Tech Support Forum banner
Status
Not open for further replies.

Popups;WinAntiVirusPro2006 and others

3K views 24 replies 2 participants last post by  src2206 
#1 ·
Hello.

I followed the 5 steps in the sticky, but when I run ad aware and spybot, I STILL pick up entries. I get random popups from IE, and from firefox when I am using it. It's very frustrating. Here's what I have for you:

HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 2:53:47 AM, on 10/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\avgamsvr.exe
C:\PROGRA~1\avgupsvc.exe
C:\PROGRA~1\avgemc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\GM SPO\eSI\Apache Group\Tomcat 4.1\bin\tomcat.exe
C:\Program Files\GM SPO\eSI\Transbase\tbmux32.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\GM SPO\eSI\Transbase\tbkern32.exe
C:\Program Files\GM SPO\eSI\Transbase\tbkern32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\MMTray.exe
G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtray2k.exe
G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtraylsi.exe
C:\PROGRA~1\avgcc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
G:\PowerDVD6\PDVDServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Messenger\msmsgs.exe
G:\steam\steam.exe
E:\Wlan\WLANPRO.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
E:\Wlan\Reg.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [MMTray] "G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\MMTray.exe"
O4 - HKLM\..\Run: [mmtray2k] "G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtray2k.exe"
O4 - HKLM\..\Run: [mmtraylsi] "G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtraylsi.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] G:\PowerDVD6\PDVDServ.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "g:\steam\steam.exe" -silent
O4 - Global Startup: 108Mbps Wireless LAN Adapter Configuration Utility.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Reg.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4866/mcfscan.cab
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SI Tomcat (SITomcat) - Alexandria Software Consulting - C:\Program Files\GM SPO\eSI\Apache Group\Tomcat 4.1\bin\tomcat.exe
O23 - Service: SI Transbase (SITransbase) - TransAction Software, D 81737 Munich - C:\Program Files\GM SPO\eSI\Transbase\tbmux32.exe


And, here's the reports from McAfee and Bitdefender. I don't think the McAfee one deleted anything...?

C:\Documents and Settings\...\Temp\iscueesg.dll Generic Spy
C:\Documents and Settings\...\Temp\ktbahupx.dll Generic Spy
C:\Documents and Settings\...\Temp\npfmlsvw.dll Generic Spy
C:\Documents and Settings\...\Temp\onltaouo.dll Generic Spy
C:\Documents and Settings\...\Temp\rsxdxaps.dll Generic Spy
C:\System Volume Information\...\A0031633.dll Vundo
C:\System Volume Information\...\A0031659.dll Adware-SearchColours
C:\System Volume Information\...\A0031778.dll Vundo
C:\WINDOWS\system32\eyubgyev.exe Adware-SearchColours
C:\WINDOWS\system32\jjrwmnva.dll Generic Spy
C:\WINDOWS\system32\vfcwqrbr.dll Generic Spy
C:\WINDOWS\system32\xmkwanqc.dll Generic Spy

I also have a bitdefender report I can post if necessary, but it's not in a convienent log file, so it can wait.

Thanks in advance for the help!!

Nathan
 
See less See more
#2 ·
Hi and welcome to TSF, Nathan :smile:.

I am currently reviewing your log. Please note that this is under the supervision of an expert analyst, and I will be back with a fix for your problem as soon as possible.

You may wish to Subscribe to this thread (Thread Tools) so that you are notified when you receive a reply.

Please be patient with me during this time.
 
#3 ·
Hello and welcome to TSF :smile:.

Please print out or copy this page to Notepad in order to assist you when carrying out the following instructions.

You may like to subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools located near the top of this page, then click Subscribe to this Thread. Make sure it is set to Instant email Notification, then click Subscribe.
__________________________________________________________________________________________________________

Downloads

1. Please download Cleanup! and install it. You will use this later. Do not install if you are using the 64 bit version of windows.

*NOTE* Cleanup deletes EVERYTHING out of temporary folders and does not make backups.

2. Download AVG Anti-Spyware
  • Install AVG Anti-Spyware
  • Double-click the icon on Desktop to launch AVG Anti-Spyware
You will need to update AVG Anti-Spyware to the latest definition files.
  • On the top of the main screen click Shield
  • Click the word active to change it to inactive
  • On the top of the main screen click Update.
  • Then click on Start Update. The update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
When you have finished updating, EXIT AVG Anti-Spyware. Do Not run a scan just yet, we will shortly.


3. <i> Download this file -

http://download.bleepingcomputer.com/sUBs/combofix.exe
http://www.techsupportforum.com/sectools/combofix.exe

<ii> Double click combofix.exe & follow the prompts.

* Please disable your Antivirus' Script Blockers for they would interfere with combofix

<iii> When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

___________________________________________

Show Hidden Files and Folders

Go to My Computer >Tools >Folder Options >View tab and select Show hidden files and folders. Uncheck the Hide protected operating system files (recommended) option. Also make sure there is no checkmark beside Hide file extensions for known file types. Click OK.
______________________________________________

Fix

Reboot your system in Safe Mode (By repeatedly tapping the F8 key until the menu appears).

Open HijackThis and click on 'Do a System Scan Only'. Check the following entries (If they still exist, make sure you do not miss any)

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

Please remember to close all other windows, including browsers then click Fix checked.

Delete the following Files indicated in RED and Folders indicated in BLUE if they still exist.

C:\WINDOWS\system32\eyubgyev.exe
C:\WINDOWS\system32\jjrwmnva.dll
C:\WINDOWS\system32\vfcwqrbr.dll
C:\WINDOWS\system32\xmkwanqc.dll


___________________________________________________________________________________________________

Cleanup!

Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
Set the program up as follows:

Click "Options..."
Move the arrow down to "Custom CleanUp!"
Put a check next to the following (Make sure nothing else is checked!):
  • Empty Recycle Bins
  • Delete Cookies
  • Delete Prefetch files (if present)
  • Cleanup! All Users
  • Click on the Temporary Files tab and uncheck the box for Scan drives for files matching if it’s checked.
Click OK
Press the CleanUp! button to start the program.

Do not logoff or reboot when prompted.

AVG Anti-Spyware

Run AVG Anti-Spyware with it's updated definitions:(...it's important that all windows must be closed)
  • Click Scanner
  • Click on the Scan tab
  • Click Complete System Scan to begin scanning.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Once finished, click the Save report button, then click Save Report As and save it to your desktop. (make sure to remember where you saved that file, this is important).


Reboot your system in Normal Mode.
______________________________________________

Online Scan

Perform an online scan with Internet Explorer with Panda ActiveScan

Click on the "Free To Use ActiveScan" located on the top right hand corner
  • Click Check Now and a "pop up" window will appear.*Please ensure that your pop up blocker doesn't block it*
  • Enter your e-mail address, country, and state & click Scan Now *The download of the 8 MB Panda's ActiveX control will take place *
Begin the scan by selecting My Computer
  • If it finds any malware, it will offer you a report.
    [*] Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
    [*] Click on See report then click Save report
* You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
* Turn off the real time scanner of any existing antivirus program while performing the online scan
.
_____________________________________________________________________________________

Rename HijackThis.exe

I'd like you to rename HijackThis.exe to Nathan.exe.
  • Navigate to C:\hjt\HijackThis.exe
  • Right click on HijackThis.exe
  • Select 'Rename'
  • Type in Nathan.exe
  • Press Enter.
Now run a system scan with this renamed HJTand save the Logfile to post wiht your next reply.

Please provide the following logs with your next post:

ComboFix.txt
AVG Anti-Spyware
Panda Scan
HijackThis (by the renamed HJT)


Please let me know about your systems overall behaviour :smile:.
 
#4 ·
Thanks for the quick response!

Here is the combofix.exe log.

The Shaolin! - 06-10-11 15:37:53.96 Service Pack 2
ComboFix 06.10.11 - Running from: "C:\Documents and Settings\The Shaolin!\Desktop"

((((((((((((((((((((((((((((((( Files Created from 2006-09-11 to 2006-10-11 ))))))))))))))))))))))))))))))))))


