16:02:36 323072 C:\WINDOWS\SYSTEM32\QuickTime.cpl
Sony Corporation 06/08/2002 17:00:00 53248 C:\WINDOWS\SYSTEM32\SNSetup.cpl
Autodesk, Inc. 23/04/2001 01:35:50 454719 C:\WINDOWS\SYSTEM32\styleman.cpl
Microsoft Corporation 04/08/2004 00:56:58 298496 C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation 29/08/2002 13:00:00 28160 C:\WINDOWS\SYSTEM32\telephon.cpl
Microsoft Corporation 04/08/2004 00:56:58 94208 C:\WINDOWS\SYSTEM32\timedate.cpl
Sony Corporation 04/12/1999 04:11:30 151552 C:\WINDOWS\SYSTEM32\UILib.cpl
Microsoft Corporation 04/08/2004 00:56:58 148480 C:\WINDOWS\SYSTEM32\wscui.cpl
Microsoft Corporation 26/05/2005 04:16:30 174360 C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation 04/08/2004 00:56:58 68608 C:\WINDOWS\SYSTEM32\dllcache\access.cpl
Microsoft Corporation 04/08/2004 00:56:58 549888 C:\WINDOWS\SYSTEM32\dllcache\appwiz.cpl
Microsoft Corporation 04/08/2004 00:56:58 110592 C:\WINDOWS\SYSTEM32\dllcache\bthprops.cpl
Microsoft Corporation 04/08/2004 00:56:58 135168 C:\WINDOWS\SYSTEM32\dllcache\desk.cpl
Microsoft Corporation 04/08/2004 00:56:58 80384 C:\WINDOWS\SYSTEM32\dllcache\firewall.cpl
Microsoft Corporation 04/08/2004 00:56:58 155136 C:\WINDOWS\SYSTEM32\dllcache\hdwwiz.cpl
Microsoft Corporation 04/08/2004 00:56:58 358400 C:\WINDOWS\SYSTEM32\dllcache\inetcpl.cpl
Microsoft Corporation 04/08/2004 00:56:58 129536 C:\WINDOWS\SYSTEM32\dllcache\intl.cpl
Microsoft Corporation 04/08/2004 00:56:58 380416 C:\WINDOWS\SYSTEM32\dllcache\irprops.cpl
Microsoft Corporation 04/08/2004 00:56:58 68608 C:\WINDOWS\SYSTEM32\dllcache\joy.cpl
Microsoft Corporation 29/08/2002 13:00:00 187904 C:\WINDOWS\SYSTEM32\dllcache\main.cpl
Microsoft Corporation 04/08/2004 00:56:58 618496 C:\WINDOWS\SYSTEM32\dllcache\mmsys.cpl
Microsoft Corporation 29/08/2002 13:00:00 35840 C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl
Microsoft Corporation 04/08/2004 00:56:58 25600 C:\WINDOWS\SYSTEM32\dllcache\netsetup.cpl
Microsoft Corporation 04/08/2004 00:56:58 257024 C:\WINDOWS\SYSTEM32\dllcache\nusrmgr.cpl
Microsoft Corporation 04/08/2004 00:56:58 32768 C:\WINDOWS\SYSTEM32\dllcache\odbccp32.cpl
Microsoft Corporation 04/08/2004 00:56:58 114688 C:\WINDOWS\SYSTEM32\dllcache\powercfg.cpl
Microsoft Corporation 04/08/2004 00:56:58 155648 C:\WINDOWS\SYSTEM32\dllcache\sapi.cpl
Microsoft Corporation 04/08/2004 00:56:58 298496 C:\WINDOWS\SYSTEM32\dllcache\sysdm.cpl
Microsoft Corporation 29/08/2002 13:00:00 28160 C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl
Microsoft Corporation 04/08/2004 00:56:58 94208 C:\WINDOWS\SYSTEM32\dllcache\timedate.cpl
Microsoft Corporation 04/08/2004 00:56:58 148480 C:\WINDOWS\SYSTEM32\dllcache\wscui.cpl
Microsoft Corporation 26/05/2005 04:16:30 174360 C:\WINDOWS\SYSTEM32\dllcache\wuaucpl.cpl

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder...
29/03/2004 18:37:44 HS 84 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
20/04/2006 18:41:22 1522 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk

Checking files in %ALLUSERSPROFILE%\Application Data folder...
29/03/2004 19:24:54 HS 62 C:\Documents and Settings\All Users\Application Data\desktop.ini
02/11/2005 22:12:22 11 C:\Documents and Settings\All Users\Application Data\DragToDiscUserNameF.txt
10/09/2004 21:33:30 370 C:\Documents and Settings\All Users\Application Data\WhiteCap Prefs (jetAudio).txt
19/09/2004 15:55:00 385 C:\Documents and Settings\All Users\Application Data\WhiteCap Prefs (Windows Media Player).txt

Checking files in %USERPROFILE%\Startup folder...
29/03/2004 18:37:44 HS 84 C:\Documents and Settings\Chris Organ\Start Menu\Programs\Startup\desktop.ini

Checking files in %USERPROFILE%\Application Data folder...
29/03/2004 19:24:54 HS 62 C:\Documents and Settings\Chris Organ\Application Data\desktop.ini

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
WHSmith Online V1.14 = IEAKWHSmith Online
SV1 =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
=

