PDA

View Full Version : need help with cmdservice adware problem



rainshield
2007-12-05, 21:01
hi, i just got this computer from my older bro. My older bro sure didnt take a good care of this pc, n it started to get all messed up, everytime i got on internet, there's alot of pop up came from no where, so i ran spybot s&d n finally got off some spybots but there's still some left that i cant even get rid off. I'll be appreciated with any helps from u guys, thanks
here is my pc's Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:45:05 PM, on 12/5/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\Java\J2RE14~1.2_0\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hphmon05.exe
C:\PROGRA~1\COMMON~1\Sonic\UPDATE~1\sgtray.exe
C:\HP\KBD\KBD.EXE
C:\PROGRA~1\COMMON~1\SYMANT~1\ccApp.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\twain.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\PROGRA~1\Yahoo!\SEARCH~1\SEARCH~1.EXE
C:\WINDOWS\System32\SCURIT~1\wuaclt.exe
C:\WINDOWS\STEM32~1\POOLSV~1.EXE
C:\PROGRA~1\COMPAQ~1\1940576\Program\BACKWE~1.EXE
C:\PROGRA~1\INTERM~1\SPAMSU~1\SpamSub.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\HIJACK~1.EXE
C:\WINDOWS\System32\vbdicggu.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn7\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\mjtup.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,webyach.exe
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {81DD71C2-F59D-40FD-8B75-E318C0D8FC3B} - C:\WINDOWS\System32\jkkll.dll
O2 - BHO: (no name) - {95CB3857-A0E7-F21B-EE5B-FD8A45862C97} - C:\WINDOWS\System32\cnsi.dll (file missing)
O2 - BHO: (no name) - {B8DDAA3C-66A8-335D-895D-3FE6008709E7} - C:\WINDOWS\System32\oannas.dll
O2 - BHO: (no name) - {C3352FCD-CFE5-4F35-831A-19C68DDB7CF4} - C:\WINDOWS\System32\xxyvtqn.dll
O2 - BHO: {0dfef156-ff96-6188-d8a4-066f8639c83e} - {e38c9368-f660-4a8d-8816-69ff651fefd0} - C:\WINDOWS\System32\ybdvjgcn.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn7\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer]
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PS2]
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [Cabal_GSP] C:\WINDOWS\twain.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\qttask.exe" -atboottime
O4 - HKLM\..\Run: [winshow] "C:\WINDOWS\winshow.exe"
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\tsitra572.exe 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139
O4 - HKLM\..\Run: [e4c80086] rundll32.exe "C:\WINDOWS\System32\bbqjofrl.dll",b
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Notn] "C:\WINDOWS\System32\SCURIT~1\wuaclt.exe" -vt yazb
O4 - HKCU\..\Run: [Insider] C:\Program Files\Insider\Insider.exe
O4 - HKCU\..\Run: [Omht] C:\WINDOWS\??stem32\?poolsv.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - S-1-5-18 Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'Default user')
O4 - .DEFAULT User Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (User 'Default user')
O4 - .DEFAULT User Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'Default user')
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\kqdsrngj.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: palstart.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O20 - AppInit_DLLs: tcpsvcs.dll
O20 - Winlogon Notify: xxyvtqn - C:\WINDOWS\SYSTEM32\xxyvtqn.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DomainService - - C:\WINDOWS\System32\vbdicggu.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe

--
End of file - 9550 bytes

ken545
2007-12-06, 14:03
Hello
Welcome to Safer Networking.

Please read Before You Post (http://forums.spybot.info/showthread.php?t=288)
That said, All advice given by anyone volunteering here, is taken at own risk.
While best efforts are made to assist in removing infections safely, unexpected stuff can happen.


You have variety of infections on this computer, lets do a few things. One of the infections you have is a downloader that will download other infections so I urge you until your clean , outside of posting here to stay off the internet.


Download ComboFix from Here (http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe) or Here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) to your Desktop.

Double click combofix.exe and follow the prompts.
When finished, it shall produce a log for you. Post the Combofix log and a HiJackthis log in your next reply

Note: Do not mouseclick combofix's window while its running. That may cause it to stall




Please download SuperAntiSpyware (http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE)
Install the program

Run SuperAntiSpyware and click: Check for updates
Once the update is finished, on the main screen, click: Scan your computer
Check: Perform Complete Scan
Click Next to start the scan.

Superantispyware scans the computer, and when finished, lists all the infections found.
Make sure everything found has a check next to it, and press: Next
Then, click Finish

It is possible that the program asks to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
Click: Preferences
Click the Statistics/Logs tab
Under Scanner Logs, double-click SuperAntiSpyware Scan Log
It opens in your default text editor (such as Notepad)

Please provide the SuperAntiSpyware log in your reply, as well as a new HijackThis log.





Download CCleaner from here (http://www.ccleaner.com/) to clean temp files from your computer.

Double click on the file to start the installation of the program.
Select your language and click OK, then next.
Read the license agreement and click I Agree.
Click next to use the default install location. Click Install then finish to complete installation.
Double click the CCleaner shortcut on the desktop to start the program.
On the "Windows" tab, under "Internet Explorer," uncheck "Cookies" if you do not want them deleted. (If deleted, you will likely need to reenter your passwords at all sites where a cookie is used to recognize you when you visit).
If you use either the Firefox or Mozilla browsers, the box to uncheck for "Cookies" is on the Applications tab, under Firefox/Mozilla.
Click on the "Options" icon at the left side of the window, then click on "Advanced."
deselect "Only delete files in Windows Temp folders older than 48 hours."
Click on the "Cleaner" icon on the left side of the window, then click Run Cleaner to run the program.
Caution: It is not recommended that you use the "Issues" feature unless you are very familiar with the registry as it has been known to find legitimate items.
After CCleaner has completed its process, click Exit.

*NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders. If you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner!



Go to where you have HJT installed and rename Hijackthis.exe to Scanner.exe

I need to see the Combofix log, the SAS log and New HJT log renamed please.

rainshield
2007-12-06, 22:55
Thanks for ur respond, i can tell my pc's running smoothly more than b4 now, but somehow i cant post SAS log and combofix log, the logs are too long. So i'm only able to post the new renamed hjackthis logs.
here it is:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:40:02 PM, on 12/6/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\interMute\SpamSubtract\SpamSub.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\scanner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn7\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe,
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,webyach.exe
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {95CB3857-A0E7-F21B-EE5B-FD8A45862C97} - C:\WINDOWS\System32\cnsi.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn7\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer]
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PS2]
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\qttask.exe" -atboottime
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Notn] "C:\WINDOWS\System32\SCURIT~1\wuaclt.exe" -vt yazb
O4 - HKCU\..\Run: [Omht] C:\WINDOWS\??stem32\?poolsv.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [rnokq] C:\WINDOWS\System32\vadqpv.exe reg_run
O4 - S-1-5-18 Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'Default user')
O4 - .DEFAULT User Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (User 'Default user')
O4 - .DEFAULT User Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'Default user')
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe

--
End of file - 8346 bytes

ken545
2007-12-07, 00:40
I need to see both the SAS and Combofix log, you can use the Submit reply and use as many as you need.

rainshield
2007-12-07, 07:32
ok here is combofix log:
ComboFix 07-12-02.7 - Owner 2007-12-06 12:27:18.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.224 [GMT -8:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\check_LSA7.txt
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nhprv.exe
C:\WINDOWS\system32\bwrtb.dat
C:\WINDOWS\system32\jkkll.dll
C:\WINDOWS\system32\xxyvtqn.dll
.
---- Previous Run -------
.
C:\Documents and Settings\Administrator\Application Data\install.dat
C:\Documents and Settings\Administrator\Application Data\Sskknwrd.dll
C:\Documents and Settings\All Users.\documents\settings
C:\Documents and Settings\All Users.\documents\settings\desktop.ini
C:\Documents and Settings\All Users\Application Data.\microsoft\pctools
C:\Documents and Settings\All Users\Application Data.\microsoft\pctools\pctools.dll
C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007\Data\Abbr
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007\Data\ProductCode
C:\Documents and Settings\All Users\Application Data\microsoft\pctools\pctools.dll
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\Abbr
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\ProductCode
C:\Documents and Settings\Default User\Application Data\Install.dat
C:\Documents and Settings\Owner\Application Data\CROSOF~1
C:\Documents and Settings\Owner\Application Data\CROSOF~1\??plorer.exe
C:\Documents and Settings\Owner\Application Data\DOBE~1
C:\Documents and Settings\Owner\Application Data\DOBE~1\s?ool32.exe
C:\Documents and Settings\Owner\Application Data\Install.dat
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\KUJMKQRS\www.broadcaster.com
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\Owner\Application Data\MANTEC~1
C:\Documents and Settings\Owner\Application Data\MBOLS~1
C:\Documents and Settings\Owner\Application Data\RACLE~1
C:\Documents and Settings\Owner\Application Data\RACLE~1\?racle\
C:\Documents and Settings\Owner\Application Data\RACLE~1\dvdplay.exe
C:\Documents and Settings\Owner\Application Data\tmp7C.tmp.exe
C:\Documents and Settings\Owner\Application Data\tmp7D.tmp.exe
C:\Documents and Settings\Owner\Application Data\WinAntiSpyware 2007
C:\Documents and Settings\Owner\Application Data\WinAntiSpyware 2007\Logs\update.log
C:\Documents and Settings\Owner\Application Data\WinTouch
C:\Documents and Settings\Owner\Application Data\WinTouch\wintouch.cfg
C:\Documents and Settings\Owner\Application Data\WinTouch\WinTouch.exe
C:\Documents and Settings\Owner\Application Data\WinTouch\WTUninstaller.exe
C:\Documents and Settings\Owner\err.log
C:\Documents and Settings\Owner\My Documents\DOBE~1
C:\Documents and Settings\Owner\My Documents\DOBE~1\bak\winword.exe
C:\Documents and Settings\Owner\My Documents\DOBE~1\winword.exe
C:\Documents and Settings\Owner\My Documents\ICROSO~1.NET
C:\Documents and Settings\Owner\My Documents\ICROSO~1.NET\?icrosoft.NET\
C:\Documents and Settings\Owner\My Documents\ICROSO~1.NET\cmd.exe
C:\Documents and Settings\Owner\My Documents\PPATCH~1
C:\Documents and Settings\Owner\My Documents\TSKS~1
C:\Documents and Settings\Owner\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\Owner\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\Owner\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Documents and Settings\Owner\Start Menu\Programs\Outerinfo
C:\Documents and Settings\Owner\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\Owner\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\ta_start.lnk
C:\Documents and Settings\Owner\winstall.exe
C:\Program Files\Common Files\{34C80~1
C:\Program Files\Common Files\{34C80~1\Activate.exe
C:\Program Files\Common Files\{34C80~1\Bar888.dll
C:\Program Files\Common Files\{34C80~1\toolbardll.lzma
C:\Program Files\Common Files\{34C80~1\UnInstall.exe
C:\Program Files\Common Files\{E4C80~1
C:\Program Files\Common Files\{E4C80~1\system.dll
C:\Program Files\Common Files\{E4C80~1\Update.exe
C:\Program Files\Common Files\download
C:\Program Files\Common Files\fnts~1
C:\Program Files\Common Files\fnts~1\s?ool32.exe
C:\Program Files\Common Files\mantec~1
C:\Program Files\Common Files\mbols~1
C:\Program Files\Common Files\stem32~1
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\winantispyware 2007\uwas7cw.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\Program Files\dobe~1
C:\Program Files\e2g
C:\Program Files\e2g\data19
C:\Program Files\Insider
C:\Program Files\Insider\Insider.exe
C:\Program Files\Insider\UnInstall.exe
C:\Program Files\ISM
C:\Program Files\ISM\BndDrive.dll
C:\Program Files\ISM\bndloader.exe
C:\Program Files\ISM\dictionary.gz
C:\Program Files\ISM\ism.exe
C:\Program Files\ISM\ISMModule2.exe
C:\Program Files\ISM\targets.gz
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\sembly~1
C:\Program Files\sembly~1\??sembly\
C:\Program Files\sembly~1\lsass.exe
C:\Program Files\smbols~1
C:\Program Files\svhost
C:\Program Files\svhost\wr-1-0000077.exe
C:\Program Files\system files
C:\Program Files\WinAble
C:\Program Files\winantispyware 2007
C:\Program Files\WinAntiSpyware 2007\Activate.dat
C:\Program Files\WinAntiSpyware 2007\appupdate.dat
C:\Program Files\WinAntiSpyware 2007\AsAgents.dll
C:\Program Files\winantispyware 2007\AsAgents.xml
C:\Program Files\winantispyware 2007\atl71.dll
C:\Program Files\winantispyware 2007\AutoProcess.dat
C:\Program Files\winantispyware 2007\bnlink.dat
C:\Program Files\winantispyware 2007\database\enemies.dat
C:\Program Files\winantispyware 2007\database\knownfiles.dat
C:\Program Files\WinAntiSpyware 2007\database\TEBase.dat
C:\Program Files\winantispyware 2007\database\vbpv.dat
C:\Program Files\winantispyware 2007\dbupdate.dat
C:\Program Files\WinAntiSpyware 2007\fopnl.dll
C:\Program Files\winantispyware 2007\InstHelp.exe
C:\Program Files\WinAntiSpyware 2007\InstUp.exe
C:\Program Files\WinAntiSpyware 2007\lapv.dat
C:\Program Files\winantispyware 2007\license.rtf
C:\Program Files\WinAntiSpyware 2007\manual.pdf
C:\Program Files\WinAntiSpyware 2007\manual.url
C:\Program Files\WinAntiSpyware 2007\mfc71.dll
C:\Program Files\WinAntiSpyware 2007\monstate.dat
C:\Program Files\winantispyware 2007\msvcp71.dll
C:\Program Files\winantispyware 2007\msvcr71.dll
C:\Program Files\WinAntiSpyware 2007\ps.dat
C:\Program Files\WinAntiSpyware 2007\pv.dat
C:\Program Files\WinAntiSpyware 2007\quaratine.dat\#post_quarantine
C:\Program Files\WinAntiSpyware 2007\readme.rtf
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\00fbab385ca84f7d083f868c\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\00fbab385ca84f7d083f868c\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\00fbab385ca84f7d083f868c\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\00fbab385ca84f7d083f868c\Owner
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\1b1f6449aa7e401f3f0a5182\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\1b1f6449aa7e401f3f0a5182\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\1b1f6449aa7e401f3f0a5182\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\1b1f6449aa7e401f3f0a5182\Owner
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\1b84426a0e3845f345efdda8\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\1b84426a0e3845f345efdda8\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\1b84426a0e3845f345efdda8\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\1b84426a0e3845f345efdda8\Owner
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\1dda03149b894c052c134888\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\1dda03149b894c052c134888\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\1dda03149b894c052c134888\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\1e7e7be8cb0842c7f470f88a\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\1e7e7be8cb0842c7f470f88a\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\1e7e7be8cb0842c7f470f88a\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\1e7e7be8cb0842c7f470f88a\Owner
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\1fd4958533b7449bf60c7f9a\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\1fd4958533b7449bf60c7f9a\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\1fd4958533b7449bf60c7f9a\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\262e8d97a57547d2681dbc8f\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\262e8d97a57547d2681dbc8f\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\262e8d97a57547d2681dbc8f\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\269acce845624d425d2f9089\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\269acce845624d425d2f9089\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\269acce845624d425d2f9089\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\2986358572074bcc883cd990\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\2986358572074bcc883cd990\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\2986358572074bcc883cd990\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\2986358572074bcc883cd990\Owner
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\2d23f5d52ae64864cdff51be\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\2d23f5d52ae64864cdff51be\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\2d23f5d52ae64864cdff51be\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\2d23f5d52ae64864cdff51be\Owner
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\2ee44646484647baf0d93a99\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\2ee44646484647baf0d93a99\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\2ee44646484647baf0d93a99\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\317102517a9f46e559f296b4\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\317102517a9f46e559f296b4\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\317102517a9f46e559f296b4\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3719b2d4723d48b62505e3bd\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3719b2d4723d48b62505e3bd\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3719b2d4723d48b62505e3bd\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3719b2d4723d48b62505e3bd\Owner
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3b1677afa28e416e8d6b1787\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3b1677afa28e416e8d6b1787\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3b1677afa28e416e8d6b1787\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3c30560e9a7c465f57ac71a0\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3c30560e9a7c465f57ac71a0\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3c30560e9a7c465f57ac71a0\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3cf1992878d0422bf3bc6aa0\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3cf1992878d0422bf3bc6aa0\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3cf1992878d0422bf3bc6aa0\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3cf2c8913a1b485425d334bb\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3cf2c8913a1b485425d334bb\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3cf2c8913a1b485425d334bb\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3da524b65f3447dd60151dad\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3da524b65f3447dd60151dad\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\3da524b65f3447dd60151dad\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\45989b69fddc4be29db54884\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\45989b69fddc4be29db54884\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\45989b69fddc4be29db54884\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\4c9908412fdc423c806652bb\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\4c9908412fdc423c806652bb\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\4c9908412fdc423c806652bb\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\4e493e7fe4ae4e9c7f501a8b\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\4e493e7fe4ae4e9c7f501a8b\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\4e493e7fe4ae4e9c7f501a8b\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\569df1b7d991477080b1e3b6\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\569df1b7d991477080b1e3b6\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\569df1b7d991477080b1e3b6\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\574eaa5d3221486e059184a3\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\574eaa5d3221486e059184a3\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\574eaa5d3221486e059184a3\#name

rainshield
2007-12-07, 07:33
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\58ab901e609642eb18e16092\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\58ab901e609642eb18e16092\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\58ab901e609642eb18e16092\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\5d3bf5d2ca1444b4eb4c1f80\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\5d3bf5d2ca1444b4eb4c1f80\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\5d3bf5d2ca1444b4eb4c1f80\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\5f677af4e3884f52405c58b6\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\5f677af4e3884f52405c58b6\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\5f677af4e3884f52405c58b6\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\5f677af4e3884f52405c58b6\Owner
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\60e449fbb4114d424f3f5282\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\60e449fbb4114d424f3f5282\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\60e449fbb4114d424f3f5282\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\61102722191a47ec56d25e8a\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\61102722191a47ec56d25e8a\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\61102722191a47ec56d25e8a\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\70aeaf65f5974122907a3ba5\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\70aeaf65f5974122907a3ba5\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\70aeaf65f5974122907a3ba5\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\70aeaf65f5974122907a3ba5\Owner
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\70e726e134164b2aba9123af\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\70e726e134164b2aba9123af\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\70e726e134164b2aba9123af\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\70e726e134164b2aba9123af\Owner
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\74593b16538a412e650fc199\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\74593b16538a412e650fc199\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\74593b16538a412e650fc199\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\77753364e86743dfa7c20abc\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\77753364e86743dfa7c20abc\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\77753364e86743dfa7c20abc\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\77753364e86743dfa7c20abc\Owner
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\84df34298956432c975a4182\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\84df34298956432c975a4182\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\84df34298956432c975a4182\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\84df34298956432c975a4182\Owner
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\85feeafaa966403c87bb90b9\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\85feeafaa966403c87bb90b9\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\85feeafaa966403c87bb90b9\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\85feeafaa966403c87bb90b9\Owner
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\8902dd1f0a834c46dd6de495\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\8902dd1f0a834c46dd6de495\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\8902dd1f0a834c46dd6de495\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\8902dd1f0a834c46dd6de495\Owner
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\89b5455d3ceb485313e506be\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\89b5455d3ceb485313e506be\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\89b5455d3ceb485313e506be\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\93ed64a0acda4aaa8a35478f\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\93ed64a0acda4aaa8a35478f\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\93ed64a0acda4aaa8a35478f\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\991516eb68d34e91d4b4faaa\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\991516eb68d34e91d4b4faaa\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\991516eb68d34e91d4b4faaa\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\a07342eea27c427171b7ab89\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\a07342eea27c427171b7ab89\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\a07342eea27c427171b7ab89\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\a18f767cc2d0446b6bb5cbb4\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\a18f767cc2d0446b6bb5cbb4\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\a18f767cc2d0446b6bb5cbb4\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\a18f767cc2d0446b6bb5cbb4\Owner
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\ad99a1569e3443dd901065be\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\ad99a1569e3443dd901065be\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\ad99a1569e3443dd901065be\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\afc42352fd04451d1d62ddb9\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\afc42352fd04451d1d62ddb9\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\afc42352fd04451d1d62ddb9\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\b7e9220e51ba4d1096a27286\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\b7e9220e51ba4d1096a27286\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\b7e9220e51ba4d1096a27286\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\b7e9220e51ba4d1096a27286\Owner
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\b95debe9a069451555186284\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\b95debe9a069451555186284\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\b95debe9a069451555186284\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\c68cc4ce71da4a5f8a318389\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\c68cc4ce71da4a5f8a318389\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\c68cc4ce71da4a5f8a318389\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\c68cc4ce71da4a5f8a318389\Owner
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\ca50e1456f6948aa997dd39d\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\ca50e1456f6948aa997dd39d\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\ca50e1456f6948aa997dd39d\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\cb7333f5fa3a4a9129be2cb8\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\cb7333f5fa3a4a9129be2cb8\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\cb7333f5fa3a4a9129be2cb8\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\cb7333f5fa3a4a9129be2cb8\Owner
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\cbcd85995a944a35b7065eb0\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\cbcd85995a944a35b7065eb0\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\cbcd85995a944a35b7065eb0\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\cc71bc898c604097824955b5\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\cc71bc898c604097824955b5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\cc71bc898c604097824955b5\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\cc878014de8b4f05c8d62c9b\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\cc878014de8b4f05c8d62c9b\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\cc878014de8b4f05c8d62c9b\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\cef2fd98afa04339c91327af\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\cef2fd98afa04339c91327af\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\cef2fd98afa04339c91327af\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\d05c8bcccb964e86c5da71bf\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\d05c8bcccb964e86c5da71bf\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\d05c8bcccb964e86c5da71bf\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\d61b688a96834769253c71a6\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\d61b688a96834769253c71a6\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\d61b688a96834769253c71a6\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\dca8684c7c5f42261496b6a0\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\dca8684c7c5f42261496b6a0\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\dca8684c7c5f42261496b6a0\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\ddce03a06d2c4f43ef07bf9a\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\ddce03a06d2c4f43ef07bf9a\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\ddce03a06d2c4f43ef07bf9a\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\ddce03a06d2c4f43ef07bf9a\Owner
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\de2f09711e1f4a4220467696\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\de2f09711e1f4a4220467696\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\de2f09711e1f4a4220467696\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\decd49bdcaea44033295a1bd\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\decd49bdcaea44033295a1bd\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\decd49bdcaea44033295a1bd\#name