2006-10-11 15:35 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-10-11 00:08 45,525 --a------ C:\WINDOWS\system32\jjrwmnva.dll
2006-09-28 16:22 45,525 --a------ C:\WINDOWS\system32\xmkwanqc.dll
2006-09-28 00:46 45,525 --a------ C:\WINDOWS\system32\vfcwqrbr.dll
2006-09-27 00:29 143,380 --a------ C:\WINDOWS\system32\eyubgyev.exe
2006-09-24 16:32 <DIR> d-------- C:\WINDOWS\McAfee.com
2006-09-19 15:59 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2006-09-19 15:54 223,128 --a------ C:\WINDOWS\system32\drivers\dtscsi.sys
2006-09-19 15:41 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll
2006-09-19 15:41 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll
2006-09-19 15:41 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-10-11 15:38 -------- d-------- C:\Documents and Settings\The Shaolin!\Application Data\.gaim
2006-10-11 15:35 -------- d-------- C:\Program Files\Grisoft
2006-10-11 15:31 4552808 --a------ C:\Program Files\incavi.avm
2006-10-11 15:31 254 --a------ C:\Program Files\upd_vers.cfg
2006-10-11 15:27 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-11 08:43 11980 --a------ C:\Program Files\microavi.avg
2006-10-10 08:43 298684 --a------ C:\Program Files\avg7us.lng
2006-10-07 20:28 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-10-05 15:34 458535 --a------ C:\Program Files\miniavi.avg
2006-09-28 15:26 -------- d-------- C:\Program Files\CCleaner
2006-09-28 08:43 93696 --a------ C:\Program Files\avginet.dll
2006-09-28 08:43 778656 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-09-28 08:43 729835 --a------ C:\Program Files\avg.exe
2006-09-28 08:43 501760 --a------ C:\Program Files\avgcore.dll
2006-09-28 08:43 369664 --a------ C:\Program Files\avgcc.exe
2006-09-28 08:43 310784 --a------ C:\Program Files\avgabout.dll
2006-09-28 08:43 302592 --a------ C:\Program Files\avgvv.exe
2006-09-28 08:43 289280 --a------ C:\Program Files\avgscan.dll
2006-09-28 08:43 231424 --a------ C:\Program Files\avgwb.dat
2006-09-28 08:43 192000 --a------ C:\Program Files\avgunarc.dll
2006-09-28 08:43 155136 --a------ C:\Program Files\avgw.exe
2006-09-26 00:08 -------- d-------- C:\Program Files\KC Softwares
2006-09-24 16:32 -------- d-------- C:\Program Files\iTunes
2006-09-24 16:32 -------- d-------- C:\Program Files\iPod
2006-09-24 16:31 -------- d-------- C:\Program Files\QuickTime
2006-09-20 01:14 -------- d---s---- C:\Documents and Settings\The Shaolin!\Application Data\Microsoft
2006-09-19 20:59 -------- d-------- C:\Program Files\Common Files
2006-09-19 15:58 -------- d-------- C:\Program Files\Microsoft ActiveSync
2006-09-19 15:58 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-09-19 15:57 -------- d-------- C:\Program Files\Microsoft Office
2006-09-19 15:56 -------- d-------- C:\Program Files\Microsoft.NET
2006-09-19 15:56 -------- d-------- C:\Program Files\Common Files\System
2006-09-19 15:56 -------- d-------- C:\Program Files\Common Files\DESIGNER
2006-09-19 15:54 -------- d-------- C:\Program Files\DAEMON Tools
2006-09-19 15:49 643072 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2006-09-19 15:38 -------- d-------- C:\Program Files\RedLightCenter
2006-09-11 15:33 -------- d-------- C:\Program Files\myTunes Redux
2006-09-04 17:06 -------- d-------- C:\Program Files\WS_FTP
2006-09-03 16:34 -------- d-------- C:\Program Files\Windows Media Player
2006-09-03 16:34 -------- d-------- C:\Program Files\Windows Media Connect 2
2006-08-31 00:11 -------- d-------- C:\Program Files\Futuremark
2006-08-30 21:56 -------- d-------- C:\Program Files\Internet Explorer
2006-08-30 21:55 -------- d-------- C:\Program Files\Outlook Express
2006-08-30 21:52 -------- d-------- C:\Program Files\Messenger
2006-08-30 17:53 -------- d-------- C:\Documents and Settings\The Shaolin!\Application Data\Adobe
2006-08-26 22:01 -------- d-------- C:\Program Files\Sonic Foundry
2006-08-26 22:01 -------- d-------- C:\Program Files\Pure Motion
2006-08-26 22:01 -------- d-------- C:\Program Files\DebugMode
2006-08-24 22:42 8704 --------- C:\WINDOWS\system32\wdfmgr.exe
2006-08-24 22:42 8704 --------- C:\WINDOWS\system32\uwdf.exe
2006-08-24 22:30 99840 --a------ C:\WINDOWS\system32\wmpshell.dll
2006-08-24 22:30 990208 --a------ C:\WINDOWS\system32\drmv2clt.dll
2006-08-24 22:30 937984 --a------ C:\WINDOWS\system32\WMNetMgr.dll
2006-08-24 22:30 8337920 --a------ C:\WINDOWS\system32\wmploc.dll
2006-08-24 22:30 790016 --------- C:\WINDOWS\system32\WMVSENCD.dll
2006-08-24 22:30 757248 --a------ C:\WINDOWS\system32\WMADMOD.dll
2006-08-24 22:30 7168 --a------ C:\WINDOWS\system32\asferror.dll
2006-08-24 22:30 656896 --------- C:\WINDOWS\system32\WMVXENCD.dll
2006-08-24 22:30 63488 --------- C:\WINDOWS\system32\wpdmtpus.dll
2006-08-24 22:30 629760 --------- C:\WINDOWS\system32\wpd_ci.dll
2006-08-24 22:30 611840 --------- C:\WINDOWS\system32\wmpmde.dll
2006-08-24 22:30 603648 --a------ C:\WINDOWS\system32\WMSPDMOD.dll
2006-08-24 22:30 537600 --a------ C:\WINDOWS\system32\blackbox.dll
2006-08-24 22:30 532992 --------- C:\WINDOWS\system32\wmdrmsdk.dll
2006-08-24 22:30 428032 --------- C:\WINDOWS\system32\wmdrmdev.dll
2006-08-24 22:30 414208 --a------ C:\WINDOWS\system32\msscp.dll
2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\wmvdmoe2.dll
2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\wmvdmod.dll
2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\wmsdmoe2.dll
2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\wmsdmod.dll
2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\MPG4DMOD.dll
2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\MP4SDMOD.dll
2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\MP43DMOD.dll
2006-08-24 22:30 4096 --------- C:\WINDOWS\system32\WMVADVE.DLL
2006-08-24 22:30 4096 --------- C:\WINDOWS\system32\WMVADVD.dll
2006-08-24 22:30 4096 --------- C:\WINDOWS\system32\wdfapi.dll
2006-08-24 22:30 37376 --a------ C:\WINDOWS\system32\wmdmps.dll
2006-08-24 22:30 35840 --------- C:\WINDOWS\system32\wpdconns.dll
2006-08-24 22:30 349184 --------- C:\WINDOWS\system32\wpdsp.dll
2006-08-24 22:30 347648 --------- C:\WINDOWS\system32\wmdrmnet.dll
2006-08-24 22:30 33792 --a------ C:\WINDOWS\system32\wmdmlog.dll
2006-08-24 22:30 320512 --a------ C:\WINDOWS\system32\mswmdm.dll
2006-08-24 22:30 316928 --------- C:\WINDOWS\system32\MP4SDECD.dll
2006-08-24 22:30 314368 --a------ C:\WINDOWS\system32\wmpdxm.dll
2006-08-24 22:30 305152 --------- C:\WINDOWS\system32\MSDelta.dll
2006-08-24 22:30 295424 --------- C:\WINDOWS\system32\wmpeffects.dll
2006-08-24 22:30 284160 --------- C:\WINDOWS\system32\PortableDeviceApi.dll
2006-08-24 22:30 276480 --------- C:\WINDOWS\system32\audiodev.dll
2006-08-24 22:30 27648 --a------ C:\WINDOWS\system32\mspmsnsv.dll
2006-08-24 22:30 259072 --------- C:\WINDOWS\system32\MPG4DECD.dll
2006-08-24 22:30 2589184 --------- C:\WINDOWS\system32\WpdShext.dll
2006-08-24 22:30 258560 --------- C:\WINDOWS\system32\MP43DECD.dll
2006-08-24 22:30 2450944 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-08-24 22:30 242176 --a------ C:\WINDOWS\system32\wmpasf.dll
2006-08-24 22:30 228352 --a------ C:\WINDOWS\system32\cewmdm.dll
2006-08-24 22:30 227328 --a------ C:\WINDOWS\system32\wmerror.dll
2006-08-24 22:30 222208 --a------ C:\WINDOWS\system32\WMASF.dll
2006-08-24 22:30 211968 --------- C:\WINDOWS\system32\MFPLAT.dll
2006-08-24 22:30 210432 --a------ C:\WINDOWS\system32\qasf.dll
2006-08-24 22:30 204800 --------- C:\WINDOWS\system32\wmpsrcwp.dll
2006-08-24 22:30 198144 --------- C:\WINDOWS\system32\PortableDeviceWMDRM.dll
2006-08-24 22:30 179712 --a------ C:\WINDOWS\system32\msnetobj.dll
2006-08-24 22:30 175104 --a------ C:\WINDOWS\system32\mspmsp.dll
2006-08-24 22:30 166912 --------- C:\WINDOWS\system32\PortableDeviceTypes.dll
2006-08-24 22:30 1660416 --------- C:\WINDOWS\system32\wmpencen.dll
2006-08-24 22:30 157184 --a------ C:\WINDOWS\system32\wmidx.dll
2006-08-24 22:30 154624 --------- C:\WINDOWS\system32\wpdmtp.dll
2006-08-24 22:30 1539584 --------- C:\WINDOWS\system32\WMVDECOD.dll
2006-08-24 22:30 1532416 --------- C:\WINDOWS\system32\WMVENCOD.dll
2006-08-24 22:30 1392128 --------- C:\WINDOWS\system32\WMVSDECD.dll
2006-08-24 22:30 133120 --------- C:\WINDOWS\system32\WPDShServiceObj.dll
2006-08-24 22:30 1327616 --a------ C:\WINDOWS\system32\WMSPDMOE.dll
2006-08-24 22:30 132096 --------- C:\WINDOWS\system32\PortableDeviceWiaCompat.dll
2006-08-24 22:30 130048 --------- C:\WINDOWS\system32\wmpps.dll
2006-08-24 22:30 11264 --a------ C:\WINDOWS\system32\LAPRXY.dll
2006-08-24 22:30 1118208 --a------ C:\WINDOWS\system32\WMADMOE.dll
2006-08-24 22:30 101888 --------- C:\WINDOWS\system32\PortableDeviceClassExtension.dll
2006-08-24 20:31 100864 --a------ C:\WINDOWS\system32\logagent.exe
2006-08-24 20:27 249344 --------- C:\WINDOWS\system32\drmupgds.exe
2006-08-24 20:26 95288 --------- C:\WINDOWS\system32\WUDFCoinstaller.dll
2006-08-24 20:26 38656 --------- C:\WINDOWS\system32\drivers\wpdusb.sys
2006-08-24 20:26 17408 --------- C:\WINDOWS\system32\wpdshextautoplay.exe
2006-08-24 19:22 90112 --------- C:\WINDOWS\system32\drivers\WudfRd.sys
2006-08-24 19:19 316416 --------- C:\WINDOWS\system32\WUDFx.dll
2006-08-24 19:19 145920 --------- C:\WINDOWS\system32\WudfHost.exe
2006-08-24 19:18 84864 --------- C:\WINDOWS\system32\drivers\WudfPf.sys
2006-08-24 19:18 56320 --------- C:\WINDOWS\system32\WudfSvc.dll
2006-08-24 19:18 168448 --------- C:\WINDOWS\system32\WudfPlatform.dll
2006-08-22 17:17 -------- d-------- C:\Program Files\Java
2006-08-21 07:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 04:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-21 04:14 128896 --a------ C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-16 22:02 -------- d-------- C:\Program Files\Windows Media Components
2006-08-16 22:02 -------- d-------- C:\Program Files\directx
2006-08-16 22:02 -------- d-------- C:\Program Files\Cleaner 5 EZ
2006-08-16 22:01 -------- d-------- C:\Program Files\Adobe
2006-08-15 08:44 528427 --a------ C:\Program Files\setup.dat
2006-08-15 08:44 253383 --a------ C:\Program Files\avguss.hlp
2006-08-15 08:44 1417728 --a------ C:\Program Files\setup.exe
2006-08-12 21:08 -------- d-------- C:\Documents and Settings\The Shaolin!\Application Data\AdobeUM
2006-08-12 21:06 -------- d-------- C:\Program Files\GM SPO
2006-08-10 18:29 818176 --a------ C:\Program Files\avgctrl.dll
2006-08-10 18:29 79995 --a------ C:\Program Files\setupus.lns
2006-08-10 18:29 60416 --a------ C:\Program Files\avgscan.exe
2006-08-10 18:29 58368 --a------ C:\Program Files\avglng.dll
2006-08-10 18:29 487936 --a------ C:\Program Files\avgcfg.dll
2006-08-10 18:29 459264 --a------ C:\Program Files\avgtest.dll
2006-08-10 18:29 42628 --a------ C:\Program Files\dfncfg.dat
2006-08-10 18:29 404992 --a------ C:\Program Files\avgcckrn.dll
2006-08-10 18:29 3434 --a------ C:\Program Files\contact_us.txt
2006-08-10 18:29 342528 --a------ C:\Program Files\avgtmgr.dll
2006-08-10 18:29 338432 --a------ C:\Program Files\avgset.dll
2006-08-10 18:29 334848 --a------ C:\Program Files\avgemsui.dll
2006-08-10 18:29 29755 --a------ C:\Program Files\order_us.pdf
2006-08-10 18:29 281088 --a------ C:\Program Files\avgemc.exe
2006-08-10 18:29 199168 --a------ C:\Program Files\avgtres.dll
2006-08-10 18:29 185344 --a------ C:\Program Files\avginet.exe
2006-08-10 18:29 1757 --a------ C:\Program Files\order_us.txt
2006-08-10 18:29 140288 --a------ C:\Program Files\avgmail.dll
2006-08-10 18:29 126464 --a------ C:\Program Files\avgeud32.dll
2006-08-10 18:28 626176 --a------ C:\Program Files\avgupd.dll
2006-08-09 19:27 8590 --a------ C:\Documents and Settings\The Shaolin!\Application Data\AdobeDLM.log
2006-08-09 19:27 0 --a------ C:\Documents and Settings\The Shaolin!\Application Data\dm.ini
2006-07-27 08:24 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 03:24 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-14 14:51 108144 --a------ C:\WINDOWS\system32\GEARAspi.dll
2006-07-07 19:45 980 --a------ C:\Program Files\avguss.cnt
2006-07-07 19:45 9216 --a------ C:\Program Files\saslplain.dll
2006-07-07 19:45 9216 --a------ C:\Program Files\sasllogin.dll
2006-07-07 19:45 9216 --a------ C:\Program Files\avgupsvc.dll
2006-07-07 19:45 8464 --a------ C:\Program Files\sporder.dll
2006-07-07 19:45 84480 --a------ C:\Program Files\avgupsvc.exe
2006-07-07 19:45 813568 --a------ C:\Program Files\dbghelp.dll
2006-07-07 19:45 766 --a------ C:\Program Files\avgdos.ico
2006-07-07 19:45 68608 --a------ C:\Program Files\avgrep.dll
2006-07-07 19:45 67072 --a------ C:\Program Files\avgvault.dll
2006-07-07 19:45 5572 --a------ C:\Program Files\license_us.txt
2006-07-07 19:45 5312081 --a------ C:\Program Files\avi7.avg
2006-07-07 19:45 52736 --a------ C:\Program Files\avgoff2k.dll
2006-07-07 19:45 52224 --a------ C:\Program Files\avgklib.dll
2006-07-07 19:45 500736 --a------ C:\Program Files\avgres.dll
2006-07-07 19:45 49664 --a------ C:\Program Files\avg6cmpt.dll
2006-07-07 19:45 46080 --a------ C:\Program Files\libsasl.dll
2006-07-07 19:45 4608 --a------ C:\Program Files\dos2nt.dll
2006-07-07 19:45 40960 --a------ C:\Program Files\avgse.dll
2006-07-07 19:45 336896 --a------ C:\Program Files\avgamsvr.exe
2006-07-07 19:45 31314 --a------ C:\Program Files\register_us.pdf
2006-07-07 19:45 27648 --a------ C:\Program Files\sasldigestmd5.dll
2006-07-07 19:45 258560 --a------ C:\Program Files\avgamint.dll
2006-07-07 19:45 242 --a------ C:\Program Files\set_vers.cfg
2006-07-07 19:45 2112 --a------ C:\Program Files\register_us.txt
2006-07-07 19:45 19968 --a------ C:\Program Files\avgupdln.exe
2006-07-07 19:45 16384 --a------ C:\Program Files\avghlog.dll
2006-07-07 19:45 158 --a------ C:\Program Files\avg.snu
2006-07-07 19:45 1536 --a------ C:\Program Files\czech.dll
2006-07-07 19:45 15354 --a------ C:\Program Files\avg7dos.lng
2006-07-07 19:45 14336 --a------ C:\Program Files\avgf.dll
2006-07-07 19:45 138748 --a------ C:\Program Files\avgtitle.dat
2006-07-07 19:45 10806 --a------ C:\Program Files\avgemcps.dll
2006-07-07 19:45 10752 --a------ C:\Program Files\avgamsps.dll
2006-07-07 19:45 103936 --a------ C:\Program Files\avgbat.bav
2006-07-07 19:45 10240 --a------ C:\Program Files\saslcrammd5.dll
2006-07-07 19:45 100864 --a------ C:\Program Files\avglog.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"googletalk"="\"C:\\Program Files\\Google\\Google Talk\\googletalk.exe\" /autostart"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Steam"="\"g:\\steam\\steam.exe\" -silent"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime"
"MMTray"="\"G:\\ACE Mega CoDecS Pack\\SystemS\\Morgan Multimedia\\MMTray.exe\""
"mmtray2k"="\"G:\\ACE Mega CoDecS Pack\\SystemS\\Morgan Multimedia\\mmtray2k.exe\""
"mmtraylsi"="\"G:\\ACE Mega CoDecS Pack\\SystemS\\Morgan Multimedia\\mmtraylsi.exe\""
"AVG7_CC"="C:\\PROGRA~1\\avgcc.exe /STARTUP"
"BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"type32"="\"C:\\Program Files\\Microsoft IntelliType Pro\\type32.exe\""
"IntelliPoint"="\"C:\\Program Files\\Microsoft IntelliPoint\\point32.exe\""
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"SoundMan"="SOUNDMAN.EXE"
"RemoteControl"="G:\\PowerDVD6\\PDVDServ.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,40,01,00,00,00,00,00,00,00,05,00,00,b0,04,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,20,03,00,00,c5,01,00,00,6c,01,00,00,6c,01,\
00,00,01,00,00,00