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Trojan Remover
{52B87208-9CCF-42C9-B88E-069281105805} =
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{FFFFE5C1-34AF-4d4d-B3D3-5BB86A2BAA7B}
= C:\Program Files\ntl\ntl Netguard\AVCntxtR.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\ContMenu
{EBDF1F20-C829-11D1-8233-0020AF3E97A6} =
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\jetAudio
{8D1636FD-CA49-4b4e-90E4-0A20E03A15E8} = C:\Program Files\JetAudio\JetFlExt.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\Trojan Remover
{52B87208-9CCF-42C9-B88E-069281105805} =
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\{FFFFE5C1-34AF-4d4d-B3D3-5BB86A2BAA7B}
= C:\Program Files\ntl\ntl Netguard\AVCntxtR.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ContMenu
{EBDF1F20-C829-11D1-8233-0020AF3E97A6} =
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\jetAudio
{8D1636FD-CA49-4b4e-90E4-0A20E03A15E8} = C:\Program Files\JetAudio\JetFlExt.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\{FFFFE5C1-34AF-4d4d-B3D3-5BB86A2BAA7B}
= C:\Program Files\ntl\ntl Netguard\AVCntxtR.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= %SystemRoot%\system32\SHELL32.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Yahoo! Toolbar Helper = C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
AcroIEHlprObj Class = C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3C060EA2-E6A9-4E49-A530-D4657B8C449A}
PopKill Class = C:\Program Files\ntl\ntl Netguard\pkR.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{56071E0D-C61B-11D3-B41C-00E02927A304}
ZKBho Class = C:\Program Files\ntl\ntl Netguard\FBHR.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
SSVHelper Class = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7c1ce531-09e9-4fc5-9803-1c2956615786}
IeCaptureBho Object = C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}
ST = C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
MSNToolBandBHO = C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = %SystemRoot%\system32\shdocvw.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{FE54FA40-D68C-11d2-98FA-00C0F0318AFE}
Real.com = C:\WINDOWS\System32\Shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} = Yahoo! Toolbar : C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} = MSN : C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
MenuText = Sun Java Console : C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2D663D1A-8670-49D9-A1A5-4C56B4E14E84}
ButtonText = Spyware Doctor :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CCA281CA-C863-46ef-9331-5C8D4460577F}
ButtonText = @btrez.dll,-4015 :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
ButtonText = Real.com :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
ButtonText = Messenger : C:\Program Files\Messenger\msmsgs.exe

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
=
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}
File Search Explorer Band = %SystemRoot%\system32\SHELL32.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E}
Explorer Band = %SystemRoot%\system32\shdocvw.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} = :
{0494D0D9-F8E0-41AD-92A3-14154ECE70AC} = :
{07B18EA9-A523-4961-B6BB-170DE4475CCA} = :
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{2318C2B1-4965-11D4-9B18-009027A5CD4F} = :
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} = :
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\system32\SHELL32.dll
{EF99BD32-C1FB-11D2-892F-0090271D4F88} = Yahoo! Toolbar : C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} = MSN : C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
ezShieldProtector for Px C:\WINDOWS\system32\ezSP_Px.exe
RemoveCpl "RemoveCpl.exe"
QuickTime Task "C:\Program Files\QuickTime\qttask.exe" -atboottime
Mouse Suite 98 Daemon "ICO.EXE"
HKSERV.EXE "C:\Program Files\Sony\HotKey Utility\HKserv.exe"
CARPService "carpserv.exe"
bcmwltry "bcmwltry.exe"
ATIPTA "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
ATIModeChange "Ati2mdxx.exe"
Apoint "C:\Program Files\Apoint\Apoint.exe"
DSLSTATEXE "C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon"
DSLAGENTEXE "C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe"
%FP%Friendly fts.exe "C:\Program Files\VoyagerTest\fts.exe"
RoxioEngineUtility "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
RoxioDragToDisc "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
RoxioAudioCentral "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
MMTray "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
CmUsbAudio RunDll32 cmcnfg2.cpl,CMICtrlWnd
gcasServ "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
BluetoothAuthenticationAgent rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
Motive SmartBridge C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
TkBellExe "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
Drag'n Drop CD+DVD C:\Program Files\drag'n drop cd+dvd\BinFiles\DragDrop.exe /StartUp
ntl Netguard C:\Program Files\ntl\ntl Netguard\Rps.exe
SunJavaUpdateSched C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
mmtask "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
KernelFaultCheck %systemroot%\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Google Desktop Search "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\ExpandFrom

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\ExpandTo

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state
system.ini 0
win.ini 0
bootini 0
services 0
startup 0


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID
{17492023-C23A-453E-A040-C7C580BBF700} 1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
{0DF44EAA-FF21-4412-828E-260A8728E7F1} =


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
dontdisplaylastusername 0
legalnoticecaption
legalnoticetext
shutdownwithoutlogon 1
undockwithoutlogon 1


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun •
NoComputersNearMe 0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
PostBootReminder {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
CDBurn {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
SysTray {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll
UPnPMonitor {e57ce738-33e8-4c51-8354-bb4de9d215d1} = C:\WINDOWS\system32\upnpui.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
Shell = Explorer.exe
System =

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
= crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
= cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
= cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
= sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
= WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
= wlnotify.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLs


»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.4.1 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 21/04/2006 02:04:31
....And on the 8th day God said, "When my children are intelligent, and create the Computer, for my sake may they never screw around with the registry or subscribe to AOL"Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users