rainshield
2007-12-07, 07:34
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\decd49bdcaea44033295a1bd\Owner
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\f1703e0251f54afc0be5f08e\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\f1703e0251f54afc0be5f08e\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\f1703e0251f54afc0be5f08e\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\f3efbe7d74254001a956169f\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\f3efbe7d74254001a956169f\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\f3efbe7d74254001a956169f\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\f50a6ca4af8a49b6d9d6bfaf\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\f50a6ca4af8a49b6d9d6bfaf\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\f50a6ca4af8a49b6d9d6bfaf\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\f50a6ca4af8a49b6d9d6bfaf\Owner
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\f7870764233b46354c98b8bc\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\f7870764233b46354c98b8bc\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\f7870764233b46354c98b8bc\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\f9ddbacb51034159089eeca0\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\f9ddbacb51034159089eeca0\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\f9ddbacb51034159089eeca0\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\fa3d80311cb44ff670a8f498\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\fa3d80311cb44ff670a8f498\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\79e8ab1807404eb1169a18a2\fa3d80311cb44ff670a8f498\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\8ca3239c7db644d44ed0d7b3\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\8ca3239c7db644d44ed0d7b3\351bacf25461493c8cb71da2\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\8ca3239c7db644d44ed0d7b3\351bacf25461493c8cb71da2\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\8ca3239c7db644d44ed0d7b3\351bacf25461493c8cb71da2\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\8ca3239c7db644d44ed0d7b3\999755b07e7048c2cff60f8c\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\8ca3239c7db644d44ed0d7b3\999755b07e7048c2cff60f8c\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\8ca3239c7db644d44ed0d7b3\999755b07e7048c2cff60f8c\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\8ca3239c7db644d44ed0d7b3\d4857b4a087f4cba6dc0d6b2\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\8ca3239c7db644d44ed0d7b3\d4857b4a087f4cba6dc0d6b2\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\8ca3239c7db644d44ed0d7b3\d4857b4a087f4cba6dc0d6b2\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\9faec3f2cbd24009a8154eaf\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\9faec3f2cbd24009a8154eaf\04482d152e6c43133d818a85\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\9faec3f2cbd24009a8154eaf\04482d152e6c43133d818a85\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\9faec3f2cbd24009a8154eaf\04482d152e6c43133d818a85\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\9faec3f2cbd24009a8154eaf\1908d57edc9c4757e4bf4daa\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\9faec3f2cbd24009a8154eaf\1908d57edc9c4757e4bf4daa\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\9faec3f2cbd24009a8154eaf\1908d57edc9c4757e4bf4daa\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\9faec3f2cbd24009a8154eaf\217a7caf553e40f56a4770b8\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\9faec3f2cbd24009a8154eaf\217a7caf553e40f56a4770b8\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\9faec3f2cbd24009a8154eaf\217a7caf553e40f56a4770b8\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\9faec3f2cbd24009a8154eaf\2e8740ee71e94c35a9b3b081\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\9faec3f2cbd24009a8154eaf\2e8740ee71e94c35a9b3b081\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\100be8acfde94d05f8f42288\9faec3f2cbd24009a8154eaf\2e8740ee71e94c35a9b3b081\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\048c01efc2c64cb028eb5cac\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\048c01efc2c64cb028eb5cac\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\09c6a64db1ea43c29e57409a\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\09c6a64db1ea43c29e57409a\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\15bc9b88cc1f461705f34b93\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\15bc9b88cc1f461705f34b93\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\22db6651476e44bacc9acaac\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\22db6651476e44bacc9acaac\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\2ab122e5d87f4f318077ac9e\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\2ab122e5d87f4f318077ac9e\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\2d802fa9cdd5451baea9a480\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\2d802fa9cdd5451baea9a480\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\2ef3983e690346ee1b31beb2\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\2ef3983e690346ee1b31beb2\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\3342b9e871e640b8f87af393\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\3342b9e871e640b8f87af393\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\3c1376034b1d491427b4899e\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\3c1376034b1d491427b4899e\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\3e9729b3d3f240bf0710f6ae\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\3e9729b3d3f240bf0710f6ae\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\40ecbfb94d3b4b134441e98e\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\40ecbfb94d3b4b134441e98e\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\46b4892edc33426dd669ba95\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\46b4892edc33426dd669ba95\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\4cc0c53f1e8c465a10662dac\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\4cc0c53f1e8c465a10662dac\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\503b606c24ed41f8bd0d7aac\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\503b606c24ed41f8bd0d7aac\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\525dd56264904aae6d5d06a2\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\525dd56264904aae6d5d06a2\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\54349ad626ed490b715b7a9b\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\54349ad626ed490b715b7a9b\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\568d6e0aff394cf8432fb9b2\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\568d6e0aff394cf8432fb9b2\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\5a790306cc784cd4aea28094\#internal

rainshield
2007-12-07, 07:35
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\5a790306cc784cd4aea28094\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\5d36247d1c8b44ce1e10bea5\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\5d36247d1c8b44ce1e10bea5\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\5dad24a6f8a649ab9303bf80\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\5dad24a6f8a649ab9303bf80\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\61cef268d6ff4c90c9975090\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\61cef268d6ff4c90c9975090\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\669135c1e302475988e3d7a7\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\669135c1e302475988e3d7a7\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\6d7ba912cc214ffe65796081\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\6d7ba912cc214ffe65796081\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\6ea08637aed945d185539eb5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\6ea08637aed945d185539eb5\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\6f095bf442a5485d9076058f\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\6f095bf442a5485d9076058f\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\70f0265283234d91980a3da2\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\70f0265283234d91980a3da2\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\7613ee957964488ed70595a7\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\7613ee957964488ed70595a7\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\7e9a2ee631c8474a40156a8f\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\7e9a2ee631c8474a40156a8f\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\820741bb8df849af4d1041a5\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\820741bb8df849af4d1041a5\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\86b7b9a71da64bfbba972987\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\86b7b9a71da64bfbba972987\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\8742659b6f9b42b528dc3682\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\8742659b6f9b42b528dc3682\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\879930e1615c4e5e5c295396\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\879930e1615c4e5e5c295396\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\88693e58948246d450d6c082\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\88693e58948246d450d6c082\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\8886d009272a4d5305d0a495\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\8886d009272a4d5305d0a495\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\889ad8232b0c4b1fc649cc81\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\889ad8232b0c4b1fc649cc81\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\889ad8232b0c4b1fc649cc81\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\8a9282a8419d423bc17d328b\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\8a9282a8419d423bc17d328b\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\8a9282a8419d423bc17d328b\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\8c2d11ea25c24f1b6c769085\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\8c2d11ea25c24f1b6c769085\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\991b92a76d12461ca82a65b6\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\991b92a76d12461ca82a65b6\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\9bad51810ae4478c364ac1b1\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\9bad51810ae4478c364ac1b1\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\9e7d2709fc844acb2d68a6bd\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\9e7d2709fc844acb2d68a6bd\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\9e7d2709fc844acb2d68a6bd\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\a47264b827d04fdb4db3a29e\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\a47264b827d04fdb4db3a29e\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\a4fdb950e7fc4d56a13fff8c\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\a4fdb950e7fc4d56a13fff8c\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\a784e9637a604c760495d087\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\a784e9637a604c760495d087\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\a7d1e602e45e41734f18149c\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\a7d1e602e45e41734f18149c\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\abf381abd6604f4f0e5f53a5\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\abf381abd6604f4f0e5f53a5\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\b302b1cee9b54179fdcf5ca3\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\b302b1cee9b54179fdcf5ca3\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\e2cdef08a3764bef1e9b2ca6\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\e2cdef08a3764bef1e9b2ca6\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\ec8a869ae58e41a82c2bea88\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\ec8a869ae58e41a82c2bea88\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\eed03af9f9db4fea59a640a3\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\eed03af9f9db4fea59a640a3\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\f8d0c21c591e40565ddf4594\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\23bf22c85e7649cea9655ca2\f8d0c21c591e40565ddf4594\#startup

rainshield
2007-12-07, 07:36
C:\Program Files\winantispyware 2007\scanlog.xml
C:\Program Files\WinAntiSpyware 2007\settings.ini
C:\Program Files\winantispyware 2007\shellext.dll
C:\Program Files\winantispyware 2007\shellext.xml
C:\Program Files\winantispyware 2007\sr.log
C:\Program Files\winantispyware 2007\Summary.dat
C:\Program Files\winantispyware 2007\support.url
C:\Program Files\WinAntiSpyware 2007\tasks.dat
C:\Program Files\WinAntiSpyware 2007\threatnet.dat
C:\Program Files\winantispyware 2007\threatnet.ini
C:\Program Files\WinAntiSpyware 2007\unins000.dat
C:\Program Files\WinAntiSpyware 2007\unins000.exe
C:\Program Files\winantispyware 2007\uninstall.ico
C:\Program Files\WinAntiSpyware 2007\UnWizard.exe
C:\Program Files\winantispyware 2007\unwizard.xml
C:\Program Files\winantispyware 2007\up.dat
C:\Program Files\WinAntiSpyware 2007\updater.dat
C:\Program Files\winantispyware 2007\was7.exe
C:\Program Files\WinAntiSpyware 2007\WAS7.url
C:\Program Files\WinAntiSpyware 2007\WAS7.xml
C:\Program Files\WinBudget
C:\Program Files\wnsxs~1
C:\Program Files\wnsxs~1\j?vaw.exe
C:\Program Files\wnsxs~1\w?aclt.exe
C:\temp\17o7
C:\temp\17o7\tmpTF.log
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\temp\tn3
C:\Temp\xOe
C:\Temp\xOe\tOasF.log
C:\WINDOWS\.exe
C:\WINDOWS\awurpq.dll
C:\WINDOWS\b103.exe
C:\WINDOWS\b104.exe
C:\WINDOWS\b129.exe
C:\WINDOWS\b138.exe
C:\WINDOWS\b147.exe
C:\WINDOWS\cbyvww.dll
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\UDC6_0001_D19M1908NetInstaller.exe
C:\WINDOWS\Downloaded Program Files\UERT_0001_D19M2109NetInstaller.exe
C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N91M1807NetInstaller.exe
C:\WINDOWS\Downloaded Program Files\UWAS6_0001_N91M1508NetInstaller.exe
C:\WINDOWS\Fonts\acrsecI.fon
C:\WINDOWS\IA
C:\WINDOWS\IA\asappsrv.dll
C:\WINDOWS\IA\command.exe
C:\WINDOWS\IA\KE.vbs
C:\WINDOWS\monterreya_unknown.exe
C:\WINDOWS\msresearch1.dat
C:\WINDOWS\ppatch~1
C:\WINDOWS\ppatch~1\??pPatch\
C:\WINDOWS\ppatch~1\iexplore.exe
C:\WINDOWS\qpruwa.ini
C:\WINDOWS\stem32~1
C:\WINDOWS\stem32~1\?poolsv.exe
C:\WINDOWS\svchost.com
C:\WINDOWS\svhost.exe
C:\WINDOWS\system\ntp2.ini
C:\WINDOWS\system32\abuyckrh.dll
C:\WINDOWS\system32\ackcrcyh.dll
C:\WINDOWS\system32\algnccas.dll
C:\WINDOWS\system32\amjajnnj.exe
C:\WINDOWS\system32\aonapyya.dll
C:\WINDOWS\system32\awiqrgwb.dll
C:\WINDOWS\system32\awtqqpp.dll
C:\WINDOWS\system32\ayypanoa.ini
C:\WINDOWS\system32\bglwraet.dll
C:\WINDOWS\system32\bwidqntq.dll
C:\WINDOWS\system32\cbdomevg.dll
C:\WINDOWS\system32\chrhhvjp.dll
C:\WINDOWS\system32\config\system~1\applic~1\install.dat
C:\WINDOWS\system32\config\systemprofile\Application Data\install.dat
C:\WINDOWS\system32\cxncahhk.dll
C:\WINDOWS\system32\dbemtvnm.dll
C:\WINDOWS\system32\ddcbxuu.dll
C:\WINDOWS\system32\deqceplx.dll
C:\WINDOWS\system32\dlpkefco.ini
C:\WINDOWS\system32\duqeamoa.exe
C:\WINDOWS\system32\enrwjnhp.dll
C:\WINDOWS\system32\ewsiuigu.dll
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\f02WtR\f02WtR1065.exe
C:\WINDOWS\system32\fklfpryc.dll
C:\WINDOWS\system32\fkrhrrpu.dll
C:\WINDOWS\system32\fvgtcvnk.dll
C:\WINDOWS\system32\fysasyeo.dll
C:\WINDOWS\system32\gcnpaiax.dll
C:\WINDOWS\system32\gebawwx.dll
C:\WINDOWS\system32\ghdtgqmm.exe
C:\WINDOWS\system32\hggdbaa.dll
C:\WINDOWS\system32\hiuoalsn.dll
C:\WINDOWS\system32\hnknwmse.dll
C:\WINDOWS\system32\iifeeeb.dll
C:\WINDOWS\system32\jisalexq.dll
C:\WINDOWS\system32\jwrmffdm.dll
C:\WINDOWS\system32\kfqqbwky.dll
C:\WINDOWS\system32\kfwxorel.dll
C:\WINDOWS\system32\ktbehtdy.exe
C:\WINDOWS\system32\legyhmpf.dll
C:\WINDOWS\system32\llkkj.bak1
C:\WINDOWS\system32\llkkj.bak2
C:\WINDOWS\system32\llkkj.ini
C:\WINDOWS\system32\llkkj.ini2
C:\WINDOWS\system32\llkkj.tmp
C:\WINDOWS\system32\ltehjbbg.dll
C:\WINDOWS\system32\mcswlvnp.dll
C:\WINDOWS\system32\mecxjilg.dll
C:\WINDOWS\system32\mljhfgd.dll
C:\WINDOWS\system32\mqpbnosv.dll
C:\WINDOWS\system32\mxtskoql.exe
C:\WINDOWS\system32\ndrfburp.dll
C:\WINDOWS\system32\ngyojgcr.dll
C:\WINDOWS\system32\nqeyilrb.dll
C:\WINDOWS\system32\oannas.dll
C:\WINDOWS\system32\ocahgejs.dll
C:\WINDOWS\system32\ocfekpld.dll
C:\WINDOWS\system32\ofbgkiel.dll
C:\WINDOWS\system32\okuptjhy.dll
C:\WINDOWS\system32\ontchxje.exe
C:\WINDOWS\system32\osbmuhmu.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pbriwvxo.dll
C:\WINDOWS\system32\pjvhhrhc.ini
C:\WINDOWS\system32\pwegomty.dll
C:\WINDOWS\system32\qjbgxmrn.exe
C:\WINDOWS\system32\qrjcdbvq.dll
C:\WINDOWS\system32\qwqjekhc.dll
C:\WINDOWS\system32\raaetlwn.dll
C:\WINDOWS\system32\rlcldwmx.dll
C:\WINDOWS\system32\rmrjlnmb.dll
C:\WINDOWS\system32\rtamrbtr.ini
C:\WINDOWS\system32\rtbrmatr.dll
C:\WINDOWS\system32\ruvvgcbu.dll
C:\WINDOWS\system32\scurit~1
C:\WINDOWS\system32\scurit~1\s?curity\
C:\WINDOWS\system32\scurit~1\wuaclt.exe
C:\WINDOWS\system32\soowlefo.dll
C:\WINDOWS\system32\srlixqmj.exe
C:\WINDOWS\system32\ssqppop.dll
C:\WINDOWS\system32\swinkods.exe
C:\WINDOWS\system32\swinkodt.exe
C:\WINDOWS\system32\sxlturij.dll
C:\WINDOWS\system32\teitlenv.dll
C:\WINDOWS\system32\tuvwxus.dll
C:\WINDOWS\system32\uelmlmoc.dll
C:\WINDOWS\system32\umhumbso.ini
C:\WINDOWS\system32\unbhmdov.exe
C:\WINDOWS\system32\vcambqjf.dll
C:\WINDOWS\system32\vMW10a
C:\WINDOWS\system32\vMW10a\vMW10a1099.exe
C:\WINDOWS\system32\vtyutjhp.dll
C:\WINDOWS\system32\wcosejnh.dll
C:\WINDOWS\system32\wcpsvtr.exe
C:\WINDOWS\system32\wiuhkdeh.exe
C:\WINDOWS\system32\wvoewckx.ini
C:\WINDOWS\system32\wvuuusp.dll
C:\WINDOWS\system32\xkcweovw.dll
C:\WINDOWS\system32\xmawbydc.dll
C:\WINDOWS\system32\xmwdlclr.ini
C:\WINDOWS\system32\yaealivv.dll
C:\WINDOWS\system32\ybdvjgcn.dll
C:\WINDOWS\system32\yuuwqenk.dll
C:\WINDOWS\tk58.exe
C:\WINDOWS\tsitra77.exe
C:\WINDOWS\wwvybc.ini
C:\windows\xpupdate.exe
C:\WINDOWS\ymbols~1

rainshield
2007-12-07, 07:36
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_CMDSERVICE
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_NETWORK_MONITOR
-------\DomainService




((((((((((((((((((((((((( Files Created from 2007-11-06 to 2007-12-06 )))))))))))))))))))))))))))))))
.