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\\PROGRA~1\\avgw.exe /RUNONCE"

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\\PROGRA~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pm3nu
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winexz32

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Completion time: Wed 10/11/2006 15:38:20.14
ComboFix.txt


I will edit the post with the rest of the instructions when I complete them...should be within the next half hour. Thanks again!
 
#5 ·
AVG scan:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 4:45:52 PM 10/11/2006

+ Scan result:



G:\Old Computer C\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned.
C:\System Volume Information\_restore{83230FEF-DF8F-4DD5-9594-BCD5459F8831}\RP128\A0031633.dll -> Adware.Virtumonde : Cleaned.
C:\System Volume Information\_restore{83230FEF-DF8F-4DD5-9594-BCD5459F8831}\RP135\A0031960.dll -> Logger.VBStat.e : Cleaned.
C:\System Volume Information\_restore{83230FEF-DF8F-4DD5-9594-BCD5459F8831}\RP135\A0031961.dll -> Logger.VBStat.e : Cleaned.
C:\System Volume Information\_restore{83230FEF-DF8F-4DD5-9594-BCD5459F8831}\RP135\A0031962.dll -> Logger.VBStat.e : Cleaned.
:mozilla.336:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.336:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.562:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.563:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.105:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.105:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.11:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.11:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.13:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.13:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.14:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.14:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.15:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.15:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.16:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.16:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.17:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.17:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.18:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.18:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.21:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.21:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.21:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.23:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.24:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.24:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.24:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.25:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.25:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.25:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.26:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.26:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.26:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.27:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.27:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.27:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.284:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.28:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.28:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.28:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.29:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.29:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.29:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.30:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.31:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.32:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.34:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.35:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.36:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.37:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.38:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.39:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.40:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.41:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.42:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.595:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.595:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.608:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.206:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Admarketplace : Cleaned.
:mozilla.245:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Admarketplace : Cleaned.
:mozilla.245:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Admarketplace : Cleaned.
:mozilla.320:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adorigin : Cleaned.
:mozilla.321:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adorigin : Cleaned.
:mozilla.322:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adorigin : Cleaned.
:mozilla.323:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adorigin : Cleaned.
:mozilla.324:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adorigin : Cleaned.
:mozilla.325:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adorigin : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@adorigin[2].txt -> TrackingCookie.Adorigin : Cleaned.
:mozilla.176:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.176:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.177:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.177:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.178:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.178:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.179:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.179:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.180:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.180:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.181:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.181:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.185:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.186:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.187:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.188:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.189:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.190:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.217:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.233:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.320:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.320:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.362:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.363:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.368:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.439:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.439:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.440:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.440:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.446:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.446:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.582:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.599:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.633:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.370:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.371:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.372:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.373:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.490:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.490:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.491:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.491:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.318:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.318:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.319:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.319:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.858:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.859:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@adtrak[1].txt -> TrackingCookie.Adtrak : Cleaned.
:mozilla.103:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.104:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.105:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.106:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.107:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.108:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.109:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.110:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.111:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.112:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.113:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.114:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.115:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.116:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.117:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.118:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.119:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.120:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.121:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.122:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.123:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.124:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.125:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.126:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.127:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.128:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.129:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.130:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.131:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.132:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.133:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.134:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.135:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.136:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.137:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.138:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.139:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.140:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.141:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.142:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.143:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.144:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.193:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.193:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.194:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.194:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.195:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.195:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.196:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.196:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.197:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.197:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.198:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.198:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.51:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.54:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.85:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.85:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.86:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.86:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.87:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.87:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.88:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.88:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.89:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.89:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.90:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.90:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.91:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.91:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.92:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.92:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.203:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.203:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.701:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.702:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.657:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.657:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.397:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.398:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.55:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.55:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.56:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.56:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.11:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.81:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.81:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.16:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.68:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.68:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.6:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.73:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.73:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@burstnet[3].txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.397:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.397:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.398:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.398:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.399:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.399:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.400:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.400:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.401:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.401:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.402:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.402:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.57:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.58:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.59:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.60:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.61:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.62:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.519:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Centrport : Cleaned.
:mozilla.522:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Centrport : Cleaned.
:mozilla.302:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
:mozilla.302:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@ad1.clickhype[1].txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.552:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.552:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.553:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.553:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.590:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.590:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.591:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.591:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.874:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.875:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Com : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@com[2].txt -> TrackingCookie.Com : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Local Settings\Temp\Cookies\the shaolin!@com[2].txt -> TrackingCookie.Com : Cleaned.
:mozilla.855:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.396:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Counted : Cleaned.
:mozilla.396:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Counted : Cleaned.
:mozilla.12:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.30:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.30:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.679:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@c.enhance[1].txt -> TrackingCookie.Enhance : Cleaned.
:mozilla.167:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.204:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.204:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.205:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.205:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.206:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.206:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.207:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.207:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.212:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.212:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.268:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.268:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.330:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.330:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.334:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.334:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.344:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.344:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.345:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.345:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.346:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.346:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.348:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.348:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.349:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.349:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.350:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.350:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.351:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.351:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.352:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.352:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.353:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.353:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.366:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.366:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.367:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.367:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.368:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.368:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.395:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.449:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.449:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.456:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.456:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.485:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.485:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.486:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.486:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.487:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.487:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.568:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.568:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.592:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.593:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.621:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.621:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.685:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.685:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.734:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.756:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.761:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.770:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.771:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.780:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.781:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.782:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.783:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.784:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.785:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.786:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.787:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.810:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.815:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.816:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.817:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.840:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.866:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.867:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.868:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.869:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.880:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.881:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@e-2dj6wfk4kidpwdp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@e-2dj6wfkiwncjmhp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@e-2dj6wfkococ5cbq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@e-2dj6wfkouldpmeq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@e-2dj6wflokid5maq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@e-2dj6wjkocidzwho.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@e-2dj6wjkygoczabq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@e-2dj6wjkyoocpwkp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@e-2dj6wjl4gjdzado.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@e-2dj6wjloklcpkco.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@e-2dj6wjmiamazago.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@e-2dj6wjmigkcjofp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@e-2dj6wjnyuodzckp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@ads.euniverseads[1].txt -> TrackingCookie.Euniverseads : Cleaned.
:mozilla.38:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.38:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.39:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Falkag : Cleaned.
 