2007-12-06 11:47 . 2007-12-06 11:49 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-12-06 11:47 . 2007-12-06 11:47 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2007-12-06 11:47 . 2007-12-06 11:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-06 11:45 . 2007-12-06 11:45 <DIR> d-------- C:\Program Files\CCleaner
2007-12-06 10:53 . 2007-12-06 10:53 74,304 --a------ C:\WINDOWS\system32\djtkdrcw.exe
2007-12-05 17:39 . 2007-12-06 10:53 807,528 ---hs---- C:\WINDOWS\system32\xdcmtxhf.ini
2007-12-05 17:36 . 2007-12-05 17:36 74,304 --a------ C:\WINDOWS\system32\onbsnade.exe
2007-12-05 12:44 . 2007-12-05 12:44 74,304 --a------ C:\WINDOWS\system32\vbdicggu.exe
2007-12-05 03:45 . 2004-01-26 05:10 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2007-12-05 03:45 . 2005-08-01 15:59 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2007-12-05 03:45 . 2005-08-01 15:51 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Yahoo! Messenger
2007-12-05 03:45 . 2005-09-12 22:13 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Yahoo!
2007-12-05 03:45 . 2005-12-04 02:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Ventrilo
2007-12-05 03:45 . 2004-01-27 02:21 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2007-12-05 03:45 . 2004-01-26 04:28 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2007-12-05 03:45 . 2006-01-30 16:11 <DIR> dr-h----- C:\Documents and Settings\Administrator\Application Data\SecuROM
2007-12-05 03:45 . 2004-01-26 05:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2007-12-05 03:45 . 2005-12-05 15:58 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Motive
2007-12-05 03:45 . 2005-08-16 23:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Kazaa Lite
2007-12-05 03:45 . 2004-01-27 02:26 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\interMute
2007-12-05 03:45 . 2005-08-20 20:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\FotoWire
2007-12-05 03:45 . 2005-10-22 11:54 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Aim
2007-12-05 03:45 . 2005-09-15 09:45 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AdobeUM
2007-12-05 03:45 . 2005-10-31 18:05 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\.bt2
2007-12-05 03:45 . 2005-10-09 02:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\.BitTornado
2007-12-04 23:46 . 2007-12-05 12:43 2,076,049 ---hs---- C:\WINDOWS\system32\lrfojqbb.ini
2007-12-04 23:21 . 2007-12-04 23:21 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-04 23:21 . 2007-12-04 23:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-04 23:02 . 2007-12-04 23:02 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-04 22:46 . 2007-12-04 23:44 1,471,158 ---hs---- C:\WINDOWS\system32\cjynxpts.ini
2007-12-04 22:42 . 2004-05-27 18:53 237,568 -ra------ C:\WINDOWS\system32\SiSWPars.dll
2007-12-04 22:42 . 2004-05-27 18:53 155,648 -ra------ C:\WINDOWS\system32\SiSWInst.dll
2007-12-04 22:42 . 2004-05-27 19:49 154,112 -ra------ C:\WINDOWS\system32\drivers\sis162u.sys
2007-12-04 22:42 . 2004-05-27 18:53 49,152 -ra------ C:\WINDOWS\system32\SiSWBase.dll
2007-12-04 15:10 . 2007-12-04 22:38 848,777 ---hs---- C:\WINDOWS\system32\mkwhomsv.ini
2007-12-03 15:32 . 2007-12-04 15:05 794,770 ---hs---- C:\WINDOWS\system32\ulbmfrpa.ini
2007-12-02 21:35 . 2007-12-03 15:30 794,325 ---hs---- C:\WINDOWS\system32\exmkqfsi.ini
2007-12-01 23:58 . 2007-12-01 23:59 <DIR> d-------- C:\Program Files\7-Zip
2007-12-01 23:08 . 2007-12-01 23:08 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-12-01 23:08 . 2007-12-01 23:08 268 --ah----- C:\sqmdata03.sqm
2007-12-01 23:08 . 2007-12-01 23:08 244 --ah----- C:\sqmnoopt03.sqm
2007-12-01 21:27 . 2007-12-02 21:30 794,205 ---hs---- C:\WINDOWS\system32\eqvioqie.ini
2007-11-30 14:16 . 2007-11-30 14:16 2,238 --a------ C:\WINDOWS\system32\GClogo_32x32.ico
2007-11-30 11:10 . 2007-12-01 21:22 794,085 ---hs---- C:\WINDOWS\system32\vpgxequf.ini
2007-11-29 21:42 . 2007-11-30 11:02 789,960 ---hs---- C:\WINDOWS\system32\yidiauvd.ini
2007-11-26 16:05 . 2007-11-30 13:43 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Avant Profiles

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-06 19:46 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-02 07:07 --------- d-----w C:\Program Files\MSN Messenger
2007-11-30 23:12 --------- d-----w C:\Program Files\Starcraft
2007-10-19 08:46 --------- d-----w C:\Program Files\Avant Browser
2007-10-19 03:43 --------- d-----w C:\Program Files\Norton AntiVirus
2007-10-19 01:51 --------- d-----w C:\Documents and Settings\Owner\Application Data\Avant Browser
2007-10-08 06:05 --------- d-----w C:\Program Files\LD-Anime
2007-09-23 11:17 15,360 ----a-w C:\sysfzwv.exe
2007-09-23 07:25 7,806 ----a-w C:\syssylo.exe
2007-09-19 06:14 15,360 ----a-w C:\WINDOWS\twain.exe
2007-09-19 06:14 15,360 ----a-w C:\sysinoo.exe
2007-09-02 10:50 304,453 ----a-w C:\Documents and Settings\Owner\mcc.exe
2007-09-02 06:01 160,768 ----a-w C:\Documents and Settings\Owner\gotgo.exe
2006-09-25 23:35 29,184 ----a-w C:\Documents and Settings\Owner\jrqxdwnw.exe
2005-11-22 21:24 477,746 ----a-w C:\Documents and Settings\Default User\Application Data\Sskknwrd.dll
2006-01-02 08:03 300,760 --sh--w C:\WINDOWS\mshostsr.exe
1989-12-12 16:10 404,208 --sh--r C:\WINDOWS\orqeenq.exe
2006-02-23 07:31 19,456 --sh--r C:\WINDOWS\system\svchost.dll
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 144,384 2007-09-02 06:04:14 C:\hp\KBD\bak\KBD.EXE
----a-w 2,840,064 2007-12-06 18:52:50 C:\hp\KBD\kbd.exe

----a-w 61,440 2004-04-27 22:18:34 C:\Program Files\AIM\bak\aim.exe
----a-w 61,440 2004-06-07 20:53:12 C:\Program Files\AIM\aim.exe

----a-w 155,648 2006-01-12 23:40:44 C:\Program Files\Common Files\Ahead\Lib\bak\NeroCheck.exe
----a-w 36,927 2007-03-07 07:36:59 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

----a-w 139,264 2006-11-17 03:04:20 C:\Program Files\Common Files\Ahead\Lib\bak\NMBgMonitor.exe
----a-w 36,927 2007-03-07 07:36:59 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

----a-w 151,597 2004-01-26 12:29:51 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe
----a-w 151,597 2004-01-26 12:29:51 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

----a-w 9,216 2006-07-19 22:56:46 C:\Program Files\Common Files\rqzi\bak\rqzim.exe
----a-w 9,216 2006-07-19 21:56:46 C:\Program Files\Common Files\rqzi\rqzim.exe

----a-w 110,592 2003-08-19 16:01:00 C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe
----a-w 110,592 2003-08-19 16:01:00 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe

----a-w 49,152 2003-08-21 11:23:08 C:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe
----a-w 49,152 2003-08-21 11:23:08 C:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe

----a-w 32,881 2004-01-26 10:24:04 C:\Program Files\Java\j2re1.4.2_03\bin\bak\jusched.exe
----a-w 32,881 2004-01-26 10:24:04 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

----a-w 53,248 2003-12-11 09:40:20 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\bak\mmtask.exe
----a-w 53,248 2003-12-11 09:40:20 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

----a-w 35,328 2006-11-21 17:38:22 C:\Program Files\Winamp\bak\winampa.exe
----a-w 24,080 2007-08-22 01:10:59 C:\Program Files\Winamp\winampa.exe

----a-w 72,704 2007-03-03 11:18:06 C:\qoobox\Quarantine\C\Documents and Settings\Owner\My Documents\DOBE~1\bak\winword.exe.vir
----a-w 70,144 2007-03-10 07:16:07 C:\qoobox\Quarantine\C\Documents and Settings\Owner\My Documents\DOBE~1\winword.exe.vir

----a-w 39,424 2007-08-19 21:58:06 C:\WINDOWS\bak\retadpu77.exe

----a-w 118,784 2003-12-18 07:31:42 C:\WINDOWS\CREATOR\bak\Remind_XP.exe
----a-w 118,784 2003-12-18 07:31:42 C:\WINDOWS\CREATOR\Remind_XP.exe

rainshield
2007-12-07, 07:37
----a-w 221,184 2003-11-04 00:50:40 C:\WINDOWS\SMINST\bak\RECGUARD.EXE
----a-w 221,184 2003-11-04 00:50:40 C:\WINDOWS\SMINST\Recguard.exe

----a-w 52,736 1998-05-08 00:04:38 C:\WINDOWS\system\bak\hpsysdrv.exe
----a-w 52,736 1998-05-08 00:04:38 C:\WINDOWS\system\hpsysdrv.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95CB3857-A0E7-F21B-EE5B-FD8A45862C97}]
C:\WINDOWS\System32\cnsi.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RecordNow!"="" []
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-03-28 14:10]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" []
"Notn"="C:\WINDOWS\System32\SCURIT~1\wuaclt.exe" []
"Omht"="C:\WINDOWS\??stem32\?poolsv.exe" [2003-08-15 18:40]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
"rnokq"="C:\WINDOWS\System32\vadqpv.exe" [2007-09-02 02:31]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-01-26 02:24]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 16:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-11-18 07:11]
"HPHUPD05"="c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 03:23]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-08-21 03:15]
"KBD"="C:\HP\KBD\KBD.EXE" [2007-12-06 10:52]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 08:01]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-01-26 04:29]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2003-11-03 16:50]
"VTTimer"=" " []
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 00:59]
"LTMSG"="LTMSG.exe" [2003-07-14 17:52 C:\WINDOWS\ltmsg.exe]
"PS2"=" " []
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-03 20:35 C:\WINDOWS\ALCXMNTR.EXE]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe" [2003-03-12 04:23]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-03-28 14:10]
"Cabal_GSP"="C:\WINDOWS\twain.exe" [2007-09-18 22:14]
"QuickTime Task"="C:\PROGRA~1\QUICKT~1\qttask.exe" [2007-09-24 23:37]
"uqhiot"="C:\WINDOWS\System32\vadqpv.exe" [2007-09-02 02:31]

C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSub.exe [2004-01-27 02:26:18]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSub.exe [2004-01-27 02:26:18]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-01-26 05:20:47]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 12:19:24]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-01-19 00:44:15]
palstart.exe [2005-12-15 22:38:01]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2003-07-30 04:49:48]
SBC Self Support Tool.lnk - C:\Program Files\SBC Self Support Tool\bin\matcli.exe [2006-07-11 13:16:00]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


.
Contents of the 'Scheduled Tasks' folder
"2007-10-19 00:33:48 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-06 12:42:56
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

C:\WINDOWS\system32\vadqpv.exe [1092] 0x821492D8
C:\WINDOWS\system32\mjtup.exe [1124] 0x8205D020
C:\WINDOWS\system32\mjtup.exe [1172] 0x821CF020
C:\WINDOWS\system32\mjtup.exe [1180] 0x81FE5348
scanning hidden autostart entries ...

scanning hidden files ...

C:\WINDOWS\tukxg.dll 887 bytes
C:\WINDOWS\system32\mjtup.exe 28672 bytes executable
C:\WINDOWS\system32\chdqger.dll 51712 bytes executable
C:\WINDOWS\system32\vadqpv.exe 127488 bytes executable
C:\WINDOWS\system32\webyach.exe 23552 bytes executable

scan completed successfully
hidden files: 5

**************************************************************************
.
Completion time: 2007-12-06 12:50:40 - machine was rebooted
.
--- E O F ---

rainshield
2007-12-07, 07:39
And here is the SAS log:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/06/2007 at 02:09 PM

Application Version : 3.9.1008

Core Rules Database Version : 3356
Trace Rules Database Version: 1355

Scan type : Complete Scan
Total Scan Time : 01:14:03

Memory items scanned : 425
Memory threats detected : 3
Registry items scanned : 5442
Registry threats detected : 3
File items scanned : 59356
File threats detected : 3819

Adware.WebNexus
C:\WINDOWS\SYSTEM32\CHDQGER.DLL
C:\WINDOWS\SYSTEM32\CHDQGER.DLL

Trojan.Downloader-Twain/Fake
C:\WINDOWS\TWAIN.EXE
C:\WINDOWS\TWAIN.EXE
[Cabal_GSP] C:\WINDOWS\TWAIN.EXE
C:\WINDOWS\Prefetch\TWAIN.EXE-06097ADF.pf

Adware.PalTalk
C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\STARTUP\PALSTART.EXE
C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\STARTUP\PALSTART.EXE
C:\WINDOWS\Prefetch\PALSTART.EXE-075D37F7.pf

Adware.Qoologic/QoolAid
[uqhiot] C:\WINDOWS\SYSTEM32\VADQPV.EXE
C:\WINDOWS\SYSTEM32\VADQPV.EXE
[rnokq] C:\WINDOWS\SYSTEM32\VADQPV.EXE
C:\QOOBOX\QUARANTINE\C\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\STARTUP\NHPRV.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\BWRTB.DAT.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP45\A0020921.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP50\A0034126.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP50\A0035116.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP55\A0036704.EXE
C:\WINDOWS\SYSTEM32\MJTUP.EXE
C:\WINDOWS\SYSTEM32\WEBYACH.EXE

Adware.Tracking Cookie
C:\Documents and Settings\Owner\Cookies\owner@ad.outerinfoads[6].txt
C:\Documents and Settings\Owner\Cookies\owner@advertising[13].txt
C:\Documents and Settings\Owner\Cookies\owner@media.adrevolver[3].txt
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[13].txt
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[12].txt
C:\Documents and Settings\Owner\Cookies\owner@statcounter[11].txt
C:\Documents and Settings\Owner\Cookies\owner@2o7[11].txt
C:\Documents and Settings\Owner\Cookies\owner@eas.apm.emediate[3].txt
C:\Documents and Settings\Owner\Cookies\owner@adlegend[9].txt
C:\Documents and Settings\Owner\Cookies\owner@richmedia.yahoo[3].txt
C:\Documents and Settings\Owner\Cookies\owner@revsci[13].txt
C:\Documents and Settings\Owner\Cookies\owner@atdmt[13].txt
C:\Documents and Settings\Owner\Cookies\owner@adinterax[10].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[26].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[23].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.pointroll[8].txt
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[13].txt
C:\Documents and Settings\Owner\Cookies\owner@atwola[12].txt
C:\Documents and Settings\Owner\Cookies\owner@overture[12].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[12].txt
C:\Documents and Settings\Administrator\Cookies\owner@1.primaryads[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@247realmedia[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@247realmedia[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@247realmedia[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@247realmedia[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@2o7[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@2o7[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@2o7[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@2o7[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@2o7[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@2o7[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@2o7[8].txt
C:\Documents and Settings\Administrator\Cookies\owner@a.websponsors[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@a.websponsors[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@a.websponsors[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@a.websponsors[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@a.websponsors[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad-cross.co[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad-cross.co[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad-indicator[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad.admarketplace[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad.admarketplace[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad.jamster[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad.reunion[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad.yieldmanager[10].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad.yieldmanager[11].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad.yieldmanager[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad.yieldmanager[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad.yieldmanager[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad.yieldmanager[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad.yieldmanager[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad.yieldmanager[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad.yieldmanager[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad.yieldmanager[9].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad.zanox[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad1.clickhype[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ad2.pamedia.com[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@adbrite[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@addynamix[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@adecn[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@adecn[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@adecn[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@adecn[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@adknowledge[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@adknowledge[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@adknowledge[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@adknowledge[4].txt

rainshield
2007-12-07, 07:39
C:\Documents and Settings\Administrator\Cookies\owner@adknowledge[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@adknowledge[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@adlegend[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@admarketplace[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@adopt.hbmediapro[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@adopt.hbmediapro[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@adopt.hbmediapro[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@adopt.hbmediapro[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@adopt.hbmediapro[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@adopt.hbmediapro[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@adopt.hbmediapro[8].txt
C:\Documents and Settings\Administrator\Cookies\owner@adopt.hotbar[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@adopt.hotbar[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@adopt.hotbar[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@adopt.hotbar[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@adopt.hotbar[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@adopt.specificclick[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@adopt.specificclick[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@adopt.specificclick[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@adopt.specificclick[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@adopt.specificclick[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@adopt.specificclick[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@adprofile[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@adprofile[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@adprofile[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@adrevolver[10].txt
C:\Documents and Settings\Administrator\Cookies\owner@adrevolver[11].txt
C:\Documents and Settings\Administrator\Cookies\owner@adrevolver[12].txt
C:\Documents and Settings\Administrator\Cookies\owner@adrevolver[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@adrevolver[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@adrevolver[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@adrevolver[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@adrevolver[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@adrevolver[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@adrevolver[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@adrevolver[8].txt
C:\Documents and Settings\Administrator\Cookies\owner@adrevolver[9].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.addynamix[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.addynamix[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.addynamix[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.addynamix[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.addynamix[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.addynamix[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.addynamix[8].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.as4x.tmcs[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.cc214142[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.cc214142[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.cc214142[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.digitalpoint[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.digitalpoint[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.digitalpoint[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.i-am-bored[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.monster[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.monster[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.pointroll[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.pointroll[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.pointroll[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.pointroll[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.pointroll[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.pointroll[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.pwcr[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.realcastmedia[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.realcastmedia[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.realcastmedia[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.us.e-planning[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads.us.e-planning[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads1.megaupload[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads1.megaupload[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads1.playforum[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ads1.revenue[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@adserver.adreactor[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@adserver.adreactor[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@adserver.adreactor[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@adserver.adremedy[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@adserver.filefront[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@adserver.filefront[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@adserver.filefront[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@adserver.filefront[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@adserver.mpogonline[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@adserver.rdtg[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@adserver.sharewareonline[1].txt

rainshield
2007-12-07, 07:40
C:\Documents and Settings\Administrator\Cookies\owner@adserver[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@adstat.4u[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@adtech[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@adtrak[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@adultbouncer[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@adultbouncer[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@adultfriendfinder[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@adultfriendfinder[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@advertising[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@advertising[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@advertising[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@advertising[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@advertising[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@advertising[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@advertising[8].txt
C:\Documents and Settings\Administrator\Cookies\owner@apmebf[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@apmebf[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@apmebf[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@apmebf[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@apmebf[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@ar.atwola[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ar.atwola[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ar.atwola[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@ar.atwola[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@as-eu.falkag[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@as-eu.falkag[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@as-eu.falkag[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@as-eu.falkag[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@as-us.falkag[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@as-us.falkag[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@as-us.falkag[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@as-us.falkag[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@as-us.falkag[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@as-us.falkag[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@as-us.falkag[8].txt
C:\Documents and Settings\Administrator\Cookies\owner@as1.falkag[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@as1.falkag[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@as1.falkag[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@as1.falkag[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@as1.falkag[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@as1.falkag[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@atdmt[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@atdmt[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@atdmt[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@atdmt[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@atdmt[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@atdmt[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@atdmt[8].txt
C:\Documents and Settings\Administrator\Cookies\owner@ath.belnk[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ath.belnk[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ath.belnk[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@atwola[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@atwola[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@atwola[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@atwola[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@atwola[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@atwola[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@atwola[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@azjmp[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@azjmp[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@azjmp[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@azjmp[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@azjmp[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@banner.casinolasvegas[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@banner.goldenpalace[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@bannerspace[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@banners[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@banners[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@banners[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@banners[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@banners[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@banners[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@banner[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@belnk[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@belnk[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@belnk[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@belnk[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@belnk[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@belnk[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@bizrate[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@bluestreak[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@bluestreak[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@bluestreak[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@bluestreak[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@bs.serving-sys[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@bs.serving-sys[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@btg.btgrab[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@burstnet[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@burstnet[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@burstnet[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@burstnet[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@burstnet[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@buycom.122.2o7[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@c.enhance[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@c.enhance[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@c.enhance[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@c.enhance[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@c.goclick[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@c4.zedo[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@c5.zedo[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@casalemedia[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@casalemedia[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@casalemedia[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@casalemedia[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@casalemedia[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@casalemedia[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@casalemedia[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@casinolasvegas[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@cassava[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@cb.adprofile[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@cb.adprofile[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@centralmedia[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@certified-safe-downloads[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@citi.bridgetrack[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@citi.bridgetrack[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@citi.bridgetrack[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@citi.bridgetrack[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@citi.bridgetrack[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@citi.bridgetrack[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@cityclub.gamingpromo[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@click.revsharecash[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@clickbank[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@clicksor[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@clicktorrent[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@cliks[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@cnn.122.2o7[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@counter-strike-dl[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@counter.hitslink[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@counter1.supercounter[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@counter16.sextracker[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@cpvfeed[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@cpvfeed[2].txt