#6 ·
page 2 0.0

:mozilla.39:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.40:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.40:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.41:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.41:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.42:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.42:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.45:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.45:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.46:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.46:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.535:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.75:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.76:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.77:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.78:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.79:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.80:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.81:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.262:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.262:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.265:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.265:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.266:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.266:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.267:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.267:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.52:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.53:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.498:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.498:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.534:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.534:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.691:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.691:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.788:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.291:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.292:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.300:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.300:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.301:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.301:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.314:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.314:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.352:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.357:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.357:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.358:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.358:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.359:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.359:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.360:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.360:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.385:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.387:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.406:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.411:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.411:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.412:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.412:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.428:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.429:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.431:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.432:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.433:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.434:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.435:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.436:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.444:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.469:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.469:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.470:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.471:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.47:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.47:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.494:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.494:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.499:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.49:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.49:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.500:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.509:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.509:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.50:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.50:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.51:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.51:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.534:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.536:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.691:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.813:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.838:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.230:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.230:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.231:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.231:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.232:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.232:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.233:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.233:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.326:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.327:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.328:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.329:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@hypertracker[1].txt -> TrackingCookie.Hypertracker : Cleaned.
:mozilla.297:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Itrack : Cleaned.
:mozilla.298:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Itrack : Cleaned.
:mozilla.299:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Itrack : Cleaned.
:mozilla.300:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Itrack : Cleaned.
:mozilla.384:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Linksynergy : Cleaned.
:mozilla.384:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned.
:mozilla.385:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Linksynergy : Cleaned.
:mozilla.385:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned.
:mozilla.158:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.159:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.569:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.569:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.572:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.572:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.573:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.573:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.595:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.596:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.628:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.628:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.629:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.629:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.630:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.630:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.772:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.775:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.856:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@sales.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Local Settings\Temp\Cookies\the shaolin!@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.404:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.405:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.43:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.43:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.44:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.44:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.221:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.221:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.724:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.173:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.174:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.175:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.176:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.259:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.259:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.260:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.260:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.261:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.261:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.182:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.182:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.183:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.183:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.184:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.184:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.185:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.185:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@paypopup[2].txt -> TrackingCookie.Paypopup : Cleaned.
:mozilla.354:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.355:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.356:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.357:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.441:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.441:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.442:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.442:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.443:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.443:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.444:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.444:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.445:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.445:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.172:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.172:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.173:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.173:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.73:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.94:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.94:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.461:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.462:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.463:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.643:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.643:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.399:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.400:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.401:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.402:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.403:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.74:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.74:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.75:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.75:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.76:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.76:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.77:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.77:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.78:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.78:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.79:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.79:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.132:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.132:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.133:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.133:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.134:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.134:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.135:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.135:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.178:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.179:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.180:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.183:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.184:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.676:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.676:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.420:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.421:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.594:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.594:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.413:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.413:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.414:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.414:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.415:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.415:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.416:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.416:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.417:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.417:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.722:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.723:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.538:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Spylog : Cleaned.
:mozilla.538:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Spylog : Cleaned.
:mozilla.740:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Spylog : Cleaned.
:mozilla.239:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.239:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.240:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.240:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.241:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.241:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.242:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.242:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.243:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.243:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.89:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.90:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.91:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.92:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.93:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.94:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.95:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.96:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.97:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.98:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.10:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.17:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.18:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.67:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.67:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.69:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.69:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.70:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.70:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.71:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.71:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.72:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.72:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.8:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.9:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.497:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.497:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.503:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.684:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.684:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.191:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.192:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.193:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.194:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.195:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.430:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.430:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.431:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.431:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.432:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.432:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.433:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.433:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.434:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.434:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.158:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.158:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.159:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.159:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.160:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.160:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.161:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.161:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.162:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.162:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.163:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.163:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.164:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.164:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.49:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.50:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.55:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.56:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.214:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.215:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.521:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.521:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.522:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.522:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.622:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Vortexmediagroup : Cleaned.
:mozilla.622:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Vortexmediagroup : Cleaned.
:mozilla.388:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.388:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.407:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.658:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.658:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.659:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.659:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.662:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.662:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@yadro[1].txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.196:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.197:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.198:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.199:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.200:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.201:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.202:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.203:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.204:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.322:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.322:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.324:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.324:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.325:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.325:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@ad.yieldmanager[3].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.54:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.54:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.57:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.57:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.588:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.589:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.58:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.58:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.590:G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.59:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.59:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.60:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.60:G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\System Volume Information\_restore{83230FEF-DF8F-4DD5-9594-BCD5459F8831}\RP133\A0031778.dll -> Trojan.BHO.g : Cleaned.


::Report end

The following two reports will be posted when they are completed.
 
#7 ·
Incident Status Location

Potentially unwanted tool:application/winfixer2005 Not disinfected c:\windows\downloaded program files\UWA6P_0001_N91M1807NetInstaller.exe
Spyware:Cookie/Peel Not disinfected C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\i95eohsz\cookies.txt[.peel.com/]
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Documents and Settings\The Shaolin!\Local Settings\Temporary Internet Files\Content.IE5\9SKL45FY\WinAntiVirusPro2006FreeInstall[1].cab[UWA6P_0001_N91M1807NetInstaller.exe]
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWA6P_0001_N91M1807NetInstaller.exe
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UWA6P_0001_N91M1807NetInstaller.exe
Spyware:Cookie/Peel Not disinfected G:\Firefox backup\Profiles\i95eohsz.default\cookies.txt[.peel.com/]
Spyware:Cookie/GoStats Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt[.gostats.com/]
Spyware:Cookie/Go Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt[.go.com/]
Spyware:Cookie/Tickle Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt[.tickle.com/]
Spyware:Cookie/Maxserving Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Application Data\Mozilla\Firefox\Profiles\eg6jf5f0.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/64.62.232 Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@64.62.232[2].txt
Spyware:Cookie/64.62.232 Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@64.62.232[4].txt
Spyware:Cookie/Atwola Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@atwola[1].txt
Spyware:Cookie/Atwola Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@atwola[2].txt
Spyware:Cookie/Atwola Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@atwola[3].txt
Spyware:Cookie/Banner Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@banner[1].txt
Spyware:Cookie/Banner Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@banner[2].txt
Spyware:Cookie/GoStats Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@c2.gostats[2].txt
Spyware:Cookie/Belnk Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@dist.belnk[2].txt
Spyware:Cookie/GoStats Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@gostats[2].txt
Spyware:Cookie/Go Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@go[1].txt
Spyware:Cookie/Go Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@go[2].txt
Spyware:Cookie/Kount Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@kount[1].txt
Spyware:Cookie/Rightmedia Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@rightmedia[2].txt
Spyware:Cookie/Xiti Not disinfected G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies\the shaolin!@xiti[1].txt
 
#8 ·
Logfile of HijackThis v1.99.1
Scan saved at 9:23:21 PM, on 10/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\avgamsvr.exe
C:\PROGRA~1\avgupsvc.exe
C:\PROGRA~1\avgemc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\GM SPO\eSI\Apache Group\Tomcat 4.1\bin\tomcat.exe
C:\Program Files\GM SPO\eSI\Transbase\tbmux32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\GM SPO\eSI\Transbase\tbkern32.exe
C:\Program Files\GM SPO\eSI\Transbase\tbkern32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\MMTray.exe
G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtray2k.exe
G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtraylsi.exe
C:\PROGRA~1\avgcc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
G:\PowerDVD6\PDVDServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Messenger\msmsgs.exe
G:\steam\steam.exe
E:\Wlan\WLANPRO.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\HJT\Nathan.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {05820D08-29E9-44EF-A0C7-5D2DD9A68152} - C:\WINDOWS\system32\awvvw.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6297DA1E-3435-4D6B-8F14-D6D0F2512C63} - C:\WINDOWS\msagent\pm3nu.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {849B9523-785F-4014-9CAF-079FB4A74C61} - C:\WINDOWS\system32\amgqtsrf.dll (file missing)
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [MMTray] "G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\MMTray.exe"
O4 - HKLM\..\Run: [mmtray2k] "G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtray2k.exe"
O4 - HKLM\..\Run: [mmtraylsi] "G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtraylsi.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] G:\PowerDVD6\PDVDServ.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "g:\steam\steam.exe" -silent
O4 - Global Startup: 108Mbps Wireless LAN Adapter Configuration Utility.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Reg.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4866/mcfscan.cab
O20 - Winlogon Notify: pm3nu - C:\WINDOWS\msagent\pm3nu.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winexz32 - winexz32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SI Tomcat (SITomcat) - Alexandria Software Consulting - C:\Program Files\GM SPO\eSI\Apache Group\Tomcat 4.1\bin\tomcat.exe
O23 - Service: SI Transbase (SITransbase) - TransAction Software, D 81737 Munich - C:\Program Files\GM SPO\eSI\Transbase\tbmux32.exe



Okay, that should do it. Please advise me on how to procede next :)

Everything still seems to be running a bit sluggish...this is a 4200+ AMD x2 processor, so I'm a little dissappointed :)

Thanks again!
 
#9 · (Edited)
Hello Shaolin.
I am on your logs and I'll be bck with comments ASAP. Though I would like to advise you not to connect to internet during the Fix unless you are specifically instructed to do so [eg in case of online scans]. Do not break the order of the fix- follow the instructions in the exact given order. There is no need to post one of the logs I've asked for, earlier than others because I need to see all your logs togethere to come to a conclusion regarding your sytem. Now connecting to the net while your fix is not yet completed, simply makes you more vulnerable to further infections and we may have to start everything from the begining.
Hope I could make you understand my points.

Help us to help you better :smile:.
 
#12 ·
Hello The Shaolin :smile:.

Please follow the next set of instructions very carefully and in the exact given order.