rainshield
2007-12-07, 07:41
C:\Documents and Settings\Administrator\Cookies\owner@cpvfeed[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@cpvfeed[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@cracks[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@creativeby.viewpoint[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@creativeby.viewpoint[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@creativeby.viewpoint[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@creativeby.viewpoint[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@cs.sexcounter[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@cz3.clickzs[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@cz3.clickzs[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@cz7.clickzs[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@cz8.clickzs[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@data2.perf.overture[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@data4.perf.overture[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@data4.perf.overture[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@dealtime[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@dealtime[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@directtrack[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@dist.belnk[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@dist.belnk[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@dist.belnk[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@dist.belnk[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@dist.belnk[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@dist.belnk[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@doubleclick[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@doubleclick[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@doubleclick[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@doubleclick[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@doubleclick[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@doubleclick[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@doubleclick[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@edge.ru4[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@edge.ru4[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@edge.ru4[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@edge.ru4[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@edge.ru4[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@edge.ru4[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@ehg-adteractive.hitbox[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ehg-adteractive.hitbox[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ehg-ati.hitbox[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ehg-bestbuy.hitbox[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ehg-clearchannel.hitbox[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ehg-communityconnect.hitbox[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ehg-eline.hitbox[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ehg-gamespyinc.hitbox[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ehg-idg.hitbox[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ehg-idgentertainment.hitbox[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ehg-nestleusainc.hitbox[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ehg-streamload.hitbox[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ehg.hitbox[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@elite[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@emarketmakers[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@emarketmakers[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@emarketmakers[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@emarketmakers[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@emarketmakers[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@entrepreneur.122.2o7[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@entrepreneur.122.2o7[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@entrepreneur.122.2o7[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@etype.adbureau[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@exitexchange[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@exitexchange[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@exitexchange[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@exitexchange[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@exitexchange[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@exitexchange[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@experclick[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@ez-tracks[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@eztracks.aavalue[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@fastclick[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@fastclick[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@fastclick[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@fastclick[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@fastclick[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@fastclick[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@fastclick[8].txt
C:\Documents and Settings\Administrator\Cookies\owner@findwhat[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@findwhat[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@fortunecity[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@fortunecity[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@freeze.directtrack[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@funwebproducts[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@gamingpromo[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@goclick[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@goclick[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@gtb1.acecounter[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@gtb2.acecounter[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@gtp1.acecounter[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@h.starware[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@h.starware[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@h.starware[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@hbmediapro[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@hbmediapro[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@hc2.humanclick[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@hc2.humanclick[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@hc2.humanclick[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@hentaicounter[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@hg1.hitbox[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@hitbox[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@hitbox[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@hitbox[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@hitbox[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@hits.clickandtrack[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@hits.clickandtrack[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@hits.clickandtrack[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@hits.clickandtrack[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@hits.clickandtrack[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@hits.clickandtrack[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@hurricanedigitalmedia[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@hurricanedigitalmedia[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@hypertracker[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@hypertracker[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@hypertracker[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@hypertracker[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@hypertracker[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@i.screensavers[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@i.screensavers[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@i.screensavers[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@i.screensavers[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@icc.intellisrv[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@icc.intellisrv[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@icc.intellisrv[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@icc.intellisrv[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@idesktopmedia.directtrack[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@image.masterstats[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@image.masterstats[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@imp.partner2profit[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@interclick[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@interclick[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@interclick[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@interclick[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@internetfuel[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@internetfuel[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@internetfuel[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@jamster[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@jamster[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@jamster[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@kanoodle[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@kanoodle[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@kanoodle[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@kanoodle[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@keywordmax[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@kmpads[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@kmpads[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@leadgenetwork[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@leadgenetwork[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@leadgenetwork[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@leadgenetwork[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@linksynergy[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@linksynergy[3].txt

rainshield
2007-12-07, 07:42
C:\Documents and Settings\Administrator\Cookies\owner@linksynergy[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@login.tracking101[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@login.tracking101[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@lynxtrack[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@maxserving[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@maxserving[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@maxserving[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@maxserving[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@maxserving[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@media.adrevolver[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@media.onlinewelten[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@media.top-banners[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@media2.onlinewelten[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@mediaplex[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@mediaplex[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@mediaplex[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@mediaplex[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@mediaplex[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@mediaplex[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@mediaplex[8].txt
C:\Documents and Settings\Administrator\Cookies\owner@metareward[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@metareward[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@microsofteup.112.2o7[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@microsofteup.112.2o7[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@mmm.media-motor[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@mmm.media-motor[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@moneyjunkey.directtrack[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@msnportal.112.2o7[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@mywebsearch[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@nextag[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@nextag[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@nextag[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@nextag[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@offeroptimizer[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@offeroptimizer[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@offeroptimizer[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@oinadserve[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@onlinerewardcenter[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@onlinerewardcenter[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@onlinerewardcenter[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@onlinerewardcenter[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@onlinerewardcenter[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@overture[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@overture[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@pacificpoker[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@partner2profit[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@partner2profit[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@partygaming.122.2o7[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@partypoker.touchclarity[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@partypoker.touchclarity[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@partypoker[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@partypoker[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@partypoker[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@partypoker[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@partypoker[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@partypoker[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@paycounter[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@paypopup[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@paypopup[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@paypopup[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@perf.overture[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@perf.overture[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@perf.overture[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@perf.overture[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@perf.overture[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@perf.overture[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@perf.overture[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@pornaccess[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@pornaccess[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@pro-market[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@publishers.clickbooth[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@publishers.clickbooth[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@publishers.clickbooth[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@publishers.clickbooth[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@qksrv[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@qksrv[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@qksrv[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@qksrv[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@qksrv[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@qnsr[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@qnsr[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@qnsr[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@qnsr[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@qnsr[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@qnsr[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@qnsr[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@questionmarket[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@questionmarket[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@questionmarket[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@questionmarket[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@questionmarket[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@questionmarket[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@questionmarket[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@realmedia[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@realmedia[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@realmedia[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@realmedia[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@realmedia[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@realmedia[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@realmedia[8].txt
C:\Documents and Settings\Administrator\Cookies\owner@redorbit[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@redorbit[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@reduxads.valuead[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@revenue[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@revenue[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@revenue[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@revenue[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@revenue[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@revenue[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@revsci[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@roiservice[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@roiservice[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@rotator.adjuggler[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@rotator.adjuggler[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@rotator.adjuggler[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@sales.liveperson[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@sav.coolsavings[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@searchbar.findthewebsiteyouneed[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@servedby.advertising[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@servedby.advertising[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@servedby.advertising[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@servedby.advertising[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@servedby.advertising[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@servedby.advertising[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@server.cpmstar[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@server.cpmstar[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@server.cpmstar[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@server.iad.liveperson[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@server.iad.liveperson[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@server.iad.liveperson[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@server.iad.liveperson[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@server.iad.liveperson[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@server.iad.liveperson[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@server2.bkvtrack[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@serving-sys[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@serving-sys[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@serving-sys[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@serving-sys[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@sexole[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@sextalk.sexviet[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@sextalk.sexviet[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@sextalk.sexviet[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@sextracker[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@sexviet[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@sexviet[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@sexviet[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@smileycentral[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@smileycentral[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@soundclick[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@specificclick[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@spylog[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@spylog[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@starware[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@starware[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@starware[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@starware[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@starware[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@stat.dealtime[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@stat.dealtime[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@stat.dealtime[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@stat.onestat[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@statcounter[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@statcounter[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@statcounter[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@statcounter[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@statcounter[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@statcounter[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@statcounter[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@stats1.reliablestats[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@stats1.reliablestats[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@stats1.reliablestats[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@statse.webtrendslive[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@statse.webtrendslive[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@statse.webtrendslive[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@statse.webtrendslive[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@stats[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@stats_[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@superstats[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@sxload[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@tacoda[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@tacoda[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@tacoda[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@tacoda[4].txt

rainshield
2007-12-07, 07:43
C:\Documents and Settings\Administrator\Cookies\owner@tacoda[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@tagworld[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@targetnet[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@targetnet[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@targetnet[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@targetnet[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@targetnet[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@targetnet[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@targetnet[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@toplist[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@tour.splash.sexsearch[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@tour.splash.sexsearch[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@tour.splash.sexsearch[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@tracking[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@tracking[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@tradedoubler[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@tradedoubler[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@tradedoubler[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@tradedoubler[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@tradedoubler[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@tradedoubler[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@trafficdashboard[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@trafficmp[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@trafficmp[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@trafficmp[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@trafficmp[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@trafficmp[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@trafficmp[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@trafficmp[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@trafficmp[8].txt
C:\Documents and Settings\Administrator\Cookies\owner@tribalfusion[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@tribalfusion[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@tribalfusion[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@tribalfusion[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@tribalfusion[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@tribalfusion[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@tribalfusion[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@tripod[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@tripod[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@usenext[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@usenext[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@usenext[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@usenext[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@valueclick[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@valueclick[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@valueclick[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@valueclick[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@valueclick[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@warlog[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@warlog[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@web-nexus[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@web-nexus[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@web-nexus[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@web-nexus[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@web-nexus[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@web2.realtracker[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@webcam.sexole[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@webpower[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@windowsmedia[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@windowsmedia[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@windowsmedia[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@winfixer[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@winfixer[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@winfixer[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@winfixer[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.adserv[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.azoogleads[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.bannersandpopups[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.burstbeacon[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.burstbeacon[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.burstbeacon[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.burstbeacon[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.burstnet[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.clickedyclick[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.coolcounters[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.coolcounters[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.entrepreneur[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.entrepreneur[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.ez-tracks[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.findthewebsiteyouneed[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.glispatrack[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.penisbot[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.redorbit[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.screensavers[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.screensavers[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.screensavers[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.screensavers[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.screensavers[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.sexuploader[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.sexviet[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.sexviet[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.starware[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.starware[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.stopzilla[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.tagworld[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.winantiviruspro[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.winantivirus[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.winfixer[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.xctrk[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.xctrk[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.xctrk[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.zanox-affiliate[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@www.zanox-affiliate[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@www9.dealtime[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@xiti[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@xxxcounter[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@xxxtoolbar[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@yadro[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@yadro[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@yadro[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@yieldmanager[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@yieldmanager[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@yieldmanager[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@yieldmanager[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@yieldmanager[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@yieldmanager[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@yourmedia[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ysbweb[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@ysbweb[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@z1.adserver[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@z1.adserver[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@z1.adserver[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@z1.adserver[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@z1.adserver[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@z1.adserver[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@z1.adserver[7].txt
C:\Documents and Settings\Administrator\Cookies\owner@zedo[1].txt
C:\Documents and Settings\Administrator\Cookies\owner@zedo[2].txt
C:\Documents and Settings\Administrator\Cookies\owner@zedo[3].txt
C:\Documents and Settings\Administrator\Cookies\owner@zedo[4].txt
C:\Documents and Settings\Administrator\Cookies\owner@zedo[5].txt
C:\Documents and Settings\Administrator\Cookies\owner@zedo[6].txt
C:\Documents and Settings\Administrator\Cookies\owner@zedo[7].txt
C:\Documents and Settings\Default User\Cookies\owner@1.primaryads[1].txt
C:\Documents and Settings\Default User\Cookies\owner@247realmedia[1].txt
C:\Documents and Settings\Default User\Cookies\owner@247realmedia[2].txt
C:\Documents and Settings\Default User\Cookies\owner@247realmedia[3].txt
C:\Documents and Settings\Default User\Cookies\owner@247realmedia[4].txt
C:\Documents and Settings\Default User\Cookies\owner@2o7[1].txt
C:\Documents and Settings\Default User\Cookies\owner@2o7[2].txt
C:\Documents and Settings\Default User\Cookies\owner@2o7[3].txt
C:\Documents and Settings\Default User\Cookies\owner@2o7[5].txt
C:\Documents and Settings\Default User\Cookies\owner@2o7[6].txt
C:\Documents and Settings\Default User\Cookies\owner@2o7[7].txt
C:\Documents and Settings\Default User\Cookies\owner@2o7[8].txt
C:\Documents and Settings\Default User\Cookies\owner@a.websponsors[1].txt
C:\Documents and Settings\Default User\Cookies\owner@a.websponsors[2].txt
C:\Documents and Settings\Default User\Cookies\owner@a.websponsors[3].txt
C:\Documents and Settings\Default User\Cookies\owner@a.websponsors[4].txt
C:\Documents and Settings\Default User\Cookies\owner@a.websponsors[5].txt
C:\Documents and Settings\Default User\Cookies\owner@ad-cross.co[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ad-cross.co[3].txt
C:\Documents and Settings\Default User\Cookies\owner@ad-indicator[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ad.admarketplace[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ad.admarketplace[3].txt
C:\Documents and Settings\Default User\Cookies\owner@ad.jamster[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ad.reunion[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ad.yieldmanager[10].txt
C:\Documents and Settings\Default User\Cookies\owner@ad.yieldmanager[11].txt
C:\Documents and Settings\Default User\Cookies\owner@ad.yieldmanager[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ad.yieldmanager[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ad.yieldmanager[3].txt
C:\Documents and Settings\Default User\Cookies\owner@ad.yieldmanager[4].txt
C:\Documents and Settings\Default User\Cookies\owner@ad.yieldmanager[5].txt
C:\Documents and Settings\Default User\Cookies\owner@ad.yieldmanager[6].txt
C:\Documents and Settings\Default User\Cookies\owner@ad.yieldmanager[7].txt
C:\Documents and Settings\Default User\Cookies\owner@ad.yieldmanager[9].txt
C:\Documents and Settings\Default User\Cookies\owner@ad.zanox[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ad1.clickhype[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ad2.pamedia.com[1].txt

rainshield
2007-12-07, 07:44
C:\Documents and Settings\Default User\Cookies\owner@adbrite[1].txt
C:\Documents and Settings\Default User\Cookies\owner@addynamix[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adecn[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adecn[2].txt
C:\Documents and Settings\Default User\Cookies\owner@adecn[3].txt
C:\Documents and Settings\Default User\Cookies\owner@adecn[5].txt
C:\Documents and Settings\Default User\Cookies\owner@adknowledge[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adknowledge[2].txt
C:\Documents and Settings\Default User\Cookies\owner@adknowledge[3].txt
C:\Documents and Settings\Default User\Cookies\owner@adknowledge[4].txt
C:\Documents and Settings\Default User\Cookies\owner@adknowledge[5].txt
C:\Documents and Settings\Default User\Cookies\owner@adknowledge[6].txt
C:\Documents and Settings\Default User\Cookies\owner@adlegend[1].txt
C:\Documents and Settings\Default User\Cookies\owner@admarketplace[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.hbmediapro[2].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.hbmediapro[3].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.hbmediapro[4].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.hbmediapro[5].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.hbmediapro[6].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.hbmediapro[7].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.hbmediapro[8].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.hotbar[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.hotbar[2].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.hotbar[3].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.hotbar[4].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.hotbar[5].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.specificclick[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.specificclick[2].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.specificclick[3].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.specificclick[4].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.specificclick[5].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.specificclick[6].txt
C:\Documents and Settings\Default User\Cookies\owner@adprofile[2].txt
C:\Documents and Settings\Default User\Cookies\owner@adprofile[3].txt
C:\Documents and Settings\Default User\Cookies\owner@adprofile[4].txt
C:\Documents and Settings\Default User\Cookies\owner@adrevolver[10].txt
C:\Documents and Settings\Default User\Cookies\owner@adrevolver[11].txt
C:\Documents and Settings\Default User\Cookies\owner@adrevolver[12].txt
C:\Documents and Settings\Default User\Cookies\owner@adrevolver[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adrevolver[2].txt
C:\Documents and Settings\Default User\Cookies\owner@adrevolver[3].txt
C:\Documents and Settings\Default User\Cookies\owner@adrevolver[4].txt
C:\Documents and Settings\Default User\Cookies\owner@adrevolver[5].txt
C:\Documents and Settings\Default User\Cookies\owner@adrevolver[6].txt
C:\Documents and Settings\Default User\Cookies\owner@adrevolver[7].txt
C:\Documents and Settings\Default User\Cookies\owner@adrevolver[8].txt
C:\Documents and Settings\Default User\Cookies\owner@adrevolver[9].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.addynamix[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.addynamix[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.addynamix[3].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.addynamix[4].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.addynamix[5].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.addynamix[7].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.addynamix[8].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.as4x.tmcs[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.cc214142[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.cc214142[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.cc214142[3].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.digitalpoint[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.digitalpoint[3].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.digitalpoint[4].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.i-am-bored[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.monster[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.monster[3].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.pointroll[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.pointroll[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.pointroll[3].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.pointroll[4].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.pointroll[5].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.pointroll[7].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.pwcr[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.realcastmedia[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.realcastmedia[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.realcastmedia[3].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.us.e-planning[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.us.e-planning[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ads1.megaupload[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ads1.megaupload[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ads1.playforum[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ads1.revenue[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adserver.adreactor[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adserver.adreactor[2].txt
C:\Documents and Settings\Default User\Cookies\owner@adserver.adreactor[3].txt
C:\Documents and Settings\Default User\Cookies\owner@adserver.adremedy[2].txt
C:\Documents and Settings\Default User\Cookies\owner@adserver.filefront[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adserver.filefront[2].txt
C:\Documents and Settings\Default User\Cookies\owner@adserver.filefront[3].txt
C:\Documents and Settings\Default User\Cookies\owner@adserver.filefront[4].txt
C:\Documents and Settings\Default User\Cookies\owner@adserver.mpogonline[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adserver.rdtg[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adserver.sharewareonline[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adserver[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adstat.4u[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adtech[2].txt
C:\Documents and Settings\Default User\Cookies\owner@adtrak[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adultbouncer[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adultbouncer[2].txt
C:\Documents and Settings\Default User\Cookies\owner@adultfriendfinder[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adultfriendfinder[2].txt
C:\Documents and Settings\Default User\Cookies\owner@advertising[1].txt
C:\Documents and Settings\Default User\Cookies\owner@advertising[2].txt
C:\Documents and Settings\Default User\Cookies\owner@advertising[3].txt
C:\Documents and Settings\Default User\Cookies\owner@advertising[4].txt
C:\Documents and Settings\Default User\Cookies\owner@advertising[5].txt
C:\Documents and Settings\Default User\Cookies\owner@advertising[7].txt
C:\Documents and Settings\Default User\Cookies\owner@advertising[8].txt
C:\Documents and Settings\Default User\Cookies\owner@apmebf[1].txt
C:\Documents and Settings\Default User\Cookies\owner@apmebf[2].txt
C:\Documents and Settings\Default User\Cookies\owner@apmebf[4].txt
C:\Documents and Settings\Default User\Cookies\owner@apmebf[5].txt
C:\Documents and Settings\Default User\Cookies\owner@apmebf[6].txt
C:\Documents and Settings\Default User\Cookies\owner@ar.atwola[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ar.atwola[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ar.atwola[3].txt
C:\Documents and Settings\Default User\Cookies\owner@ar.atwola[4].txt
C:\Documents and Settings\Default User\Cookies\owner@as-eu.falkag[1].txt
C:\Documents and Settings\Default User\Cookies\owner@as-eu.falkag[2].txt
C:\Documents and Settings\Default User\Cookies\owner@as-eu.falkag[3].txt
C:\Documents and Settings\Default User\Cookies\owner@as-eu.falkag[5].txt
C:\Documents and Settings\Default User\Cookies\owner@as-us.falkag[1].txt
C:\Documents and Settings\Default User\Cookies\owner@as-us.falkag[2].txt
C:\Documents and Settings\Default User\Cookies\owner@as-us.falkag[3].txt
C:\Documents and Settings\Default User\Cookies\owner@as-us.falkag[4].txt
C:\Documents and Settings\Default User\Cookies\owner@as-us.falkag[5].txt
C:\Documents and Settings\Default User\Cookies\owner@as-us.falkag[7].txt
C:\Documents and Settings\Default User\Cookies\owner@as-us.falkag[8].txt
C:\Documents and Settings\Default User\Cookies\owner@as1.falkag[1].txt
C:\Documents and Settings\Default User\Cookies\owner@as1.falkag[2].txt
C:\Documents and Settings\Default User\Cookies\owner@as1.falkag[3].txt
C:\Documents and Settings\Default User\Cookies\owner@as1.falkag[4].txt
C:\Documents and Settings\Default User\Cookies\owner@as1.falkag[5].txt
C:\Documents and Settings\Default User\Cookies\owner@as1.falkag[6].txt
C:\Documents and Settings\Default User\Cookies\owner@atdmt[2].txt
C:\Documents and Settings\Default User\Cookies\owner@atdmt[3].txt
C:\Documents and Settings\Default User\Cookies\owner@atdmt[4].txt
C:\Documents and Settings\Default User\Cookies\owner@atdmt[5].txt
C:\Documents and Settings\Default User\Cookies\owner@atdmt[6].txt
C:\Documents and Settings\Default User\Cookies\owner@atdmt[7].txt
C:\Documents and Settings\Default User\Cookies\owner@atdmt[8].txt
C:\Documents and Settings\Default User\Cookies\owner@ath.belnk[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ath.belnk[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ath.belnk[4].txt
C:\Documents and Settings\Default User\Cookies\owner@atwola[1].txt
C:\Documents and Settings\Default User\Cookies\owner@atwola[2].txt
C:\Documents and Settings\Default User\Cookies\owner@atwola[3].txt
C:\Documents and Settings\Default User\Cookies\owner@atwola[4].txt
C:\Documents and Settings\Default User\Cookies\owner@atwola[5].txt
C:\Documents and Settings\Default User\Cookies\owner@atwola[6].txt
C:\Documents and Settings\Default User\Cookies\owner@atwola[7].txt
C:\Documents and Settings\Default User\Cookies\owner@azjmp[1].txt
C:\Documents and Settings\Default User\Cookies\owner@azjmp[2].txt
C:\Documents and Settings\Default User\Cookies\owner@azjmp[3].txt
C:\Documents and Settings\Default User\Cookies\owner@azjmp[5].txt
C:\Documents and Settings\Default User\Cookies\owner@azjmp[6].txt
C:\Documents and Settings\Default User\Cookies\owner@banner.casinolasvegas[2].txt
C:\Documents and Settings\Default User\Cookies\owner@banner.goldenpalace[2].txt
C:\Documents and Settings\Default User\Cookies\owner@bannerspace[1].txt
C:\Documents and Settings\Default User\Cookies\owner@banners[1].txt
C:\Documents and Settings\Default User\Cookies\owner@banners[2].txt
C:\Documents and Settings\Default User\Cookies\owner@banners[3].txt
C:\Documents and Settings\Default User\Cookies\owner@banners[4].txt
C:\Documents and Settings\Default User\Cookies\owner@banners[5].txt
C:\Documents and Settings\Default User\Cookies\owner@banners[6].txt
C:\Documents and Settings\Default User\Cookies\owner@banner[1].txt
C:\Documents and Settings\Default User\Cookies\owner@belnk[1].txt
C:\Documents and Settings\Default User\Cookies\owner@belnk[2].txt
C:\Documents and Settings\Default User\Cookies\owner@belnk[3].txt
C:\Documents and Settings\Default User\Cookies\owner@belnk[4].txt
C:\Documents and Settings\Default User\Cookies\owner@belnk[5].txt
C:\Documents and Settings\Default User\Cookies\owner@belnk[6].txt