Disable Security Softwares

Double-click the icon on Desktop to launch Ewido. Please disable your AVG Anti-Spyware Guard, as it may hinder the removal of some entries. On the top of the main screen click Shield. Click the word active to change it to inactive

Fix



I hope you still have ComboFix on your machine. If not, please download combofix again from one of these locations:**Save it to your desktop**

Go to <<Start>> then <<Run>> then paste in the single line command shown in the following 'code' box and then click OK

Code:
[color=red][b]"%userprofile%\desktop\combofix.exe" /v pm3nu[/b][/color]
When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

Open Firefox. Go to Tools>Option>Privacy>Cookies. Click on the radio button marked as "Clear Cookies Now".

Reboot your system in Safe Mode (By repeatedly tapping the F8 key until the menu appears).

Open HijackThis and click on 'Do a System Scan Only'. Check the following entries (If they still exist, make sure you do not miss any)

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName
O2 - BHO: (no name) - {05820D08-29E9-44EF-A0C7-5D2DD9A68152} - C:\WINDOWS\system32\awvvw.dll (file missing)
O2 - BHO: (no name) - {6297DA1E-3435-4D6B-8F14-D6D0F2512C63} - C:\WINDOWS\msagent\pm3nu.dll
O2 - BHO: (no name) - {849B9523-785F-4014-9CAF-079FB4A74C61} - C:\WINDOWS\system32\amgqtsrf.dll (file missing)
O20 - Winlogon Notify: pm3nu - C:\WINDOWS\msagent\pm3nu.dll
O20 - Winlogon Notify: winexz32 - winexz32.dll (file missing)


Please remember to close all other windows, including browsers then click Fix checked.

Delete the following Files indicated in RED if they still exist.

c:\windows\downloaded program files\UWA6P_0001_N91M1807NetInstaller.exe
C:\Documents and Settings\The Shaolin!\Local Settings\Temporary Internet Files\Content.IE5\9SKL45FY\WinAntiVirusPro2006FreeInstall[1].cab
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWA6P_0001_N91M1807NetInstaller.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UWA6P_0001_N91M1807NetInstaller.exe
C:\WINDOWS\system32\jjrwmnva.dll
C:\WINDOWS\system32\xmkwanqc.dll
C:\WINDOWS\system32\vfcwqrbr.dll
C:\WINDOWS\system32\eyubgyev.exe


G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies
G:\Old Computer C\Documents and Settings\the Shaolin!\Cookies
<< Delete everything inside these "Cookies" folder at both the locations, no need to delete the folders.

Reboot your system in Normal Mode.
________________________________________________________________

Online Scan

Perform an online scan with Internet Explorer with

Kaspersky WebScanner

Next Click on Launch Kaspersky Anti-Virus Web Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives[*]Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
______________________________________________________________

Now you need to protect yourself from cookies [which you have a plenty on your system]. Please follow and implement the next set of instructions carefully:

Download IE-Spyad - Extract the contents to a new folder. IE-SPYAD will place thousands of bad websites in the Restricted Zone of Internet Explorer.
From within the folder, double-click install.bat
Select Option #2 - Install the new IE-SPYAD list.
Then return to the main menu.
Select option #4 - Add the old porn sites domain

Download MVPS Hosts file - From within Host.zip, double click on MVPS.bat & allow it to run. This will replace your current Hosts file with one that will block known adware and spy websites.

Download SpywareBlaster. Install & update SpywareBlaster with the latest definitions.
After you have updated, click the button - enable protection for all unprotected items.
SpywareBlaster can help prevent spyware installing in the first place.


Please provide the following logs with your next post:

ComboFix.txt
Kaspersky Scan
HijackThis (A fresh one)


Please let me know about your systems overall behaviour :smile:.
 
#13 ·
The Shaolin! - 06-10-16 13:21:39.76 Service Pack 2
ComboFix 06.10.11 - Running from: "C:\Documents and Settings\The Shaolin!\Desktop"
Command switches used :: /v pm3nu

((((((((((((((((((((((((((((((( Files Created from 2006-09-16 to 2006-10-16 ))))))))))))))))))))))))))))))))))