rainshield
2007-12-07, 07:44
C:\Documents and Settings\Default User\Cookies\owner@bizrate[1].txt
C:\Documents and Settings\Default User\Cookies\owner@bluestreak[1].txt
C:\Documents and Settings\Default User\Cookies\owner@bluestreak[2].txt
C:\Documents and Settings\Default User\Cookies\owner@bluestreak[3].txt
C:\Documents and Settings\Default User\Cookies\owner@bluestreak[4].txt
C:\Documents and Settings\Default User\Cookies\owner@bs.serving-sys[1].txt
C:\Documents and Settings\Default User\Cookies\owner@bs.serving-sys[3].txt
C:\Documents and Settings\Default User\Cookies\owner@btg.btgrab[1].txt
C:\Documents and Settings\Default User\Cookies\owner@burstnet[1].txt
C:\Documents and Settings\Default User\Cookies\owner@burstnet[2].txt
C:\Documents and Settings\Default User\Cookies\owner@burstnet[3].txt
C:\Documents and Settings\Default User\Cookies\owner@burstnet[4].txt
C:\Documents and Settings\Default User\Cookies\owner@burstnet[6].txt
C:\Documents and Settings\Default User\Cookies\owner@buycom.122.2o7[2].txt
C:\Documents and Settings\Default User\Cookies\owner@c.enhance[1].txt
C:\Documents and Settings\Default User\Cookies\owner@c.enhance[2].txt
C:\Documents and Settings\Default User\Cookies\owner@c.enhance[3].txt
C:\Documents and Settings\Default User\Cookies\owner@c.enhance[4].txt
C:\Documents and Settings\Default User\Cookies\owner@c.goclick[2].txt
C:\Documents and Settings\Default User\Cookies\owner@c4.zedo[1].txt
C:\Documents and Settings\Default User\Cookies\owner@c5.zedo[1].txt
C:\Documents and Settings\Default User\Cookies\owner@casalemedia[1].txt
C:\Documents and Settings\Default User\Cookies\owner@casalemedia[2].txt
C:\Documents and Settings\Default User\Cookies\owner@casalemedia[3].txt
C:\Documents and Settings\Default User\Cookies\owner@casalemedia[4].txt
C:\Documents and Settings\Default User\Cookies\owner@casalemedia[5].txt
C:\Documents and Settings\Default User\Cookies\owner@casalemedia[6].txt
C:\Documents and Settings\Default User\Cookies\owner@casalemedia[7].txt
C:\Documents and Settings\Default User\Cookies\owner@casinolasvegas[1].txt
C:\Documents and Settings\Default User\Cookies\owner@cassava[1].txt
C:\Documents and Settings\Default User\Cookies\owner@cb.adprofile[1].txt
C:\Documents and Settings\Default User\Cookies\owner@cb.adprofile[2].txt
C:\Documents and Settings\Default User\Cookies\owner@centralmedia[1].txt
C:\Documents and Settings\Default User\Cookies\owner@certified-safe-downloads[1].txt
C:\Documents and Settings\Default User\Cookies\owner@citi.bridgetrack[1].txt
C:\Documents and Settings\Default User\Cookies\owner@citi.bridgetrack[2].txt
C:\Documents and Settings\Default User\Cookies\owner@citi.bridgetrack[3].txt
C:\Documents and Settings\Default User\Cookies\owner@citi.bridgetrack[4].txt
C:\Documents and Settings\Default User\Cookies\owner@citi.bridgetrack[5].txt
C:\Documents and Settings\Default User\Cookies\owner@citi.bridgetrack[6].txt
C:\Documents and Settings\Default User\Cookies\owner@cityclub.gamingpromo[2].txt
C:\Documents and Settings\Default User\Cookies\owner@click.revsharecash[1].txt
C:\Documents and Settings\Default User\Cookies\owner@clickbank[1].txt
C:\Documents and Settings\Default User\Cookies\owner@clicksor[1].txt
C:\Documents and Settings\Default User\Cookies\owner@clicktorrent[1].txt
C:\Documents and Settings\Default User\Cookies\owner@cliks[1].txt
C:\Documents and Settings\Default User\Cookies\owner@cnn.122.2o7[2].txt
C:\Documents and Settings\Default User\Cookies\owner@counter-strike-dl[1].txt
C:\Documents and Settings\Default User\Cookies\owner@counter.hitslink[2].txt
C:\Documents and Settings\Default User\Cookies\owner@counter1.supercounter[2].txt
C:\Documents and Settings\Default User\Cookies\owner@counter16.sextracker[1].txt
C:\Documents and Settings\Default User\Cookies\owner@cpvfeed[1].txt
C:\Documents and Settings\Default User\Cookies\owner@cpvfeed[2].txt
C:\Documents and Settings\Default User\Cookies\owner@cpvfeed[3].txt
C:\Documents and Settings\Default User\Cookies\owner@cpvfeed[4].txt
C:\Documents and Settings\Default User\Cookies\owner@cracks[1].txt
C:\Documents and Settings\Default User\Cookies\owner@creativeby.viewpoint[1].txt
C:\Documents and Settings\Default User\Cookies\owner@creativeby.viewpoint[2].txt
C:\Documents and Settings\Default User\Cookies\owner@creativeby.viewpoint[3].txt
C:\Documents and Settings\Default User\Cookies\owner@creativeby.viewpoint[5].txt
C:\Documents and Settings\Default User\Cookies\owner@cs.sexcounter[2].txt
C:\Documents and Settings\Default User\Cookies\owner@cz3.clickzs[2].txt
C:\Documents and Settings\Default User\Cookies\owner@cz3.clickzs[3].txt
C:\Documents and Settings\Default User\Cookies\owner@cz7.clickzs[2].txt
C:\Documents and Settings\Default User\Cookies\owner@cz8.clickzs[2].txt
C:\Documents and Settings\Default User\Cookies\owner@data2.perf.overture[1].txt
C:\Documents and Settings\Default User\Cookies\owner@data4.perf.overture[1].txt
C:\Documents and Settings\Default User\Cookies\owner@data4.perf.overture[2].txt
C:\Documents and Settings\Default User\Cookies\owner@dealtime[2].txt
C:\Documents and Settings\Default User\Cookies\owner@dealtime[3].txt
C:\Documents and Settings\Default User\Cookies\owner@directtrack[1].txt
C:\Documents and Settings\Default User\Cookies\owner@dist.belnk[1].txt
C:\Documents and Settings\Default User\Cookies\owner@dist.belnk[2].txt
C:\Documents and Settings\Default User\Cookies\owner@dist.belnk[3].txt
C:\Documents and Settings\Default User\Cookies\owner@dist.belnk[4].txt
C:\Documents and Settings\Default User\Cookies\owner@dist.belnk[5].txt
C:\Documents and Settings\Default User\Cookies\owner@dist.belnk[6].txt
C:\Documents and Settings\Default User\Cookies\owner@doubleclick[1].txt
C:\Documents and Settings\Default User\Cookies\owner@doubleclick[2].txt
C:\Documents and Settings\Default User\Cookies\owner@doubleclick[3].txt
C:\Documents and Settings\Default User\Cookies\owner@doubleclick[4].txt
C:\Documents and Settings\Default User\Cookies\owner@doubleclick[5].txt
C:\Documents and Settings\Default User\Cookies\owner@doubleclick[6].txt
C:\Documents and Settings\Default User\Cookies\owner@doubleclick[7].txt
C:\Documents and Settings\Default User\Cookies\owner@edge.ru4[1].txt
C:\Documents and Settings\Default User\Cookies\owner@edge.ru4[2].txt
C:\Documents and Settings\Default User\Cookies\owner@edge.ru4[3].txt
C:\Documents and Settings\Default User\Cookies\owner@edge.ru4[4].txt
C:\Documents and Settings\Default User\Cookies\owner@edge.ru4[5].txt
C:\Documents and Settings\Default User\Cookies\owner@edge.ru4[6].txt
C:\Documents and Settings\Default User\Cookies\owner@ehg-adteractive.hitbox[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ehg-adteractive.hitbox[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ehg-ati.hitbox[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ehg-bestbuy.hitbox[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ehg-clearchannel.hitbox[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ehg-communityconnect.hitbox[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ehg-eline.hitbox[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ehg-gamespyinc.hitbox[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ehg-idg.hitbox[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ehg-idgentertainment.hitbox[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ehg-nestleusainc.hitbox[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ehg-streamload.hitbox[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ehg.hitbox[2].txt
C:\Documents and Settings\Default User\Cookies\owner@elite[2].txt
C:\Documents and Settings\Default User\Cookies\owner@emarketmakers[1].txt
C:\Documents and Settings\Default User\Cookies\owner@emarketmakers[2].txt
C:\Documents and Settings\Default User\Cookies\owner@emarketmakers[3].txt
C:\Documents and Settings\Default User\Cookies\owner@emarketmakers[4].txt
C:\Documents and Settings\Default User\Cookies\owner@emarketmakers[5].txt
C:\Documents and Settings\Default User\Cookies\owner@entrepreneur.122.2o7[1].txt
C:\Documents and Settings\Default User\Cookies\owner@entrepreneur.122.2o7[2].txt
C:\Documents and Settings\Default User\Cookies\owner@entrepreneur.122.2o7[3].txt
C:\Documents and Settings\Default User\Cookies\owner@etype.adbureau[1].txt
C:\Documents and Settings\Default User\Cookies\owner@exitexchange[1].txt
C:\Documents and Settings\Default User\Cookies\owner@exitexchange[2].txt
C:\Documents and Settings\Default User\Cookies\owner@exitexchange[3].txt
C:\Documents and Settings\Default User\Cookies\owner@exitexchange[4].txt
C:\Documents and Settings\Default User\Cookies\owner@exitexchange[5].txt
C:\Documents and Settings\Default User\Cookies\owner@exitexchange[6].txt
C:\Documents and Settings\Default User\Cookies\owner@experclick[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ez-tracks[2].txt
C:\Documents and Settings\Default User\Cookies\owner@eztracks.aavalue[2].txt
C:\Documents and Settings\Default User\Cookies\owner@fastclick[1].txt
C:\Documents and Settings\Default User\Cookies\owner@fastclick[2].txt
C:\Documents and Settings\Default User\Cookies\owner@fastclick[3].txt
C:\Documents and Settings\Default User\Cookies\owner@fastclick[5].txt
C:\Documents and Settings\Default User\Cookies\owner@fastclick[6].txt
C:\Documents and Settings\Default User\Cookies\owner@fastclick[7].txt
C:\Documents and Settings\Default User\Cookies\owner@fastclick[8].txt
C:\Documents and Settings\Default User\Cookies\owner@findwhat[1].txt
C:\Documents and Settings\Default User\Cookies\owner@findwhat[2].txt
C:\Documents and Settings\Default User\Cookies\owner@fortunecity[1].txt
C:\Documents and Settings\Default User\Cookies\owner@fortunecity[3].txt
C:\Documents and Settings\Default User\Cookies\owner@freeze.directtrack[2].txt
C:\Documents and Settings\Default User\Cookies\owner@funwebproducts[2].txt
C:\Documents and Settings\Default User\Cookies\owner@gamingpromo[1].txt
C:\Documents and Settings\Default User\Cookies\owner@goclick[1].txt
C:\Documents and Settings\Default User\Cookies\owner@goclick[2].txt
C:\Documents and Settings\Default User\Cookies\owner@gtb1.acecounter[1].txt
C:\Documents and Settings\Default User\Cookies\owner@gtb2.acecounter[1].txt
C:\Documents and Settings\Default User\Cookies\owner@gtp1.acecounter[1].txt
C:\Documents and Settings\Default User\Cookies\owner@h.starware[1].txt
C:\Documents and Settings\Default User\Cookies\owner@h.starware[2].txt
C:\Documents and Settings\Default User\Cookies\owner@h.starware[4].txt
C:\Documents and Settings\Default User\Cookies\owner@hbmediapro[1].txt
C:\Documents and Settings\Default User\Cookies\owner@hbmediapro[2].txt
C:\Documents and Settings\Default User\Cookies\owner@hc2.humanclick[1].txt
C:\Documents and Settings\Default User\Cookies\owner@hc2.humanclick[2].txt
C:\Documents and Settings\Default User\Cookies\owner@hc2.humanclick[3].txt
C:\Documents and Settings\Default User\Cookies\owner@hentaicounter[1].txt
C:\Documents and Settings\Default User\Cookies\owner@hg1.hitbox[1].txt
C:\Documents and Settings\Default User\Cookies\owner@hitbox[1].txt
C:\Documents and Settings\Default User\Cookies\owner@hitbox[2].txt
C:\Documents and Settings\Default User\Cookies\owner@hitbox[3].txt