2006-10-11 15:35 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-09-24 16:32 <DIR> d-------- C:\WINDOWS\McAfee.com
2006-09-19 15:59 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2006-09-19 15:54 223,128 --a------ C:\WINDOWS\system32\drivers\dtscsi.sys
2006-09-19 15:41 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll
2006-09-19 15:41 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll
2006-09-19 15:41 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-10-16 13:17 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-15 17:38 -------- d-------- C:\Documents and Settings\The Shaolin!\Application Data\.gaim
2006-10-15 08:43 4571048 --a------ C:\Program Files\incavi.avm
2006-10-15 08:43 254 --a------ C:\Program Files\upd_vers.cfg
2006-10-14 08:43 22719 --a------ C:\Program Files\microavi.avg
2006-10-12 18:15 -------- d-------- C:\Program Files\Picasa2
2006-10-11 17:11 -------- d-------- C:\Program Files\QuickTime
2006-10-11 17:09 -------- d-------- C:\Program Files\Microsoft IntelliType Pro
2006-10-11 17:09 -------- d-------- C:\Program Files\Microsoft IntelliPoint
2006-10-11 17:09 -------- d-------- C:\Program Files\Messenger
2006-10-11 17:08 -------- d-------- C:\Program Files\iTunes
2006-10-11 17:08 -------- d-------- C:\Program Files\Internet Explorer
2006-10-11 17:08 -------- d-------- C:\Program Files\DAEMON Tools
2006-10-11 16:00 -------- d-------- C:\Program Files\CleanUp!
2006-10-11 15:35 -------- d-------- C:\Program Files\Grisoft
2006-10-10 08:43 298684 --a------ C:\Program Files\avg7us.lng
2006-10-07 20:28 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-10-05 15:34 458535 --a------ C:\Program Files\miniavi.avg
2006-09-28 15:26 -------- d-------- C:\Program Files\CCleaner
2006-09-28 08:43 93696 --a------ C:\Program Files\avginet.dll
2006-09-28 08:43 778656 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-09-28 08:43 729835 --a------ C:\Program Files\avg.exe
2006-09-28 08:43 501760 --a------ C:\Program Files\avgcore.dll
2006-09-28 08:43 369664 --a------ C:\Program Files\avgcc.exe
2006-09-28 08:43 310784 --a------ C:\Program Files\avgabout.dll
2006-09-28 08:43 302592 --a------ C:\Program Files\avgvv.exe
2006-09-28 08:43 289280 --a------ C:\Program Files\avgscan.dll
2006-09-28 08:43 231424 --a------ C:\Program Files\avgwb.dat
2006-09-28 08:43 192000 --a------ C:\Program Files\avgunarc.dll
2006-09-28 08:43 155136 --a------ C:\Program Files\avgw.exe
2006-09-26 00:08 -------- d-------- C:\Program Files\KC Softwares
2006-09-24 16:32 -------- d-------- C:\Program Files\iPod
2006-09-20 01:14 -------- d---s---- C:\Documents and Settings\The Shaolin!\Application Data\Microsoft
2006-09-19 20:59 -------- d-------- C:\Program Files\Common Files
2006-09-19 15:58 -------- d-------- C:\Program Files\Microsoft ActiveSync
2006-09-19 15:58 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-09-19 15:57 -------- d-------- C:\Program Files\Microsoft Office
2006-09-19 15:56 -------- d-------- C:\Program Files\Microsoft.NET
2006-09-19 15:56 -------- d-------- C:\Program Files\Common Files\System
2006-09-19 15:56 -------- d-------- C:\Program Files\Common Files\DESIGNER
2006-09-19 15:49 643072 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2006-09-19 15:38 -------- d-------- C:\Program Files\RedLightCenter
2006-09-11 15:33 -------- d-------- C:\Program Files\myTunes Redux
2006-09-04 17:06 -------- d-------- C:\Program Files\WS_FTP
2006-09-03 16:34 -------- d-------- C:\Program Files\Windows Media Player
2006-09-03 16:34 -------- d-------- C:\Program Files\Windows Media Connect 2
2006-08-31 00:11 -------- d-------- C:\Program Files\Futuremark
2006-08-30 21:55 -------- d-------- C:\Program Files\Outlook Express
2006-08-30 17:53 -------- d-------- C:\Documents and Settings\The Shaolin!\Application Data\Adobe
2006-08-26 22:01 -------- d-------- C:\Program Files\Sonic Foundry
2006-08-26 22:01 -------- d-------- C:\Program Files\Pure Motion
2006-08-26 22:01 -------- d-------- C:\Program Files\DebugMode
2006-08-24 22:42 8704 --------- C:\WINDOWS\system32\wdfmgr.exe
2006-08-24 22:42 8704 --------- C:\WINDOWS\system32\uwdf.exe
2006-08-24 22:30 99840 --a------ C:\WINDOWS\system32\wmpshell.dll
2006-08-24 22:30 990208 --a------ C:\WINDOWS\system32\drmv2clt.dll
2006-08-24 22:30 937984 --a------ C:\WINDOWS\system32\WMNetMgr.dll
2006-08-24 22:30 8337920 --a------ C:\WINDOWS\system32\wmploc.dll
2006-08-24 22:30 790016 --------- C:\WINDOWS\system32\WMVSENCD.dll
2006-08-24 22:30 757248 --a------ C:\WINDOWS\system32\WMADMOD.dll
2006-08-24 22:30 7168 --a------ C:\WINDOWS\system32\asferror.dll
2006-08-24 22:30 656896 --------- C:\WINDOWS\system32\WMVXENCD.dll
2006-08-24 22:30 63488 --------- C:\WINDOWS\system32\wpdmtpus.dll
2006-08-24 22:30 629760 --------- C:\WINDOWS\system32\wpd_ci.dll
2006-08-24 22:30 611840 --------- C:\WINDOWS\system32\wmpmde.dll
2006-08-24 22:30 603648 --a------ C:\WINDOWS\system32\WMSPDMOD.dll
2006-08-24 22:30 537600 --a------ C:\WINDOWS\system32\blackbox.dll
2006-08-24 22:30 532992 --------- C:\WINDOWS\system32\wmdrmsdk.dll
2006-08-24 22:30 428032 --------- C:\WINDOWS\system32\wmdrmdev.dll
2006-08-24 22:30 414208 --a------ C:\WINDOWS\system32\msscp.dll
2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\wmvdmoe2.dll
2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\wmvdmod.dll
2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\wmsdmoe2.dll
2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\wmsdmod.dll
2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\MPG4DMOD.dll
2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\MP4SDMOD.dll
2006-08-24 22:30 4096 --a------ C:\WINDOWS\system32\MP43DMOD.dll
2006-08-24 22:30 4096 --------- C:\WINDOWS\system32\WMVADVE.DLL
2006-08-24 22:30 4096 --------- C:\WINDOWS\system32\WMVADVD.dll
2006-08-24 22:30 4096 --------- C:\WINDOWS\system32\wdfapi.dll
2006-08-24 22:30 37376 --a------ C:\WINDOWS\system32\wmdmps.dll
2006-08-24 22:30 35840 --------- C:\WINDOWS\system32\wpdconns.dll
2006-08-24 22:30 349184 --------- C:\WINDOWS\system32\wpdsp.dll
2006-08-24 22:30 347648 --------- C:\WINDOWS\system32\wmdrmnet.dll
2006-08-24 22:30 33792 --a------ C:\WINDOWS\system32\wmdmlog.dll
2006-08-24 22:30 320512 --a------ C:\WINDOWS\system32\mswmdm.dll
2006-08-24 22:30 316928 --------- C:\WINDOWS\system32\MP4SDECD.dll
2006-08-24 22:30 314368 --a------ C:\WINDOWS\system32\wmpdxm.dll
2006-08-24 22:30 305152 --------- C:\WINDOWS\system32\MSDelta.dll
2006-08-24 22:30 295424 --------- C:\WINDOWS\system32\wmpeffects.dll
2006-08-24 22:30 284160 --------- C:\WINDOWS\system32\PortableDeviceApi.dll
2006-08-24 22:30 276480 --------- C:\WINDOWS\system32\audiodev.dll
2006-08-24 22:30 27648 --a------ C:\WINDOWS\system32\mspmsnsv.dll
2006-08-24 22:30 259072 --------- C:\WINDOWS\system32\MPG4DECD.dll
2006-08-24 22:30 2589184 --------- C:\WINDOWS\system32\WpdShext.dll
2006-08-24 22:30 258560 --------- C:\WINDOWS\system32\MP43DECD.dll
2006-08-24 22:30 2450944 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-08-24 22:30 242176 --a------ C:\WINDOWS\system32\wmpasf.dll
2006-08-24 22:30 228352 --a------ C:\WINDOWS\system32\cewmdm.dll
2006-08-24 22:30 227328 --a------ C:\WINDOWS\system32\wmerror.dll
2006-08-24 22:30 222208 --a------ C:\WINDOWS\system32\WMASF.dll
2006-08-24 22:30 211968 --------- C:\WINDOWS\system32\MFPLAT.dll
2006-08-24 22:30 210432 --a------ C:\WINDOWS\system32\qasf.dll
2006-08-24 22:30 204800 --------- C:\WINDOWS\system32\wmpsrcwp.dll
2006-08-24 22:30 198144 --------- C:\WINDOWS\system32\PortableDeviceWMDRM.dll
2006-08-24 22:30 179712 --a------ C:\WINDOWS\system32\msnetobj.dll
2006-08-24 22:30 175104 --a------ C:\WINDOWS\system32\mspmsp.dll
2006-08-24 22:30 166912 --------- C:\WINDOWS\system32\PortableDeviceTypes.dll
2006-08-24 22:30 1660416 --------- C:\WINDOWS\system32\wmpencen.dll
2006-08-24 22:30 157184 --a------ C:\WINDOWS\system32\wmidx.dll
2006-08-24 22:30 154624 --------- C:\WINDOWS\system32\wpdmtp.dll
2006-08-24 22:30 1539584 --------- C:\WINDOWS\system32\WMVDECOD.dll
2006-08-24 22:30 1532416 --------- C:\WINDOWS\system32\WMVENCOD.dll
2006-08-24 22:30 1392128 --------- C:\WINDOWS\system32\WMVSDECD.dll
2006-08-24 22:30 133120 --------- C:\WINDOWS\system32\WPDShServiceObj.dll
2006-08-24 22:30 1327616 --a------ C:\WINDOWS\system32\WMSPDMOE.dll
2006-08-24 22:30 132096 --------- C:\WINDOWS\system32\PortableDeviceWiaCompat.dll
2006-08-24 22:30 130048 --------- C:\WINDOWS\system32\wmpps.dll
2006-08-24 22:30 11264 --a------ C:\WINDOWS\system32\LAPRXY.dll
2006-08-24 22:30 1118208 --a------ C:\WINDOWS\system32\WMADMOE.dll
2006-08-24 22:30 101888 --------- C:\WINDOWS\system32\PortableDeviceClassExtension.dll
2006-08-24 20:31 100864 --a------ C:\WINDOWS\system32\logagent.exe
2006-08-24 20:27 249344 --------- C:\WINDOWS\system32\drmupgds.exe
2006-08-24 20:26 95288 --------- C:\WINDOWS\system32\WUDFCoinstaller.dll
2006-08-24 20:26 38656 --------- C:\WINDOWS\system32\drivers\wpdusb.sys
2006-08-24 20:26 17408 --------- C:\WINDOWS\system32\wpdshextautoplay.exe
2006-08-24 19:22 90112 --------- C:\WINDOWS\system32\drivers\WudfRd.sys
2006-08-24 19:19 316416 --------- C:\WINDOWS\system32\WUDFx.dll
2006-08-24 19:19 145920 --------- C:\WINDOWS\system32\WudfHost.exe
2006-08-24 19:18 84864 --------- C:\WINDOWS\system32\drivers\WudfPf.sys
2006-08-24 19:18 56320 --------- C:\WINDOWS\system32\WudfSvc.dll
2006-08-24 19:18 168448 --------- C:\WINDOWS\system32\WudfPlatform.dll
2006-08-22 17:17 -------- d-------- C:\Program Files\Java
2006-08-21 07:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 04:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-21 04:14 128896 --a------ C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-16 22:02 -------- d-------- C:\Program Files\Windows Media Components
2006-08-16 22:02 -------- d-------- C:\Program Files\directx
2006-08-16 22:02 -------- d-------- C:\Program Files\Cleaner 5 EZ
2006-08-16 22:01 -------- d-------- C:\Program Files\Adobe
2006-08-15 08:44 528427 --a------ C:\Program Files\setup.dat
2006-08-15 08:44 253383 --a------ C:\Program Files\avguss.hlp
2006-08-15 08:44 1417728 --a------ C:\Program Files\setup.exe
2006-08-10 18:29 818176 --a------ C:\Program Files\avgctrl.dll
2006-08-10 18:29 79995 --a------ C:\Program Files\setupus.lns
2006-08-10 18:29 60416 --a------ C:\Program Files\avgscan.exe
2006-08-10 18:29 58368 --a------ C:\Program Files\avglng.dll
2006-08-10 18:29 487936 --a------ C:\Program Files\avgcfg.dll
2006-08-10 18:29 459264 --a------ C:\Program Files\avgtest.dll
2006-08-10 18:29 42628 --a------ C:\Program Files\dfncfg.dat
2006-08-10 18:29 404992 --a------ C:\Program Files\avgcckrn.dll
2006-08-10 18:29 3434 --a------ C:\Program Files\contact_us.txt
2006-08-10 18:29 342528 --a------ C:\Program Files\avgtmgr.dll
2006-08-10 18:29 338432 --a------ C:\Program Files\avgset.dll
2006-08-10 18:29 334848 --a------ C:\Program Files\avgemsui.dll
2006-08-10 18:29 29755 --a------ C:\Program Files\order_us.pdf
2006-08-10 18:29 281088 --a------ C:\Program Files\avgemc.exe
2006-08-10 18:29 199168 --a------ C:\Program Files\avgtres.dll
2006-08-10 18:29 185344 --a------ C:\Program Files\avginet.exe
2006-08-10 18:29 1757 --a------ C:\Program Files\order_us.txt
2006-08-10 18:29 140288 --a------ C:\Program Files\avgmail.dll
2006-08-10 18:29 126464 --a------ C:\Program Files\avgeud32.dll
2006-08-10 18:28 626176 --a------ C:\Program Files\avgupd.dll
2006-08-09 19:27 8590 --a------ C:\Documents and Settings\The Shaolin!\Application Data\AdobeDLM.log
2006-08-09 19:27 0 --a------ C:\Documents and Settings\The Shaolin!\Application Data\dm.ini
2006-07-27 08:24 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 03:24 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-07 19:45 980 --a------ C:\Program Files\avguss.cnt
2006-07-07 19:45 9216 --a------ C:\Program Files\saslplain.dll
2006-07-07 19:45 9216 --a------ C:\Program Files\sasllogin.dll
2006-07-07 19:45 9216 --a------ C:\Program Files\avgupsvc.dll
2006-07-07 19:45 8464 --a------ C:\Program Files\sporder.dll
2006-07-07 19:45 84480 --a------ C:\Program Files\avgupsvc.exe
2006-07-07 19:45 813568 --a------ C:\Program Files\dbghelp.dll
2006-07-07 19:45 766 --a------ C:\Program Files\avgdos.ico
2006-07-07 19:45 68608 --a------ C:\Program Files\avgrep.dll
2006-07-07 19:45 67072 --a------ C:\Program Files\avgvault.dll
2006-07-07 19:45 5572 --a------ C:\Program Files\license_us.txt
2006-07-07 19:45 5312081 --a------ C:\Program Files\avi7.avg
2006-07-07 19:45 52736 --a------ C:\Program Files\avgoff2k.dll
2006-07-07 19:45 52224 --a------ C:\Program Files\avgklib.dll
2006-07-07 19:45 500736 --a------ C:\Program Files\avgres.dll
2006-07-07 19:45 49664 --a------ C:\Program Files\avg6cmpt.dll
2006-07-07 19:45 46080 --a------ C:\Program Files\libsasl.dll
2006-07-07 19:45 4608 --a------ C:\Program Files\dos2nt.dll
2006-07-07 19:45 40960 --a------ C:\Program Files\avgse.dll
2006-07-07 19:45 336896 --a------ C:\Program Files\avgamsvr.exe
2006-07-07 19:45 31314 --a------ C:\Program Files\register_us.pdf
2006-07-07 19:45 27648 --a------ C:\Program Files\sasldigestmd5.dll
2006-07-07 19:45 258560 --a------ C:\Program Files\avgamint.dll
2006-07-07 19:45 242 --a------ C:\Program Files\set_vers.cfg
2006-07-07 19:45 2112 --a------ C:\Program Files\register_us.txt
2006-07-07 19:45 19968 --a------ C:\Program Files\avgupdln.exe
2006-07-07 19:45 16384 --a------ C:\Program Files\avghlog.dll
2006-07-07 19:45 158 --a------ C:\Program Files\avg.snu
2006-07-07 19:45 1536 --a------ C:\Program Files\czech.dll
2006-07-07 19:45 15354 --a------ C:\Program Files\avg7dos.lng
2006-07-07 19:45 14336 --a------ C:\Program Files\avgf.dll
2006-07-07 19:45 138748 --a------ C:\Program Files\avgtitle.dat
2006-07-07 19:45 10806 --a------ C:\Program Files\avgemcps.dll
2006-07-07 19:45 10752 --a------ C:\Program Files\avgamsps.dll
2006-07-07 19:45 103936 --a------ C:\Program Files\avgbat.bav
2006-07-07 19:45 10240 --a------ C:\Program Files\saslcrammd5.dll
2006-07-07 19:45 100864 --a------ C:\Program Files\avglog.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"googletalk"="\"C:\\Program Files\\Google\\Google Talk\\googletalk.exe\" /autostart"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Steam"="\"g:\\steam\\steam.exe\" -silent"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime"
"MMTray"="\"G:\\ACE Mega CoDecS Pack\\SystemS\\Morgan Multimedia\\MMTray.exe\""
"mmtray2k"="\"G:\\ACE Mega CoDecS Pack\\SystemS\\Morgan Multimedia\\mmtray2k.exe\""
"mmtraylsi"="\"G:\\ACE Mega CoDecS Pack\\SystemS\\Morgan Multimedia\\mmtraylsi.exe\""
"AVG7_CC"="C:\\PROGRA~1\\avgcc.exe /STARTUP"
"BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"type32"="\"C:\\Program Files\\Microsoft IntelliType Pro\\type32.exe\""
"IntelliPoint"="\"C:\\Program Files\\Microsoft IntelliPoint\\point32.exe\""
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"SoundMan"="SOUNDMAN.EXE"
"RemoteControl"="G:\\PowerDVD6\\PDVDServ.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,40,01,00,00,00,00,00,00,00,05,00,00,b0,04,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,20,03,00,00,c5,01,00,00,6c,01,00,00,6c,01,\
00,00,01,00,00,00

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\\PROGRA~1\\avgw.exe /RUNONCE"

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\\PROGRA~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pm3nu
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winexz32

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Completion time: Mon 10/16/2006 13:22:04.75
ComboFix.txt
ComboFix2.txt
 
#14 · (Edited)
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, October 16, 2006 4:25:09 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 16/10/2006
Kaspersky Anti-Virus database records: 232288
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan Statistics:
Total number of scanned objects: 192585
Number of viruses found: 2
Number of infected objects: 3 / 0
Number of suspicious objects: 0
Duration of the scan process: 02:24:16

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\The Shaolin!\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\The Shaolin!\Local Settings\Application Data\ApplicationHistory\cli.exe.c88dbd71.ini.inuse Object is locked skipped
C:\Documents and Settings\The Shaolin!\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\The Shaolin!\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\The Shaolin!\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\The Shaolin!\Local Settings\Temp\Perflib_Perfdata_b6c.dat Object is locked skipped
C:\Documents and Settings\The Shaolin!\Local Settings\Temp\Perflib_Perfdata_c3c.dat Object is locked skipped
C:\Documents and Settings\The Shaolin!\Local Settings\Temp\Perflib_Perfdata_d54.dat Object is locked skipped
C:\Documents and Settings\The Shaolin!\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\The Shaolin!\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\The Shaolin!\ntuser.dat.LOG Object is locked skipped
C:\Program Files\GM SPO\eSI\Apache Group\Tomcat 4.1\logs\localhost_log.2006-10-16.txt Object is locked skipped
C:\Program Files\GM SPO\eSI\Apache Group\Tomcat 4.1\logs\stderr.log Object is locked skipped
C:\Program Files\GM SPO\eSI\Apache Group\Tomcat 4.1\logs\stdout.log Object is locked skipped
C:\Program Files\GM SPO\eSI\Apache Group\Tomcat 4.1\webapps\ROOT\common\SA\logs\referral.R2.log Object is locked skipped
C:\Program Files\GM SPO\eSI\Apache Group\Tomcat 4.1\webapps\ROOT\common\SA\logs\SIenPool.log Object is locked skipped
C:\Program Files\GM SPO\eSI\SIROM\SIen\DB\disks\tbdsk001 Object is locked skipped
C:\Program Files\GM SPO\eSI\SIROM\SIen\DB\roms\cd\comp000.000 Object is locked skipped
C:\Program Files\GM SPO\eSI\SIROM\SIen\R0\rfile000.000 Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{83230FEF-DF8F-4DD5-9594-BCD5459F8831}\RP128\A0031632.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{83230FEF-DF8F-4DD5-9594-BCD5459F8831}\RP138\A0033037.dll Object is locked skipped
C:\System Volume Information\_restore{83230FEF-DF8F-4DD5-9594-BCD5459F8831}\RP139\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\drivers\dtscsi.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd9981.sys Object is locked skipped
C:\WINDOWS\system32\drivers\vaxscsi.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\hsperfdata_SYSTEM\548 Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_29c.dat Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
G:\Steam\Steam.log Object is locked skipped
G:\Steam\SteamApps\winui.gcf Object is locked skipped
G:\Steam\SteamLogs\SteamStats.log Object is locked skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.









Logfile of HijackThis v1.99.1
Scan saved at 4:36:47 PM, on 10/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\avgamsvr.exe
C:\PROGRA~1\avgupsvc.exe
C:\PROGRA~1\avgemc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\GM SPO\eSI\Apache Group\Tomcat 4.1\bin\tomcat.exe
C:\Program Files\GM SPO\eSI\Transbase\tbmux32.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\GM SPO\eSI\Transbase\tbkern32.exe
C:\Program Files\GM SPO\eSI\Transbase\tbkern32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\MMTray.exe
G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtray2k.exe
G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtraylsi.exe
C:\PROGRA~1\avgcc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
G:\PowerDVD6\PDVDServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Messenger\msmsgs.exe
G:\steam\steam.exe
E:\Wlan\WLANPRO.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJT\Nathan.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {35585227-1E4D-4568-9663-C69131BF0CC4} - C:\WINDOWS\msagent\pm3nu.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [MMTray] "G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\MMTray.exe"
O4 - HKLM\..\Run: [mmtray2k] "G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtray2k.exe"
O4 - HKLM\..\Run: [mmtraylsi] "G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtraylsi.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] G:\PowerDVD6\PDVDServ.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "g:\steam\steam.exe" -silent
O4 - Global Startup: 108Mbps Wireless LAN Adapter Configuration Utility.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Reg.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4866/mcfscan.cab
O20 - Winlogon Notify: pm3nu - C:\WINDOWS\msagent\pm3nu.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SI Tomcat (SITomcat) - Alexandria Software Consulting - C:\Program Files\GM SPO\eSI\Apache Group\Tomcat 4.1\bin\tomcat.exe
O23 - Service: SI Transbase (SITransbase) - TransAction Software, D 81737 Munich - C:\Program Files\GM SPO\eSI\Transbase\tbmux32.exe


Thank you!

-Nathan
 
#15 ·
Hello Nathan. Good job! :smile:. You have done really well. We need to carry on a little longer to completely erase all the traces of malwares from your PC and ensure that it should never come back [unless you invite it :grin:).

Please give me the following informations:

1. It does not appear that you have installed all the programs I have asked you to. Did you face any difficulty in downloading or installing these softwares?

2. Are you still getting the popups?

Please follow the next set of instructions very carefully.

Update Avg Anti-Spyware and Disable Avg Anti-Spyware Guard

Double-click the icon on Desktop to launch AVG Anti-Spyware. You will need to update AVG Anti-Spyware to the latest definition files. After running update, please disable your AVG Anti-Spyware Guard, as it may hinder the removal of some entries. On the top of the main screen click Shield. Click the word active to change it to inactive.

Fix

Reboot your system in Safe Mode (By repeatedly tapping the F8 key until the menu appears).

Open HiJackThis.
Click "Open the Misc Tools".
Click "Delete a file on reboot..."
In the "Enter file to delete on reboot..." window, navigate to:

C:\WINDOWS\msagent.

Select the file

pm3nu.dll

Then click Open. After you click Open, HiJackThis will ask you if you want to restart your computer now- click No. We shall restart manually afterwards.

Open HijackThis again and click on 'Do a System Scan Only'. Check the following entries (If they still exist, make sure you do not miss any)

O2 - BHO: (no name) - {6297DA1E-3435-4D6B-8F14-D6D0F2512C63} - C:\WINDOWS\msagent\pm3nu.dll
O20 - Winlogon Notify: pm3nu - C:\WINDOWS\msagent\pm3nu.dll
O20 - Winlogon Notify: winexz32 - winexz32.dll (file missing)


Please remember to close all other windows, including browsers then click Fix checked.

AVG Anti-Spyware

Run AVG Anti-Spyware with it's updated definitions:(...it's important that all windows must be closed)
  • Click Scanner
  • Click on the Scan tab
  • Click Complete System Scan to begin scanning.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Once finished, click the Save report button, then click Save Report As and save it to your desktop. (make sure to remember where you saved that file, this is important).

Reboot your system in Normal Mode.
________________________________________________________________

Online Scan

Perform an online scan with Internet Explorer with Panda ActiveScan
** click on "Free use ActiveScan" located on the top right hand corner
  1. Click Scan your PC & a 'pop up' window shall appear. *ensure that your pop up blocker doesn't block it
  2. Click Scan Now
  3. Enter your e-mail address & click Scan Now ...begins downloading 8 MB Panda's ActiveX controls
Begin the scan by selecting My Computer
  • If it finds any malware, it will offer you a report. [*] Click on see report. Then click Save report
Please post that log in your next reply.

So with your next post please provide me the following logs:

Panda Scan
AVG Anti-Spyware
HJT [A Fresh One]


Please do not forget to provide me with all the informations I have asked at the begining. :smile:
 
#16 ·
Which programs haven't I installed? Your instructions have been very clear, and I've followed everything as best I could. I didn't think I missed anything.

Yes, I'm still getting popups. At least, I was before this last step...none yet. *knock on wood!*

Here are the next logs.

I think this is the Pandasoft one? I may have lost it >.<

C:\Documents and Settings\...\Temp\iscueesg.dll Generic Spy
C:\Documents and Settings\...\Temp\ktbahupx.dll Generic Spy
C:\Documents and Settings\...\Temp\npfmlsvw.dll Generic Spy
C:\Documents and Settings\...\Temp\onltaouo.dll Generic Spy
C:\Documents and Settings\...\Temp\rsxdxaps.dll Generic Spy
C:\System Volume Information\...\A0031633.dll Vundo
C:\System Volume Information\...\A0031659.dll Adware-SearchColours
C:\System Volume Information\...\A0031778.dll Vundo
C:\WINDOWS\system32\eyubgyev.exe Adware-SearchColours
C:\WINDOWS\system32\jjrwmnva.dll Generic Spy
C:\WINDOWS\system32\vfcwqrbr.dll Generic Spy
C:\WINDOWS\system32\xmkwanqc.dll Generic Spy


---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 7:39:42 PM 10/18/2006

+ Scan result:



C:\System Volume Information\_restore{83230FEF-DF8F-4DD5-9594-BCD5459F8831}\RP129\A0031659.dll -> Adware.Searchcolours : Cleaned.
C:\Documents and Settings\The Shaolin!\Cookies\the shaolin!@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\The Shaolin!\Cookies\the shaolin!@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\The Shaolin!\Cookies\the shaolin!@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.15:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\sk6c4uji.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\The Shaolin!\Cookies\the shaolin!@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\The Shaolin!\Cookies\the shaolin!@as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\The Shaolin!\Cookies\the shaolin!@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\The Shaolin!\Cookies\the shaolin!@www.myaffiliateprogram[2].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.23:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\sk6c4uji.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.24:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\sk6c4uji.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.25:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\sk6c4uji.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.26:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\sk6c4uji.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.30:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\sk6c4uji.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.31:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\sk6c4uji.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.32:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\sk6c4uji.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.33:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\sk6c4uji.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.34:C:\Documents and Settings\The Shaolin!\Application Data\Mozilla\Firefox\Profiles\sk6c4uji.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\The Shaolin!\Cookies\the shaolin!@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\The Shaolin!\Cookies\the shaolin!@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\The Shaolin!\Cookies\the shaolin!@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\The Shaolin!\Cookies\the shaolin!@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\The Shaolin!\Cookies\the shaolin!@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.