rainshield
2007-12-07, 07:45
C:\Documents and Settings\Default User\Cookies\owner@hitbox[4].txt
C:\Documents and Settings\Default User\Cookies\owner@hits.clickandtrack[1].txt
C:\Documents and Settings\Default User\Cookies\owner@hits.clickandtrack[2].txt
C:\Documents and Settings\Default User\Cookies\owner@hits.clickandtrack[3].txt
C:\Documents and Settings\Default User\Cookies\owner@hits.clickandtrack[4].txt
C:\Documents and Settings\Default User\Cookies\owner@hits.clickandtrack[5].txt
C:\Documents and Settings\Default User\Cookies\owner@hits.clickandtrack[6].txt
C:\Documents and Settings\Default User\Cookies\owner@hurricanedigitalmedia[2].txt
C:\Documents and Settings\Default User\Cookies\owner@hurricanedigitalmedia[3].txt
C:\Documents and Settings\Default User\Cookies\owner@hypertracker[1].txt
C:\Documents and Settings\Default User\Cookies\owner@hypertracker[2].txt
C:\Documents and Settings\Default User\Cookies\owner@hypertracker[3].txt
C:\Documents and Settings\Default User\Cookies\owner@hypertracker[4].txt
C:\Documents and Settings\Default User\Cookies\owner@hypertracker[5].txt
C:\Documents and Settings\Default User\Cookies\owner@i.screensavers[1].txt
C:\Documents and Settings\Default User\Cookies\owner@i.screensavers[2].txt
C:\Documents and Settings\Default User\Cookies\owner@i.screensavers[3].txt
C:\Documents and Settings\Default User\Cookies\owner@i.screensavers[4].txt
C:\Documents and Settings\Default User\Cookies\owner@icc.intellisrv[2].txt
C:\Documents and Settings\Default User\Cookies\owner@icc.intellisrv[3].txt
C:\Documents and Settings\Default User\Cookies\owner@icc.intellisrv[4].txt
C:\Documents and Settings\Default User\Cookies\owner@icc.intellisrv[5].txt
C:\Documents and Settings\Default User\Cookies\owner@idesktopmedia.directtrack[2].txt
C:\Documents and Settings\Default User\Cookies\owner@image.masterstats[1].txt
C:\Documents and Settings\Default User\Cookies\owner@image.masterstats[2].txt
C:\Documents and Settings\Default User\Cookies\owner@imp.partner2profit[2].txt
C:\Documents and Settings\Default User\Cookies\owner@interclick[2].txt
C:\Documents and Settings\Default User\Cookies\owner@interclick[3].txt
C:\Documents and Settings\Default User\Cookies\owner@interclick[4].txt
C:\Documents and Settings\Default User\Cookies\owner@interclick[5].txt
C:\Documents and Settings\Default User\Cookies\owner@internetfuel[1].txt
C:\Documents and Settings\Default User\Cookies\owner@internetfuel[2].txt
C:\Documents and Settings\Default User\Cookies\owner@internetfuel[4].txt
C:\Documents and Settings\Default User\Cookies\owner@jamster[1].txt
C:\Documents and Settings\Default User\Cookies\owner@jamster[3].txt
C:\Documents and Settings\Default User\Cookies\owner@jamster[4].txt
C:\Documents and Settings\Default User\Cookies\owner@kanoodle[1].txt
C:\Documents and Settings\Default User\Cookies\owner@kanoodle[3].txt
C:\Documents and Settings\Default User\Cookies\owner@kanoodle[4].txt
C:\Documents and Settings\Default User\Cookies\owner@kanoodle[5].txt
C:\Documents and Settings\Default User\Cookies\owner@keywordmax[1].txt
C:\Documents and Settings\Default User\Cookies\owner@kmpads[1].txt
C:\Documents and Settings\Default User\Cookies\owner@kmpads[2].txt
C:\Documents and Settings\Default User\Cookies\owner@leadgenetwork[1].txt
C:\Documents and Settings\Default User\Cookies\owner@leadgenetwork[2].txt
C:\Documents and Settings\Default User\Cookies\owner@leadgenetwork[4].txt
C:\Documents and Settings\Default User\Cookies\owner@leadgenetwork[5].txt
C:\Documents and Settings\Default User\Cookies\owner@linksynergy[2].txt
C:\Documents and Settings\Default User\Cookies\owner@linksynergy[3].txt
C:\Documents and Settings\Default User\Cookies\owner@linksynergy[4].txt
C:\Documents and Settings\Default User\Cookies\owner@login.tracking101[2].txt
C:\Documents and Settings\Default User\Cookies\owner@login.tracking101[3].txt
C:\Documents and Settings\Default User\Cookies\owner@lynxtrack[1].txt
C:\Documents and Settings\Default User\Cookies\owner@maxserving[1].txt
C:\Documents and Settings\Default User\Cookies\owner@maxserving[2].txt
C:\Documents and Settings\Default User\Cookies\owner@maxserving[3].txt
C:\Documents and Settings\Default User\Cookies\owner@maxserving[4].txt
C:\Documents and Settings\Default User\Cookies\owner@maxserving[5].txt
C:\Documents and Settings\Default User\Cookies\owner@media.adrevolver[1].txt
C:\Documents and Settings\Default User\Cookies\owner@media.onlinewelten[2].txt
C:\Documents and Settings\Default User\Cookies\owner@media.top-banners[1].txt
C:\Documents and Settings\Default User\Cookies\owner@media2.onlinewelten[2].txt
C:\Documents and Settings\Default User\Cookies\owner@mediaplex[1].txt
C:\Documents and Settings\Default User\Cookies\owner@mediaplex[2].txt
C:\Documents and Settings\Default User\Cookies\owner@mediaplex[3].txt
C:\Documents and Settings\Default User\Cookies\owner@mediaplex[4].txt
C:\Documents and Settings\Default User\Cookies\owner@mediaplex[5].txt
C:\Documents and Settings\Default User\Cookies\owner@mediaplex[6].txt
C:\Documents and Settings\Default User\Cookies\owner@mediaplex[8].txt
C:\Documents and Settings\Default User\Cookies\owner@metareward[1].txt
C:\Documents and Settings\Default User\Cookies\owner@metareward[2].txt
C:\Documents and Settings\Default User\Cookies\owner@microsofteup.112.2o7[1].txt
C:\Documents and Settings\Default User\Cookies\owner@microsofteup.112.2o7[2].txt
C:\Documents and Settings\Default User\Cookies\owner@mmm.media-motor[1].txt
C:\Documents and Settings\Default User\Cookies\owner@mmm.media-motor[3].txt
C:\Documents and Settings\Default User\Cookies\owner@moneyjunkey.directtrack[2].txt
C:\Documents and Settings\Default User\Cookies\owner@msnportal.112.2o7[1].txt
C:\Documents and Settings\Default User\Cookies\owner@mywebsearch[2].txt
C:\Documents and Settings\Default User\Cookies\owner@nextag[1].txt
C:\Documents and Settings\Default User\Cookies\owner@nextag[2].txt
C:\Documents and Settings\Default User\Cookies\owner@nextag[4].txt
C:\Documents and Settings\Default User\Cookies\owner@nextag[5].txt
C:\Documents and Settings\Default User\Cookies\owner@offeroptimizer[1].txt
C:\Documents and Settings\Default User\Cookies\owner@offeroptimizer[3].txt
C:\Documents and Settings\Default User\Cookies\owner@offeroptimizer[4].txt
C:\Documents and Settings\Default User\Cookies\owner@oinadserve[2].txt
C:\Documents and Settings\Default User\Cookies\owner@onlinerewardcenter[1].txt
C:\Documents and Settings\Default User\Cookies\owner@onlinerewardcenter[2].txt
C:\Documents and Settings\Default User\Cookies\owner@onlinerewardcenter[3].txt
C:\Documents and Settings\Default User\Cookies\owner@onlinerewardcenter[4].txt
C:\Documents and Settings\Default User\Cookies\owner@onlinerewardcenter[5].txt
C:\Documents and Settings\Default User\Cookies\owner@overture[1].txt
C:\Documents and Settings\Default User\Cookies\owner@overture[2].txt
C:\Documents and Settings\Default User\Cookies\owner@pacificpoker[1].txt
C:\Documents and Settings\Default User\Cookies\owner@partner2profit[1].txt
C:\Documents and Settings\Default User\Cookies\owner@partner2profit[2].txt
C:\Documents and Settings\Default User\Cookies\owner@partygaming.122.2o7[1].txt
C:\Documents and Settings\Default User\Cookies\owner@partypoker.touchclarity[1].txt
C:\Documents and Settings\Default User\Cookies\owner@partypoker.touchclarity[2].txt
C:\Documents and Settings\Default User\Cookies\owner@partypoker[1].txt
C:\Documents and Settings\Default User\Cookies\owner@partypoker[2].txt
C:\Documents and Settings\Default User\Cookies\owner@partypoker[3].txt
C:\Documents and Settings\Default User\Cookies\owner@partypoker[4].txt
C:\Documents and Settings\Default User\Cookies\owner@partypoker[5].txt
C:\Documents and Settings\Default User\Cookies\owner@partypoker[6].txt
C:\Documents and Settings\Default User\Cookies\owner@paycounter[1].txt
C:\Documents and Settings\Default User\Cookies\owner@paypopup[1].txt
C:\Documents and Settings\Default User\Cookies\owner@paypopup[2].txt
C:\Documents and Settings\Default User\Cookies\owner@paypopup[3].txt
C:\Documents and Settings\Default User\Cookies\owner@perf.overture[1].txt
C:\Documents and Settings\Default User\Cookies\owner@perf.overture[2].txt
C:\Documents and Settings\Default User\Cookies\owner@perf.overture[3].txt
C:\Documents and Settings\Default User\Cookies\owner@perf.overture[4].txt
C:\Documents and Settings\Default User\Cookies\owner@perf.overture[5].txt
C:\Documents and Settings\Default User\Cookies\owner@perf.overture[6].txt
C:\Documents and Settings\Default User\Cookies\owner@perf.overture[7].txt
C:\Documents and Settings\Default User\Cookies\owner@pornaccess[1].txt
C:\Documents and Settings\Default User\Cookies\owner@pornaccess[2].txt
C:\Documents and Settings\Default User\Cookies\owner@pro-market[2].txt
C:\Documents and Settings\Default User\Cookies\owner@publishers.clickbooth[2].txt
C:\Documents and Settings\Default User\Cookies\owner@publishers.clickbooth[3].txt
C:\Documents and Settings\Default User\Cookies\owner@publishers.clickbooth[4].txt
C:\Documents and Settings\Default User\Cookies\owner@publishers.clickbooth[5].txt
C:\Documents and Settings\Default User\Cookies\owner@qksrv[1].txt
C:\Documents and Settings\Default User\Cookies\owner@qksrv[2].txt
C:\Documents and Settings\Default User\Cookies\owner@qksrv[4].txt
C:\Documents and Settings\Default User\Cookies\owner@qksrv[5].txt
C:\Documents and Settings\Default User\Cookies\owner@qksrv[6].txt
C:\Documents and Settings\Default User\Cookies\owner@qnsr[1].txt
C:\Documents and Settings\Default User\Cookies\owner@qnsr[2].txt
C:\Documents and Settings\Default User\Cookies\owner@qnsr[3].txt
C:\Documents and Settings\Default User\Cookies\owner@qnsr[4].txt
C:\Documents and Settings\Default User\Cookies\owner@qnsr[5].txt
C:\Documents and Settings\Default User\Cookies\owner@qnsr[6].txt
C:\Documents and Settings\Default User\Cookies\owner@qnsr[7].txt
C:\Documents and Settings\Default User\Cookies\owner@questionmarket[1].txt
C:\Documents and Settings\Default User\Cookies\owner@questionmarket[2].txt
C:\Documents and Settings\Default User\Cookies\owner@questionmarket[3].txt
C:\Documents and Settings\Default User\Cookies\owner@questionmarket[4].txt
C:\Documents and Settings\Default User\Cookies\owner@questionmarket[5].txt
C:\Documents and Settings\Default User\Cookies\owner@questionmarket[6].txt
C:\Documents and Settings\Default User\Cookies\owner@questionmarket[7].txt
C:\Documents and Settings\Default User\Cookies\owner@realmedia[1].txt
C:\Documents and Settings\Default User\Cookies\owner@realmedia[2].txt
C:\Documents and Settings\Default User\Cookies\owner@realmedia[3].txt
C:\Documents and Settings\Default User\Cookies\owner@realmedia[4].txt
C:\Documents and Settings\Default User\Cookies\owner@realmedia[5].txt
C:\Documents and Settings\Default User\Cookies\owner@realmedia[7].txt
C:\Documents and Settings\Default User\Cookies\owner@realmedia[8].txt
C:\Documents and Settings\Default User\Cookies\owner@redorbit[1].txt
C:\Documents and Settings\Default User\Cookies\owner@redorbit[2].txt
C:\Documents and Settings\Default User\Cookies\owner@reduxads.valuead[1].txt
C:\Documents and Settings\Default User\Cookies\owner@revenue[1].txt
C:\Documents and Settings\Default User\Cookies\owner@revenue[2].txt
C:\Documents and Settings\Default User\Cookies\owner@revenue[3].txt
C:\Documents and Settings\Default User\Cookies\owner@revenue[4].txt
C:\Documents and Settings\Default User\Cookies\owner@revenue[5].txt
C:\Documents and Settings\Default User\Cookies\owner@revenue[7].txt
C:\Documents and Settings\Default User\Cookies\owner@revsci[1].txt
C:\Documents and Settings\Default User\Cookies\owner@roiservice[1].txt
C:\Documents and Settings\Default User\Cookies\owner@roiservice[3].txt
C:\Documents and Settings\Default User\Cookies\owner@rotator.adjuggler[1].txt
C:\Documents and Settings\Default User\Cookies\owner@rotator.adjuggler[2].txt
C:\Documents and Settings\Default User\Cookies\owner@rotator.adjuggler[3].txt
C:\Documents and Settings\Default User\Cookies\owner@sales.liveperson[2].txt
C:\Documents and Settings\Default User\Cookies\owner@sav.coolsavings[1].txt
C:\Documents and Settings\Default User\Cookies\owner@searchbar.findthewebsiteyouneed[2].txt
C:\Documents and Settings\Default User\Cookies\owner@servedby.advertising[1].txt
C:\Documents and Settings\Default User\Cookies\owner@servedby.advertising[2].txt
C:\Documents and Settings\Default User\Cookies\owner@servedby.advertising[3].txt
C:\Documents and Settings\Default User\Cookies\owner@servedby.advertising[4].txt
C:\Documents and Settings\Default User\Cookies\owner@servedby.advertising[5].txt

rainshield
2007-12-07, 07:46
C:\Documents and Settings\Default User\Cookies\owner@servedby.advertising[6].txt
C:\Documents and Settings\Default User\Cookies\owner@server.cpmstar[2].txt
C:\Documents and Settings\Default User\Cookies\owner@server.cpmstar[3].txt
C:\Documents and Settings\Default User\Cookies\owner@server.cpmstar[4].txt
C:\Documents and Settings\Default User\Cookies\owner@server.iad.liveperson[1].txt
C:\Documents and Settings\Default User\Cookies\owner@server.iad.liveperson[2].txt
C:\Documents and Settings\Default User\Cookies\owner@server.iad.liveperson[3].txt
C:\Documents and Settings\Default User\Cookies\owner@server.iad.liveperson[4].txt
C:\Documents and Settings\Default User\Cookies\owner@server.iad.liveperson[5].txt
C:\Documents and Settings\Default User\Cookies\owner@server.iad.liveperson[6].txt
C:\Documents and Settings\Default User\Cookies\owner@server2.bkvtrack[1].txt
C:\Documents and Settings\Default User\Cookies\owner@serving-sys[1].txt
C:\Documents and Settings\Default User\Cookies\owner@serving-sys[2].txt
C:\Documents and Settings\Default User\Cookies\owner@serving-sys[3].txt
C:\Documents and Settings\Default User\Cookies\owner@serving-sys[4].txt
C:\Documents and Settings\Default User\Cookies\owner@sexole[1].txt
C:\Documents and Settings\Default User\Cookies\owner@sextalk.sexviet[1].txt
C:\Documents and Settings\Default User\Cookies\owner@sextalk.sexviet[2].txt
C:\Documents and Settings\Default User\Cookies\owner@sextalk.sexviet[3].txt
C:\Documents and Settings\Default User\Cookies\owner@sextracker[2].txt
C:\Documents and Settings\Default User\Cookies\owner@sexviet[1].txt
C:\Documents and Settings\Default User\Cookies\owner@sexviet[2].txt
C:\Documents and Settings\Default User\Cookies\owner@sexviet[4].txt
C:\Documents and Settings\Default User\Cookies\owner@smileycentral[1].txt
C:\Documents and Settings\Default User\Cookies\owner@smileycentral[3].txt
C:\Documents and Settings\Default User\Cookies\owner@soundclick[2].txt
C:\Documents and Settings\Default User\Cookies\owner@specificclick[1].txt
C:\Documents and Settings\Default User\Cookies\owner@spylog[1].txt
C:\Documents and Settings\Default User\Cookies\owner@spylog[2].txt
C:\Documents and Settings\Default User\Cookies\owner@starware[1].txt
C:\Documents and Settings\Default User\Cookies\owner@starware[2].txt
C:\Documents and Settings\Default User\Cookies\owner@starware[3].txt
C:\Documents and Settings\Default User\Cookies\owner@starware[4].txt
C:\Documents and Settings\Default User\Cookies\owner@starware[6].txt
C:\Documents and Settings\Default User\Cookies\owner@stat.dealtime[2].txt
C:\Documents and Settings\Default User\Cookies\owner@stat.dealtime[3].txt
C:\Documents and Settings\Default User\Cookies\owner@stat.dealtime[4].txt
C:\Documents and Settings\Default User\Cookies\owner@stat.onestat[1].txt
C:\Documents and Settings\Default User\Cookies\owner@statcounter[1].txt
C:\Documents and Settings\Default User\Cookies\owner@statcounter[2].txt
C:\Documents and Settings\Default User\Cookies\owner@statcounter[3].txt
C:\Documents and Settings\Default User\Cookies\owner@statcounter[4].txt
C:\Documents and Settings\Default User\Cookies\owner@statcounter[5].txt
C:\Documents and Settings\Default User\Cookies\owner@statcounter[6].txt
C:\Documents and Settings\Default User\Cookies\owner@statcounter[7].txt
C:\Documents and Settings\Default User\Cookies\owner@stats1.reliablestats[2].txt
C:\Documents and Settings\Default User\Cookies\owner@stats1.reliablestats[3].txt
C:\Documents and Settings\Default User\Cookies\owner@stats1.reliablestats[4].txt
C:\Documents and Settings\Default User\Cookies\owner@statse.webtrendslive[1].txt
C:\Documents and Settings\Default User\Cookies\owner@statse.webtrendslive[2].txt
C:\Documents and Settings\Default User\Cookies\owner@statse.webtrendslive[3].txt
C:\Documents and Settings\Default User\Cookies\owner@statse.webtrendslive[5].txt
C:\Documents and Settings\Default User\Cookies\owner@stats[2].txt
C:\Documents and Settings\Default User\Cookies\owner@stats_[2].txt
C:\Documents and Settings\Default User\Cookies\owner@superstats[1].txt
C:\Documents and Settings\Default User\Cookies\owner@sxload[2].txt
C:\Documents and Settings\Default User\Cookies\owner@tacoda[1].txt
C:\Documents and Settings\Default User\Cookies\owner@tacoda[2].txt
C:\Documents and Settings\Default User\Cookies\owner@tacoda[3].txt
C:\Documents and Settings\Default User\Cookies\owner@tacoda[4].txt
C:\Documents and Settings\Default User\Cookies\owner@tacoda[5].txt
C:\Documents and Settings\Default User\Cookies\owner@tagworld[1].txt
C:\Documents and Settings\Default User\Cookies\owner@targetnet[1].txt
C:\Documents and Settings\Default User\Cookies\owner@targetnet[2].txt
C:\Documents and Settings\Default User\Cookies\owner@targetnet[3].txt
C:\Documents and Settings\Default User\Cookies\owner@targetnet[4].txt
C:\Documents and Settings\Default User\Cookies\owner@targetnet[5].txt
C:\Documents and Settings\Default User\Cookies\owner@targetnet[6].txt
C:\Documents and Settings\Default User\Cookies\owner@targetnet[7].txt
C:\Documents and Settings\Default User\Cookies\owner@toplist[1].txt
C:\Documents and Settings\Default User\Cookies\owner@tour.splash.sexsearch[1].txt
C:\Documents and Settings\Default User\Cookies\owner@tour.splash.sexsearch[2].txt
C:\Documents and Settings\Default User\Cookies\owner@tour.splash.sexsearch[3].txt
C:\Documents and Settings\Default User\Cookies\owner@tracking[1].txt
C:\Documents and Settings\Default User\Cookies\owner@tracking[2].txt
C:\Documents and Settings\Default User\Cookies\owner@tradedoubler[1].txt
C:\Documents and Settings\Default User\Cookies\owner@tradedoubler[2].txt
C:\Documents and Settings\Default User\Cookies\owner@tradedoubler[3].txt
C:\Documents and Settings\Default User\Cookies\owner@tradedoubler[4].txt
C:\Documents and Settings\Default User\Cookies\owner@tradedoubler[5].txt
C:\Documents and Settings\Default User\Cookies\owner@tradedoubler[6].txt
C:\Documents and Settings\Default User\Cookies\owner@trafficdashboard[1].txt
C:\Documents and Settings\Default User\Cookies\owner@trafficmp[1].txt
C:\Documents and Settings\Default User\Cookies\owner@trafficmp[2].txt
C:\Documents and Settings\Default User\Cookies\owner@trafficmp[3].txt
C:\Documents and Settings\Default User\Cookies\owner@trafficmp[4].txt
C:\Documents and Settings\Default User\Cookies\owner@trafficmp[5].txt
C:\Documents and Settings\Default User\Cookies\owner@trafficmp[6].txt
C:\Documents and Settings\Default User\Cookies\owner@trafficmp[7].txt
C:\Documents and Settings\Default User\Cookies\owner@trafficmp[8].txt
C:\Documents and Settings\Default User\Cookies\owner@tribalfusion[1].txt
C:\Documents and Settings\Default User\Cookies\owner@tribalfusion[2].txt
C:\Documents and Settings\Default User\Cookies\owner@tribalfusion[3].txt
C:\Documents and Settings\Default User\Cookies\owner@tribalfusion[4].txt
C:\Documents and Settings\Default User\Cookies\owner@tribalfusion[5].txt
C:\Documents and Settings\Default User\Cookies\owner@tribalfusion[6].txt
C:\Documents and Settings\Default User\Cookies\owner@tribalfusion[7].txt
C:\Documents and Settings\Default User\Cookies\owner@tripod[1].txt
C:\Documents and Settings\Default User\Cookies\owner@tripod[2].txt
C:\Documents and Settings\Default User\Cookies\owner@usenext[1].txt
C:\Documents and Settings\Default User\Cookies\owner@usenext[2].txt
C:\Documents and Settings\Default User\Cookies\owner@usenext[3].txt
C:\Documents and Settings\Default User\Cookies\owner@usenext[4].txt
C:\Documents and Settings\Default User\Cookies\owner@valueclick[1].txt
C:\Documents and Settings\Default User\Cookies\owner@valueclick[2].txt
C:\Documents and Settings\Default User\Cookies\owner@valueclick[3].txt
C:\Documents and Settings\Default User\Cookies\owner@valueclick[4].txt
C:\Documents and Settings\Default User\Cookies\owner@valueclick[5].txt
C:\Documents and Settings\Default User\Cookies\owner@warlog[2].txt
C:\Documents and Settings\Default User\Cookies\owner@warlog[3].txt
C:\Documents and Settings\Default User\Cookies\owner@web-nexus[1].txt
C:\Documents and Settings\Default User\Cookies\owner@web-nexus[2].txt
C:\Documents and Settings\Default User\Cookies\owner@web-nexus[3].txt
C:\Documents and Settings\Default User\Cookies\owner@web-nexus[4].txt
C:\Documents and Settings\Default User\Cookies\owner@web-nexus[6].txt
C:\Documents and Settings\Default User\Cookies\owner@web2.realtracker[2].txt
C:\Documents and Settings\Default User\Cookies\owner@webcam.sexole[1].txt
C:\Documents and Settings\Default User\Cookies\owner@webpower[2].txt
C:\Documents and Settings\Default User\Cookies\owner@windowsmedia[1].txt
C:\Documents and Settings\Default User\Cookies\owner@windowsmedia[2].txt
C:\Documents and Settings\Default User\Cookies\owner@windowsmedia[3].txt
C:\Documents and Settings\Default User\Cookies\owner@winfixer[1].txt
C:\Documents and Settings\Default User\Cookies\owner@winfixer[2].txt
C:\Documents and Settings\Default User\Cookies\owner@winfixer[3].txt
C:\Documents and Settings\Default User\Cookies\owner@winfixer[4].txt
C:\Documents and Settings\Default User\Cookies\owner@www.adserv[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.azoogleads[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.bannersandpopups[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.burstbeacon[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.burstbeacon[2].txt
C:\Documents and Settings\Default User\Cookies\owner@www.burstbeacon[3].txt
C:\Documents and Settings\Default User\Cookies\owner@www.burstbeacon[4].txt
C:\Documents and Settings\Default User\Cookies\owner@www.burstnet[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.clickedyclick[2].txt
C:\Documents and Settings\Default User\Cookies\owner@www.coolcounters[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.coolcounters[2].txt
C:\Documents and Settings\Default User\Cookies\owner@www.entrepreneur[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.entrepreneur[2].txt
C:\Documents and Settings\Default User\Cookies\owner@www.ez-tracks[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.findthewebsiteyouneed[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.glispatrack[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.penisbot[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.redorbit[2].txt
C:\Documents and Settings\Default User\Cookies\owner@www.screensavers[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.screensavers[2].txt
C:\Documents and Settings\Default User\Cookies\owner@www.screensavers[3].txt
C:\Documents and Settings\Default User\Cookies\owner@www.screensavers[4].txt
C:\Documents and Settings\Default User\Cookies\owner@www.screensavers[5].txt
C:\Documents and Settings\Default User\Cookies\owner@www.sexuploader[2].txt
C:\Documents and Settings\Default User\Cookies\owner@www.sexviet[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.sexviet[3].txt
C:\Documents and Settings\Default User\Cookies\owner@www.starware[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.starware[2].txt
C:\Documents and Settings\Default User\Cookies\owner@www.stopzilla[2].txt
C:\Documents and Settings\Default User\Cookies\owner@www.tagworld[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.winantiviruspro[2].txt
C:\Documents and Settings\Default User\Cookies\owner@www.winantivirus[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.winfixer[2].txt
C:\Documents and Settings\Default User\Cookies\owner@www.xctrk[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.xctrk[3].txt
C:\Documents and Settings\Default User\Cookies\owner@www.xctrk[4].txt
C:\Documents and Settings\Default User\Cookies\owner@www.zanox-affiliate[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.zanox-affiliate[2].txt
C:\Documents and Settings\Default User\Cookies\owner@www9.dealtime[1].txt
C:\Documents and Settings\Default User\Cookies\owner@xiti[1].txt
C:\Documents and Settings\Default User\Cookies\owner@xxxcounter[1].txt
C:\Documents and Settings\Default User\Cookies\owner@xxxtoolbar[1].txt
C:\Documents and Settings\Default User\Cookies\owner@yadro[1].txt
C:\Documents and Settings\Default User\Cookies\owner@yadro[2].txt
C:\Documents and Settings\Default User\Cookies\owner@yadro[3].txt
C:\Documents and Settings\Default User\Cookies\owner@yieldmanager[1].txt
C:\Documents and Settings\Default User\Cookies\owner@yieldmanager[2].txt
C:\Documents and Settings\Default User\Cookies\owner@yieldmanager[3].txt
C:\Documents and Settings\Default User\Cookies\owner@yieldmanager[4].txt
C:\Documents and Settings\Default User\Cookies\owner@yieldmanager[5].txt

rainshield
2007-12-07, 07:47
C:\Documents and Settings\Default User\Cookies\owner@yieldmanager[7].txt
C:\Documents and Settings\Default User\Cookies\owner@yourmedia[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ysbweb[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ysbweb[2].txt
C:\Documents and Settings\Default User\Cookies\owner@z1.adserver[1].txt
C:\Documents and Settings\Default User\Cookies\owner@z1.adserver[2].txt
C:\Documents and Settings\Default User\Cookies\owner@z1.adserver[3].txt
C:\Documents and Settings\Default User\Cookies\owner@z1.adserver[4].txt
C:\Documents and Settings\Default User\Cookies\owner@z1.adserver[5].txt
C:\Documents and Settings\Default User\Cookies\owner@z1.adserver[6].txt
C:\Documents and Settings\Default User\Cookies\owner@z1.adserver[7].txt
C:\Documents and Settings\Default User\Cookies\owner@zedo[1].txt
C:\Documents and Settings\Default User\Cookies\owner@zedo[2].txt
C:\Documents and Settings\Default User\Cookies\owner@zedo[3].txt
C:\Documents and Settings\Default User\Cookies\owner@zedo[4].txt
C:\Documents and Settings\Default User\Cookies\owner@zedo[5].txt
C:\Documents and Settings\Default User\Cookies\owner@zedo[6].txt
C:\Documents and Settings\Default User\Cookies\owner@zedo[7].txt
C:\Documents and Settings\LocalService\Cookies\system@atdmt[1].txt
C:\Documents and Settings\LocalService\Cookies\system@enhance[2].txt
C:\Documents and Settings\LocalService\Cookies\system@findwhat[1].txt
C:\Documents and Settings\LocalService\Cookies\system@goclick[2].txt
C:\Documents and Settings\Owner\Cookies\owner@105-bmp.googleadservices[2].txt
C:\Documents and Settings\Owner\Cookies\owner@112.2o7[2].txt
C:\Documents and Settings\Owner\Cookies\owner@247realmedia[1].txt
C:\Documents and Settings\Owner\Cookies\owner@247realmedia[2].txt
C:\Documents and Settings\Owner\Cookies\owner@247realmedia[3].txt
C:\Documents and Settings\Owner\Cookies\owner@247realmedia[5].txt
C:\Documents and Settings\Owner\Cookies\owner@2o7[10].txt
C:\Documents and Settings\Owner\Cookies\owner@2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@2o7[2].txt
C:\Documents and Settings\Owner\Cookies\owner@2o7[3].txt
C:\Documents and Settings\Owner\Cookies\owner@2o7[4].txt
C:\Documents and Settings\Owner\Cookies\owner@2o7[5].txt
C:\Documents and Settings\Owner\Cookies\owner@2o7[6].txt
C:\Documents and Settings\Owner\Cookies\owner@2o7[7].txt
C:\Documents and Settings\Owner\Cookies\owner@2o7[8].txt
C:\Documents and Settings\Owner\Cookies\owner@2o7[9].txt
C:\Documents and Settings\Owner\Cookies\owner@3.adbrite[2].txt
C:\Documents and Settings\Owner\Cookies\owner@3d-sexgames[2].txt
C:\Documents and Settings\Owner\Cookies\owner@4.adbrite[1].txt
C:\Documents and Settings\Owner\Cookies\owner@4.adbrite[2].txt
C:\Documents and Settings\Owner\Cookies\owner@4.adbrite[3].txt
C:\Documents and Settings\Owner\Cookies\owner@4.adbrite[4].txt
C:\Documents and Settings\Owner\Cookies\owner@4.adbrite[6].txt
C:\Documents and Settings\Owner\Cookies\owner@67.15.239[1].txt
C:\Documents and Settings\Owner\Cookies\owner@a.tribalfusion[1].txt
C:\Documents and Settings\Owner\Cookies\owner@a.websponsors[1].txt
C:\Documents and Settings\Owner\Cookies\owner@a.websponsors[2].txt
C:\Documents and Settings\Owner\Cookies\owner@a.websponsors[4].txt
C:\Documents and Settings\Owner\Cookies\owner@acvs.mediaonenetwork[1].txt
C:\Documents and Settings\Owner\Cookies\owner@acvs.mediaonenetwork[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad-cross.co[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.adnetwork.com[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.bannerconnect[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.cnetym.cnet[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.hinet[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.interclick[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.media-servers[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.media-servers[3].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.outerinfoads[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.outerinfoads[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.outerinfoads[3].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.outerinfoads[4].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.outerinfo[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.outerinfo[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.outerinfo[3].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.outerinfo[5].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.outerinfo[6].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.sensismediasmart.com[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.xplusone[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.xplusone[3].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[10].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[11].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[13].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[3].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[4].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[5].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[6].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[7].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[8].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[9].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.zanox[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.zanox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.zanox[3].txt
C:\Documents and Settings\Owner\Cookies\owner@ad1.clickhype[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ad1.clickhype[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad1.clickhype[3].txt
C:\Documents and Settings\Owner\Cookies\owner@ad1.clickhype[4].txt
C:\Documents and Settings\Owner\Cookies\owner@ad1.emediate[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad2.adecn[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ad2.adnetinteractive[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad2.fotki[2].txt
C:\Documents and Settings\Owner\Cookies\owner@adbrite[10].txt
C:\Documents and Settings\Owner\Cookies\owner@adbrite[11].txt
C:\Documents and Settings\Owner\Cookies\owner@adbrite[1].txt
C:\Documents and Settings\Owner\Cookies\owner@adbrite[2].txt
C:\Documents and Settings\Owner\Cookies\owner@adbrite[3].txt
C:\Documents and Settings\Owner\Cookies\owner@adbrite[4].txt
C:\Documents and Settings\Owner\Cookies\owner@adbrite[5].txt
C:\Documents and Settings\Owner\Cookies\owner@adbrite[6].txt
C:\Documents and Settings\Owner\Cookies\owner@adbrite[7].txt
C:\Documents and Settings\Owner\Cookies\owner@adbrite[8].txt
C:\Documents and Settings\Owner\Cookies\owner@adecn[2].txt
C:\Documents and Settings\Owner\Cookies\owner@adinterax[1].txt
C:\Documents and Settings\Owner\Cookies\owner@adinterax[2].txt
C:\Documents and Settings\Owner\Cookies\owner@adinterax[3].txt
C:\Documents and Settings\Owner\Cookies\owner@adinterax[4].txt
C:\Documents and Settings\Owner\Cookies\owner@adinterax[5].txt
C:\Documents and Settings\Owner\Cookies\owner@adinterax[6].txt
C:\Documents and Settings\Owner\Cookies\owner@adinterax[7].txt
C:\Documents and Settings\Owner\Cookies\owner@adinterax[8].txt
C:\Documents and Settings\Owner\Cookies\owner@adknowledge[2].txt
C:\Documents and Settings\Owner\Cookies\owner@adknowledge[3].txt
C:\Documents and Settings\Owner\Cookies\owner@adknowledge[4].txt
C:\Documents and Settings\Owner\Cookies\owner@adlegend[1].txt
C:\Documents and Settings\Owner\Cookies\owner@adlegend[2].txt
C:\Documents and Settings\Owner\Cookies\owner@adlegend[3].txt
C:\Documents and Settings\Owner\Cookies\owner@adlegend[4].txt
C:\Documents and Settings\Owner\Cookies\owner@adlegend[5].txt
C:\Documents and Settings\Owner\Cookies\owner@adlegend[6].txt
C:\Documents and Settings\Owner\Cookies\owner@adlegend[7].txt
C:\Documents and Settings\Owner\Cookies\owner@adlegend[8].txt
C:\Documents and Settings\Owner\Cookies\owner@admarketplace[1].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.euroclick[11].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.euroclick[1].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.euroclick[2].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.euroclick[3].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.euroclick[4].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.euroclick[5].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.euroclick[6].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.euroclick[7].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.euroclick[8].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.euroclick[9].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.hbmediapro[2].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.hbmediapro[3].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.hbmediapro[4].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.specificclick[1].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.specificclick[3].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.specificclick[4].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.specificclick[5].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.specificclick[6].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.specificclick[7].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.specificclick[8].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[10].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[11].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[12].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[13].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[14].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[15].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[16].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[17].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[18].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[19].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[1].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[20].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[21].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[22].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[24].txt

rainshield
2007-12-07, 07:48
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[2].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[3].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[4].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[5].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[6].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[7].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[8].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[9].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.12titans[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.adbrite[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.adbrite[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.adbrite[3].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.adbrite[4].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.adbrite[6].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.addynamix[10].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.addynamix[11].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.addynamix[12].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.addynamix[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.addynamix[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.addynamix[3].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.addynamix[4].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.addynamix[5].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.addynamix[6].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.addynamix[7].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.addynamix[9].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.as4x.tmcs[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.as4x.tmcs[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.blizzard[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.bridgetrack[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.cobrad[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.contactmusic[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.cosplay[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.gamershell[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.gamershell[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.gamershell[4].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.glispa[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.glispa[3].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.goyk[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.jokaroo[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.k8l[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.k8l[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.mediology[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.mininova[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.modthesims2[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.neodelight[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.o2[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.pointroll[10].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.pointroll[11].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.pointroll[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.pointroll[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.pointroll[3].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.pointroll[4].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.pointroll[5].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.pointroll[6].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.pointroll[7].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.pointroll[9].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.realtechnetwork[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.realtechnetwork[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.realtechnetwork[3].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.realtechnetwork[4].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.uncoverthenet[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.us.e-planning[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.videoadvertising[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads1.playforum[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads3.think-adz[1].txt
C:\Documents and Settings\Owner\Cookies\owner@adserve.webtoolcafe[1].txt
C:\Documents and Settings\Owner\Cookies\owner@adserver.adreactor[1].txt
C:\Documents and Settings\Owner\Cookies\owner@adserver.adreactor[2].txt
C:\Documents and Settings\Owner\Cookies\owner@adserver.adreactor[3].txt
C:\Documents and Settings\Owner\Cookies\owner@adserver.filefront[1].txt
C:\Documents and Settings\Owner\Cookies\owner@adserver.filefront[2].txt
C:\Documents and Settings\Owner\Cookies\owner@adserver[1].txt
C:\Documents and Settings\Owner\Cookies\owner@adserver[2].txt
C:\Documents and Settings\Owner\Cookies\owner@adserver[3].txt
C:\Documents and Settings\Owner\Cookies\owner@adserver[4].txt
C:\Documents and Settings\Owner\Cookies\owner@adserver[5].txt
C:\Documents and Settings\Owner\Cookies\owner@adserving.cpxinteractive[2].txt
C:\Documents and Settings\Owner\Cookies\owner@adtech[1].txt
C:\Documents and Settings\Owner\Cookies\owner@adtech[2].txt
C:\Documents and Settings\Owner\Cookies\owner@adtech[3].txt
C:\Documents and Settings\Owner\Cookies\owner@adtech[4].txt
C:\Documents and Settings\Owner\Cookies\owner@adtech[6].txt
C:\Documents and Settings\Owner\Cookies\owner@adultadworld[1].txt
C:\Documents and Settings\Owner\Cookies\owner@adultadworld[2].txt
C:\Documents and Settings\Owner\Cookies\owner@adultadworld[4].txt
C:\Documents and Settings\Owner\Cookies\owner@adultadworld[5].txt
C:\Documents and Settings\Owner\Cookies\owner@adultadworld[6].txt
C:\Documents and Settings\Owner\Cookies\owner@adultfriendfinder[2].txt
C:\Documents and Settings\Owner\Cookies\owner@adv.publiweb[1].txt
C:\Documents and Settings\Owner\Cookies\owner@advertising[10].txt
C:\Documents and Settings\Owner\Cookies\owner@advertising[11].txt
C:\Documents and Settings\Owner\Cookies\owner@advertising[12].txt
C:\Documents and Settings\Owner\Cookies\owner@advertising[1].txt
C:\Documents and Settings\Owner\Cookies\owner@advertising[2].txt
C:\Documents and Settings\Owner\Cookies\owner@advertising[3].txt
C:\Documents and Settings\Owner\Cookies\owner@advertising[4].txt
C:\Documents and Settings\Owner\Cookies\owner@advertising[5].txt
C:\Documents and Settings\Owner\Cookies\owner@advertising[6].txt
C:\Documents and Settings\Owner\Cookies\owner@advertising[7].txt
C:\Documents and Settings\Owner\Cookies\owner@advertising[8].txt
C:\Documents and Settings\Owner\Cookies\owner@advertising[9].txt
C:\Documents and Settings\Owner\Cookies\owner@anad.tacoda[1].txt
C:\Documents and Settings\Owner\Cookies\owner@anad.tacoda[2].txt
C:\Documents and Settings\Owner\Cookies\owner@anad.tacoda[3].txt
C:\Documents and Settings\Owner\Cookies\owner@anad.tacoda[4].txt
C:\Documents and Settings\Owner\Cookies\owner@anad.tacoda[5].txt
C:\Documents and Settings\Owner\Cookies\owner@anad.tacoda[6].txt
C:\Documents and Settings\Owner\Cookies\owner@anad.tacoda[8].txt
C:\Documents and Settings\Owner\Cookies\owner@anat.tacoda[1].txt
C:\Documents and Settings\Owner\Cookies\owner@anat.tacoda[2].txt
C:\Documents and Settings\Owner\Cookies\owner@anat.tacoda[3].txt
C:\Documents and Settings\Owner\Cookies\owner@anat.tacoda[4].txt
C:\Documents and Settings\Owner\Cookies\owner@angleinteractive.directtrack[2].txt
C:\Documents and Settings\Owner\Cookies\owner@apmebf[10].txt
C:\Documents and Settings\Owner\Cookies\owner@apmebf[1].txt
C:\Documents and Settings\Owner\Cookies\owner@apmebf[2].txt
C:\Documents and Settings\Owner\Cookies\owner@apmebf[3].txt
C:\Documents and Settings\Owner\Cookies\owner@apmebf[4].txt
C:\Documents and Settings\Owner\Cookies\owner@apmebf[5].txt
C:\Documents and Settings\Owner\Cookies\owner@apmebf[6].txt
C:\Documents and Settings\Owner\Cookies\owner@apmebf[7].txt
C:\Documents and Settings\Owner\Cookies\owner@apmebf[8].txt
C:\Documents and Settings\Owner\Cookies\owner@apmebf[9].txt
C:\Documents and Settings\Owner\Cookies\owner@as-eu.falkag[1].txt
C:\Documents and Settings\Owner\Cookies\owner@as-eu.falkag[2].txt
C:\Documents and Settings\Owner\Cookies\owner@as-eu.falkag[3].txt
C:\Documents and Settings\Owner\Cookies\owner@as-eu.falkag[4].txt
C:\Documents and Settings\Owner\Cookies\owner@as-us.falkag[1].txt
C:\Documents and Settings\Owner\Cookies\owner@as-us.falkag[2].txt
C:\Documents and Settings\Owner\Cookies\owner@as-us.falkag[4].txt
C:\Documents and Settings\Owner\Cookies\owner@as1.falkag[1].txt
C:\Documents and Settings\Owner\Cookies\owner@atdmt[10].txt
C:\Documents and Settings\Owner\Cookies\owner@atdmt[11].txt
C:\Documents and Settings\Owner\Cookies\owner@atdmt[12].txt
C:\Documents and Settings\Owner\Cookies\owner@atdmt[2].txt
C:\Documents and Settings\Owner\Cookies\owner@atdmt[3].txt
C:\Documents and Settings\Owner\Cookies\owner@atdmt[4].txt
C:\Documents and Settings\Owner\Cookies\owner@atdmt[5].txt
C:\Documents and Settings\Owner\Cookies\owner@atdmt[6].txt
C:\Documents and Settings\Owner\Cookies\owner@atdmt[7].txt
C:\Documents and Settings\Owner\Cookies\owner@atdmt[8].txt
C:\Documents and Settings\Owner\Cookies\owner@atdmt[9].txt
C:\Documents and Settings\Owner\Cookies\owner@atwola[10].txt
C:\Documents and Settings\Owner\Cookies\owner@atwola[11].txt
C:\Documents and Settings\Owner\Cookies\owner@atwola[1].txt
C:\Documents and Settings\Owner\Cookies\owner@atwola[2].txt
C:\Documents and Settings\Owner\Cookies\owner@atwola[3].txt
C:\Documents and Settings\Owner\Cookies\owner@atwola[4].txt
C:\Documents and Settings\Owner\Cookies\owner@atwola[5].txt
C:\Documents and Settings\Owner\Cookies\owner@atwola[6].txt
C:\Documents and Settings\Owner\Cookies\owner@atwola[7].txt
C:\Documents and Settings\Owner\Cookies\owner@atwola[8].txt
C:\Documents and Settings\Owner\Cookies\owner@atwola[9].txt
C:\Documents and Settings\Owner\Cookies\owner@audit.median[1].txt
C:\Documents and Settings\Owner\Cookies\owner@audit.median[2].txt
C:\Documents and Settings\Owner\Cookies\owner@audit.median[3].txt
C:\Documents and Settings\Owner\Cookies\owner@audit.median[4].txt
C:\Documents and Settings\Owner\Cookies\owner@audit.median[5].txt
C:\Documents and Settings\Owner\Cookies\owner@audit.median[6].txt
C:\Documents and Settings\Owner\Cookies\owner@azjmp[1].txt
C:\Documents and Settings\Owner\Cookies\owner@azjmp[2].txt
C:\Documents and Settings\Owner\Cookies\owner@azjmp[3].txt
C:\Documents and Settings\Owner\Cookies\owner@azjmp[4].txt
C:\Documents and Settings\Owner\Cookies\owner@azoogleads[1].txt
C:\Documents and Settings\Owner\Cookies\owner@azoogleads[2].txt
C:\Documents and Settings\Owner\Cookies\owner@azoogleads[4].txt
C:\Documents and Settings\Owner\Cookies\owner@banner.goldenpalace[2].txt
C:\Documents and Settings\Owner\Cookies\owner@banner[1].txt
C:\Documents and Settings\Owner\Cookies\owner@belnk[1].txt
C:\Documents and Settings\Owner\Cookies\owner@belnk[2].txt
C:\Documents and Settings\Owner\Cookies\owner@belnk[3].txt
C:\Documents and Settings\Owner\Cookies\owner@belnk[4].txt
C:\Documents and Settings\Owner\Cookies\owner@belnk[5].txt
C:\Documents and Settings\Owner\Cookies\owner@bidzcom.112.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@bluestreak[1].txt
C:\Documents and Settings\Owner\Cookies\owner@bluestreak[2].txt
C:\Documents and Settings\Owner\Cookies\owner@bluestreak[3].txt
C:\Documents and Settings\Owner\Cookies\owner@bluestreak[4].txt
C:\Documents and Settings\Owner\Cookies\owner@bluestreak[5].txt
C:\Documents and Settings\Owner\Cookies\owner@bluestreak[6].txt
C:\Documents and Settings\Owner\Cookies\owner@bluestreak[7].txt
C:\Documents and Settings\Owner\Cookies\owner@Brandie_Belle_gets_fucked_on_a_bed[1].txt
C:\Documents and Settings\Owner\Cookies\owner@bravenetmedianetwork[1].txt