::Report end




Logfile of HijackThis v1.99.1
Scan saved at 4:36:47 PM, on 10/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\avgamsvr.exe
C:\PROGRA~1\avgupsvc.exe
C:\PROGRA~1\avgemc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\GM SPO\eSI\Apache Group\Tomcat 4.1\bin\tomcat.exe
C:\Program Files\GM SPO\eSI\Transbase\tbmux32.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\GM SPO\eSI\Transbase\tbkern32.exe
C:\Program Files\GM SPO\eSI\Transbase\tbkern32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\MMTray.exe
G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtray2k.exe
G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtraylsi.exe
C:\PROGRA~1\avgcc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
G:\PowerDVD6\PDVDServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Messenger\msmsgs.exe
G:\steam\steam.exe
E:\Wlan\WLANPRO.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJT\Nathan.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {35585227-1E4D-4568-9663-C69131BF0CC4} - C:\WINDOWS\msagent\pm3nu.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [MMTray] "G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\MMTray.exe"
O4 - HKLM\..\Run: [mmtray2k] "G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtray2k.exe"
O4 - HKLM\..\Run: [mmtraylsi] "G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtraylsi.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] G:\PowerDVD6\PDVDServ.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "g:\steam\steam.exe" -silent
O4 - Global Startup: 108Mbps Wireless LAN Adapter Configuration Utility.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Reg.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4866/mcfscan.cab
O20 - Winlogon Notify: pm3nu - C:\WINDOWS\msagent\pm3nu.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SI Tomcat (SITomcat) - Alexandria Software Consulting - C:\Program Files\GM SPO\eSI\Apache Group\Tomcat 4.1\bin\tomcat.exe
O23 - Service: SI Transbase (SITransbase) - TransAction Software, D 81737 Munich - C:\Program Files\GM SPO\eSI\Transbase\tbmux32.exe
 
#17 ·
Hello Nathan, do not worry, we are going to get the baddies :smile:.

I meant the programs I suggested at the end of this post: http://www.techsupportforum.com/showpost.php?p=664558&postcount=12.
One of these programs [SpywareGuard] should be running as your startup program, but it is not there. If you have not installed these programs, wait till we clear PC completely.

I'm reviewing your logs and please be patient, I'll be back with a fix ASAP.
 
#18 · (Edited by Moderator)
Hello Nathan :smile:.

Killbox

Download Pocket Killbox and unzip the exe file to your desktop.

*********************************************

Launch KillBox.exe & select the following options:
  • Delete on Reboot
  • All files (if available)
Now copy/paste the file below into the 'Full path of File to Delete' field.

C:\WINDOWS\msagent\pm3nu.dll

Select/tick the following:
* Delete on Reboot
* End Explorer Shell While Killing File
* Unregister.dll Before Deleting".
Click the RED X button.

Click Yes at the 'Delete on Reboot' prompt. Click Yes at the Pending Operations prompt.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, download and run missingfilesetup.exe. Then try Killbox again.

* If you received a message such as: "PendingFileRenameOperations registry data has been removed by external process", you have to manually restart Windows.
_________________________________________________________________

Open HijackThis and click on 'Do a System Scan Only'. Check the following entries (If they still exist, make sure you do not miss any)

O2 - BHO: (no name) - {6297DA1E-3435-4D6B-8F14-D6D0F2512C63} - C:\WINDOWS\msagent\pm3nu.dll
O20 - Winlogon Notify: pm3nu - C:\WINDOWS\msagent\pm3nu.dll


Please remember to close all other windows, including browsers then click Fix checked.

Reboot your system in Normal Mode.

With your next reply please provide A New HJT Log.
 
#19 ·
Hello :)

The popups have finally stopped!!

Here's the fresh HJT log.

Logfile of HijackThis v1.99.1
Scan saved at 5:41:08 PM, on 10/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\avgamsvr.exe
C:\PROGRA~1\avgupsvc.exe
C:\PROGRA~1\avgemc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\GM SPO\eSI\Apache Group\Tomcat 4.1\bin\tomcat.exe
C:\Program Files\GM SPO\eSI\Transbase\tbmux32.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\GM SPO\eSI\Transbase\tbkern32.exe
C:\Program Files\GM SPO\eSI\Transbase\tbkern32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\MMTray.exe
G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtray2k.exe
G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtraylsi.exe
C:\PROGRA~1\avgcc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
G:\PowerDVD6\PDVDServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Messenger\msmsgs.exe
G:\steam\steam.exe
C:\Program Files\iPod\bin\iPodService.exe
E:\Wlan\WLANPRO.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
E:\Wlan\Reg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\Nathan.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {622DCBBF-2FF5-487D-8144-273B5EE3F428} - C:\WINDOWS\msagent\pm3nu.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [MMTray] "G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\MMTray.exe"
O4 - HKLM\..\Run: [mmtray2k] "G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtray2k.exe"
O4 - HKLM\..\Run: [mmtraylsi] "G:\ACE Mega CoDecS Pack\SystemS\Morgan Multimedia\mmtraylsi.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] G:\PowerDVD6\PDVDServ.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "g:\steam\steam.exe" -silent
O4 - Global Startup: 108Mbps Wireless LAN Adapter Configuration Utility.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Reg.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4866/mcfscan.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SI Tomcat (SITomcat) - Alexandria Software Consulting - C:\Program Files\GM SPO\eSI\Apache Group\Tomcat 4.1\bin\tomcat.exe
O23 - Service: SI Transbase (SITransbase) - TransAction Software, D 81737 Munich - C:\Program Files\GM SPO\eSI\Transbase\tbmux32.exe



Thanks!
 
#20 ·
Hello Shaolin :smile:.

Well done, your logs are almost clean!

Just follow the next steps to completely clean your sytem and protect it in future from malwares.

Open HijackThis and click on 'Do a System Scan Only'. Check the following entries (If they still exist, make sure you do not miss any)

O2 - BHO: (no name) - {622DCBBF-2FF5-487D-8144-273B5EE3F428} - C:\WINDOWS\msagent\pm3nu.dll (file missing)

Please remember to close all other windows, including browsers then click Fix checked.

Reset hidden/system files and folders

  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Deselect the Show hidden files and folders option.
  • Select the Hide file extensions for known types option.
  • Select the Hide protected operating system files option.
  • Click Yes to confirm.
  • Click OK.

System Restore

To turn off System Restore click Start > Right Click My Computer > Properties. Click the System Restore tab and Check "Turn off System Restore" or "Turn off System Restore on all drives" Click Apply. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this then Click OK.

Turn on System Restore by Clicking Start. Right-click My Computer, and then click Properties. Click the System Restore tab. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives." Click Apply, and then OK.

This will create a new Restore Point.


Updating Java and Clearing Cache

  1. Go to Start > Control Panel double-click on the Java Icon (coffee cup) in the Control Panel.
  2. It will say "Java Plug-in" under the icon.
  3. If it is not visible, click on 'Switch to Classic View' in the left pane of the Control Panel or 'Other Control Panel Options'
  4. Please find the Update button or tab in the Java Control Panel. Update your Java then reboot.
  5. If you are unable to update you can manually update by going here:
  6. After the reboot, go back into the Control Panel and double-click the Java Icon.
  7. Under the Advanced Tab, click <Applet> tag support and select the browser(s) you are using.
  8. Under "Temporary Internet Files", click the Delete Files button.
  9. There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
    • Downloaded Applications
    • Other Files
  10. Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  11. Click OK to leave the Java Control Panel.

MICROSOFT UPDATES

It is very important that you get all of the critical updates for your Operating System and Internet Explorer. Keeping your OS and browser up to date will help make you less susceptible to attacks by Trojans and viruses. Please go to Microsoft and download all the critical updates to help prevent possible re-infection.

SPYWARE PREVENTION SPEECH

This is a good time to set up protection against further attacks. Read TonyKlein's How Did I Get Infected In The First Place?. You need an antivirus that is continually updated, a good firewall, a spyware blocker such as Spyware Blaster, and a real time spyware program such as Spyware Guard, to prevent spyware intrusions. IE-Spyad is another excellent program that places over 4000 websites and domains in the IE Restricted list, which will help prevent attempts to infect your system. All of the above have good free versions available. However, be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

More information and downloads are available at the following links:

Happy surfing :wave: .
 
#21 ·
Thank you so much for your help! I just have one final question.

I ran a virus scan, and it still finds a virus. "Virus found: Klone." I've found and removed this virus several times, but it's still there. I know it's probably not exactly your cup of tea, but do you have any idea how to fix this? Thanks

-Nathan
 
#23 ·
Yes, I followed all the instructions in your last post, except for one involving hiding file extensions and system files. I prefer to have those viewable, unless it is a security risk?

I'm using AVG anti-virus. The two questionable files are

C:\Windows\system32\vfcwqrbr.dll and
C:\Windows\system32\xmkwanqc.dll
 
#24 · (Edited)
Hello Nathan,

Reboot your system in Safe Mode (By repeatedly tapping the F8 key until the menu appears).

Delete the following Files indicated in RED if they still exist.

C:\Windows\system32\vfcwqrbr.dll
C:\Windows\system32\xmkwanqc.dll


Reboot your system in normal mode.

See if this solves your problem. If not, please let me know. Also please post a new HJT log taken in normal mode with your reply.

Now having system files and extensions viewable is not a very good idea as accidental deletion or renaming of files can cause serious problems. As you already know how to enable this when need arises, I suggest you to disable thenm when you do not need. For the time being keep them enabled till we get rid of these two files.
 
#25 ·
Hello Nathan :smile:

With reference to your previous complain I think there is some infection still left in your system. So please go through the following steps.

Please download VundoFix to your desktop.
  • Double-click VundoFix.exe to run it.
  • Right Click inside the listbox (white box) and click add more files
  • Copy&Paste the 4 entries below into the top 4 boxes
    • C:\Windows\system32\rbrqwcfv.dll
    • C:\WINDOWS\system32\vfcwqrbr.*
    • C:\Windows\system32\cqnawkmx.dll
    • C:\WINDOWS\system32\xmkwanqc.*
  • Click Add Files and Click Close Window
  • Click Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • It will produce a log of it's actions at C:\vundofix.txt

Run a system scan with HJT and save the logfile to post here.


So with your next reply please provide:
VundoFix.txt
HJT Log


Let me know about the overall behaviour of your system :smile:.
 
Status
Not open for further replies.
You have insufficient privileges to reply here.
Top