rainshield
2007-12-07, 07:48
C:\Documents and Settings\Owner\Cookies\owner@bs.serving-sys[1].txt
C:\Documents and Settings\Owner\Cookies\owner@bs.serving-sys[2].txt
C:\Documents and Settings\Owner\Cookies\owner@bs.serving-sys[3].txt
C:\Documents and Settings\Owner\Cookies\owner@bs.serving-sys[4].txt
C:\Documents and Settings\Owner\Cookies\owner@bs.serving-sys[5].txt
C:\Documents and Settings\Owner\Cookies\owner@bs.serving-sys[6].txt
C:\Documents and Settings\Owner\Cookies\owner@bs.serving-sys[7].txt
C:\Documents and Settings\Owner\Cookies\owner@bs.serving-sys[9].txt
C:\Documents and Settings\Owner\Cookies\owner@burstnet[1].txt
C:\Documents and Settings\Owner\Cookies\owner@burstnet[2].txt
C:\Documents and Settings\Owner\Cookies\owner@burstnet[4].txt
C:\Documents and Settings\Owner\Cookies\owner@burstnet[5].txt
C:\Documents and Settings\Owner\Cookies\owner@burstnet[6].txt
C:\Documents and Settings\Owner\Cookies\owner@burstnet[7].txt
C:\Documents and Settings\Owner\Cookies\owner@buycom.122.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@c5.zedo[2].txt
C:\Documents and Settings\Owner\Cookies\owner@casalemedia[10].txt
C:\Documents and Settings\Owner\Cookies\owner@casalemedia[1].txt
C:\Documents and Settings\Owner\Cookies\owner@casalemedia[2].txt
C:\Documents and Settings\Owner\Cookies\owner@casalemedia[3].txt
C:\Documents and Settings\Owner\Cookies\owner@casalemedia[4].txt
C:\Documents and Settings\Owner\Cookies\owner@casalemedia[5].txt
C:\Documents and Settings\Owner\Cookies\owner@casalemedia[6].txt
C:\Documents and Settings\Owner\Cookies\owner@casalemedia[7].txt
C:\Documents and Settings\Owner\Cookies\owner@casalemedia[8].txt
C:\Documents and Settings\Owner\Cookies\owner@chetos-counter[1].txt
C:\Documents and Settings\Owner\Cookies\owner@chetos-counter[3].txt
C:\Documents and Settings\Owner\Cookies\owner@citi.bridgetrack[2].txt
C:\Documents and Settings\Owner\Cookies\owner@citi.bridgetrack[3].txt
C:\Documents and Settings\Owner\Cookies\owner@citi.bridgetrack[4].txt
C:\Documents and Settings\Owner\Cookies\owner@click.interactivebrands[1].txt
C:\Documents and Settings\Owner\Cookies\owner@clickbank[1].txt
C:\Documents and Settings\Owner\Cookies\owner@clickbank[2].txt
C:\Documents and Settings\Owner\Cookies\owner@clicksor[1].txt
C:\Documents and Settings\Owner\Cookies\owner@clicksor[2].txt
C:\Documents and Settings\Owner\Cookies\owner@clicksor[3].txt
C:\Documents and Settings\Owner\Cookies\owner@clicksor[4].txt
C:\Documents and Settings\Owner\Cookies\owner@clicksor[5].txt
C:\Documents and Settings\Owner\Cookies\owner@clicktorrent[1].txt
C:\Documents and Settings\Owner\Cookies\owner@clicktorrent[2].txt
C:\Documents and Settings\Owner\Cookies\owner@count1.exitexchange[1].txt
C:\Documents and Settings\Owner\Cookies\owner@count2.exitexchange[1].txt
C:\Documents and Settings\Owner\Cookies\owner@count3.exitexchange[1].txt
C:\Documents and Settings\Owner\Cookies\owner@count3.exitexchange[3].txt
C:\Documents and Settings\Owner\Cookies\owner@counter-strike-dl[2].txt
C:\Documents and Settings\Owner\Cookies\owner@counter-strike-hacks.us.intellitxt[1].txt
C:\Documents and Settings\Owner\Cookies\owner@counter-strike-hacks[2].txt
C:\Documents and Settings\Owner\Cookies\owner@counter.auctionworks[2].txt
C:\Documents and Settings\Owner\Cookies\owner@counter.hitslink[1].txt
C:\Documents and Settings\Owner\Cookies\owner@counter.hitslink[2].txt
C:\Documents and Settings\Owner\Cookies\owner@counter.hitslink[3].txt
C:\Documents and Settings\Owner\Cookies\owner@counter1.supercounter[1].txt
C:\Documents and Settings\Owner\Cookies\owner@counter1.supercounter[2].txt
C:\Documents and Settings\Owner\Cookies\owner@counter1.supercounter[3].txt
C:\Documents and Settings\Owner\Cookies\owner@counter11.sextracker[1].txt
C:\Documents and Settings\Owner\Cookies\owner@counter12.sextracker[1].txt
C:\Documents and Settings\Owner\Cookies\owner@counter12.sextracker[2].txt
C:\Documents and Settings\Owner\Cookies\owner@counter2.sextracker[1].txt
C:\Documents and Settings\Owner\Cookies\owner@counter5.sextracker[1].txt
C:\Documents and Settings\Owner\Cookies\owner@counterbank[2].txt
C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[10].txt
C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[2].txt
C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[3].txt
C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[4].txt
C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[5].txt
C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[6].txt
C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[7].txt
C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[8].txt
C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[9].txt
C:\Documents and Settings\Owner\Cookies\owner@cracker.com[2].txt
C:\Documents and Settings\Owner\Cookies\owner@crackserver[2].txt
C:\Documents and Settings\Owner\Cookies\owner@cs.sexcounter[2].txt
C:\Documents and Settings\Owner\Cookies\owner@cs.sexcounter[3].txt
C:\Documents and Settings\Owner\Cookies\owner@cz3.clickzs[2].txt
C:\Documents and Settings\Owner\Cookies\owner@cz4.clickzs[1].txt
C:\Documents and Settings\Owner\Cookies\owner@data1.perf.overture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@data2.perf.overture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@data2.perf.overture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@data2.perf.overture[3].txt
C:\Documents and Settings\Owner\Cookies\owner@data3.perf.overture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@data4.perf.overture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@data4.perf.overture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@dealtime[1].txt
C:\Documents and Settings\Owner\Cookies\owner@dealtime[2].txt
C:\Documents and Settings\Owner\Cookies\owner@dealtime[3].txt
C:\Documents and Settings\Owner\Cookies\owner@devart.adbureau[1].txt
C:\Documents and Settings\Owner\Cookies\owner@digus-sparda.tripod[1].txt
C:\Documents and Settings\Owner\Cookies\owner@directtrack[1].txt
C:\Documents and Settings\Owner\Cookies\owner@directtrack[2].txt
C:\Documents and Settings\Owner\Cookies\owner@directtrack[3].txt
C:\Documents and Settings\Owner\Cookies\owner@dist.belnk[2].txt
C:\Documents and Settings\Owner\Cookies\owner@dist.belnk[3].txt
C:\Documents and Settings\Owner\Cookies\owner@dist.belnk[4].txt
C:\Documents and Settings\Owner\Cookies\owner@dist.belnk[5].txt
C:\Documents and Settings\Owner\Cookies\owner@dist.belnk[6].txt
C:\Documents and Settings\Owner\Cookies\owner@divx.112.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@divx.112.2o7[2].txt
C:\Documents and Settings\Owner\Cookies\owner@divx.112.2o7[3].txt
C:\Documents and Settings\Owner\Cookies\owner@divx.112.2o7[4].txt
C:\Documents and Settings\Owner\Cookies\owner@divx.112.2o7[5].txt
C:\Documents and Settings\Owner\Cookies\owner@divx.adbureau[2].txt
C:\Documents and Settings\Owner\Cookies\owner@divx.adbureau[3].txt
C:\Documents and Settings\Owner\Cookies\owner@divx.adbureau[4].txt
C:\Documents and Settings\Owner\Cookies\owner@divx.adbureau[5].txt
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[10].txt
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[11].txt
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[12].txt
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[2].txt
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[3].txt
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[4].txt
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[5].txt
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[6].txt
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[7].txt
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[8].txt
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[9].txt
C:\Documents and Settings\Owner\Cookies\owner@drivecleaner[1].txt
C:\Documents and Settings\Owner\Cookies\owner@drivecleaner[2].txt
C:\Documents and Settings\Owner\Cookies\owner@drivecleaner[3].txt
C:\Documents and Settings\Owner\Cookies\owner@drivecleaner[4].txt
C:\Documents and Settings\Owner\Cookies\owner@drivecleaner[5].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wak4goc5kgo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wakoghajmgo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wakoqmazkko.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wakykjc5gfo.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wakyqgazego.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6waliemd5odo.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6waliopcjgdp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6waliwmczkao.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6walyegdjgfp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6walysoc5oko.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wbkogpdjweq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wblykpajifo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfk4apajckp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfk4apc5aaq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfk4khcpglo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfk4koajgaq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfk4olc5efo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfk4qgdpmkp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfk4slc5ico.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfk4uoc5cbp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfk4wgcjaco.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkickc5wlp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkiepczgbp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkigiazwdp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkigiazwdp.stats.esomniture[3].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkignc5ebo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkikmdjakp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkikpajeko.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkiokazafp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkiqjdpcho.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkiqjdpcho.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkisjczafq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkismazcfp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkisnczobp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkiwkdjggp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkiwkdjggp.stats.esomniture[3].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkiwndzafp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkocnazalo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkocpdjwdo.stats.esomniture[2].txt

rainshield
2007-12-07, 07:49
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkoeiajwcp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkoklazkkp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkokmdjocp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkoojdzofo.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkouiajcao.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkyomdjifp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkyskd5aao.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkyskd5aao.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkywkazwko.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkywmd5mhq.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfl4qgcpahq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfl4qidpclq.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfl4smcjwgp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfl4sndzsko.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfl4uodpabo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfliemd5ggp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wflioldzkap.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wflioldzkap.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wflioldzkap.stats.esomniture[4].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfliopd5kho.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfliqjczoeo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfliqlcjsho.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfliqndjckq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfliqoczkcp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wflisiazgko.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfliuiajkho.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wflocgajeko.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfloeodzmlp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfloeodzmlp.stats.esomniture[3].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wflogmazcao.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wflooicjkcp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfloomdjilp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfloomdjilp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wflooocjabp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wflospdzmfp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wflowhcpigq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wflyumdzeho.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmiemdjwbo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmienc5mgo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmiepdpcko.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmiepdpcko.stats.esomniture[3].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmiohajwbo.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmionajieo.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmionajieo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmionajieo.stats.esomniture[4].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmiqmazehq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmiqmcpwao.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmiupdjgdo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmiwmdjafq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmycnajwlp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmyqjcjgao.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmyqjcjgao.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmyqjcjgao.stats.esomniture[3].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmyqjcjgao.stats.esomniture[4].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmyqjcjgao.stats.esomniture[5].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmyqlcjccp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfmywpazslq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgk4kgazwhp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgk4qkd5egq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgk4wlc5eeq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkiencpoao.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkiepd5eap.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkigjdzwfp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkiqicpggp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkiundzoaq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkiwjdpsfo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkoaiajccq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkoapajako.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkocmdzwep.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkoemcjscq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkoqjcpwkp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkoqmajahq.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkoqocpeep.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkoupcpgfp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkowndjggp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkyakd5kkq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkyemc5oco.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkyoicjefp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkysiczego.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkysjd5eeo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkysjd5eeo.stats.esomniture[3].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkyskazklp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkywicpskp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkywnc5agp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgl4giajgeq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgl4gpcjieo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgl4wlc5iho.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgliaocjwcp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wglioiazaeo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgmigmd5cgq.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgmigmd5cgq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgmiohczilo.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgmiskajsgo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgmiuhcpcfp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgmycicpibp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgmygidzslp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgmygncpgfp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whk4end5mlo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whk4ooajkbo.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whk4ooajkbo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whkickdzoho.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whkiegdzmdo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whkieicpglp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whkiglczkap.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whkoakd5mdp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whkoakd5mep.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whkouicjwgo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whkyaiajacp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whkyaldzokp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whkyoncjklp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whkywjcjcbp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whl4khazmdp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whl4smc5kko.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whliakdzgdp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whliuhajmgo.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whliwlczkao.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whlocmczigo.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whloshajghp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whlychcziap.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whlyghdpakp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whlygoczobo.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whlyoiazweq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whlyooazibo.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whlyuhcjwho.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whmishajegq.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whmiskazklo.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whmiskazklo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whmycgc5wdo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whmyqnajabp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whmyuoazigp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjk4aid5khp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjk4eoczwhq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjk4eodpkap.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjk4ggcjshp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjk4gmdzecq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjk4kjazwho.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjk4qhajkeo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjk4qldjmgp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjk4skdzkbp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkocidjghp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkocndpwhp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkoggczeko.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkokncjieo.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkookdzacp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkoomdjkbq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkoondpcho.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkoskcjwho.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkosld5wgp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkougcjgap.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkoujcjehp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkoukc5kco.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkoulcpcdo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkowgdpkcp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkowgdpkcp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkowgdpkcp.stats.esomniture[3].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkowicpgho.stats.esomniture[2].txt

rainshield
2007-12-07, 07:50
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkowocjchp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkowocjchp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkowpdpsgp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkycic5okp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkyeldjgdp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkyeldjgdp.stats.esomniture[3].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkyggczcko.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkyggdzobp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkyggdzobp.stats.esomniture[3].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkyggdzobp.stats.esomniture[4].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkygkd5icp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkygmcjcgq.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkygmcjcgq.stats.esomniture[3].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkygmdjmlp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkygmdjmlp.stats.esomniture[3].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkyoidpeap.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkyooc5whp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkyqiazobo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkyqjdjwao.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkyshc5clp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkyshc5clp.stats.esomniture[3].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkywgczgao.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjl4cic5slo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjl4eodzsbp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjl4ghcpelp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjl4gldpccp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjl4ohczsgp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjl4oiajsco.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjl4oidzkco.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjl4oldpgho.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjl4sgcjcbq.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjl4snd5klq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjl4uhazeco.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjl4wlajifq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjliajdpibo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjliajdpkbp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjliejczolq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlieocjceo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlikhdzgco.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlikjcjwdq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlikmajigo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlikpdjsao.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjliqmazmap.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjliqnczebp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjliwkazceo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjliwkdzoaq.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjliwlcjilp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjloaldjkdo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjloamczmco.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlocgdjobp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlochczshq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlocmd5slo.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlokhc5cfp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlokicjshq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlookczgkp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjloslc5olp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlosoczkgo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlowkazwao.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlowldzghp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlycldjkgp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlyekdzcgp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlyencpelp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlyggcjcco.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlyggczsho.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlyglajchq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlykmdjshq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlyomazcfq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlyopajkap.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlyopdpwhp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlyqkajalq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlyqoc5olo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlyqpajoko.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlysncpelo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlyspd5meo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlyspdzcko.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjmiahajckq.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjmickcjoep.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjmigldpcfo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjmiokdzahp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjmisgdzckp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjmisoajaep.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjmiugazseq.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjmycjc5khp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjmygoczgco.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjmyklajoco.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjmyopdzodq.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjmyqgcpgho.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjny-1gajsh.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjny-1gajsh.stats.esomniture[3].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjny-1iazok.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjny-1kajod.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjny-1oajah.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjny-1ocjga.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnyajajogp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnyajajogp.stats.esomniture[3].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnyajdzclp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnyamcjsep.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnyclazmao.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnyeldzmao.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnygjcpsho.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnygmdjogo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnygpazeho.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnyogd5kbp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnyomczwep.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnyondjikp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnyskajgkp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnyskcpkhp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnyulajoap.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnyuncjabo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnyupczmlo.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnywjc5aep.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnywkd5gdp.stats.esomniture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnywmczilp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjnywmd5mbp.stats.esomniture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@eas.apm.emediate[2].txt
C:\Documents and Settings\Owner\Cookies\owner@eastwickcbb24.tripod[1].txt
C:\Documents and Settings\Owner\Cookies\owner@edge.ru4[10].txt
C:\Documents and Settings\Owner\Cookies\owner@edge.ru4[1].txt
C:\Documents and Settings\Owner\Cookies\owner@edge.ru4[2].txt
C:\Documents and Settings\Owner\Cookies\owner@edge.ru4[3].txt
C:\Documents and Settings\Owner\Cookies\owner@edge.ru4[4].txt
C:\Documents and Settings\Owner\Cookies\owner@edge.ru4[5].txt
C:\Documents and Settings\Owner\Cookies\owner@edge.ru4[6].txt
C:\Documents and Settings\Owner\Cookies\owner@edge.ru4[7].txt
C:\Documents and Settings\Owner\Cookies\owner@edge.ru4[8].txt
C:\Documents and Settings\Owner\Cookies\owner@edge.ru4[9].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-apcc.hitbox[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-bestbuy.hitbox[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-cardomain.hitbox[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-cardomain.hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-chrysler.hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-ctv.hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-daveandbusters.hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-digg.hitbox[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-digg.hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-eline.hitbox[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-euromonitor.hitbox[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-gamespot.hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-gamespot.hitbox[3].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-globalgamingleague.hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-groupernetworks.hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-groupernetworks.hitbox[3].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-idgentertainment.hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-lowermybills.hitbox[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-maniatv.hitbox[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-maniatv.hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-maniatv.hitbox[4].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-netquote.hitbox[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-pcsecurityshield.hitbox[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-playboy.hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-primedia.hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-publiciswest.hitbox[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-randomhouse.hitbox[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-sonycomputer.hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-traderpublishing.hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-veohnetworksinc.hitbox[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-veohnetworksinc.hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-veohnetworksinc.hitbox[3].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-veohnetworksinc.hitbox[4].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-veohnetworksinc.hitbox[5].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-vmixmediainc.hitbox[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-youtube.hitbox[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-youtube.hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-youtube.hitbox[3].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-youtube.hitbox[4].txt
C:\Documents and Settings\Owner\Cookies\owner@emarketmakers[2].txt
C:\Documents and Settings\Owner\Cookies\owner@entrepreneur.122.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@entrepreneur[1].txt
C:\Documents and Settings\Owner\Cookies\owner@entrepreneur[3].txt
C:\Documents and Settings\Owner\Cookies\owner@etronics.122.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@euros4click[2].txt
C:\Documents and Settings\Owner\Cookies\owner@exitexchange[1].txt
C:\Documents and Settings\Owner\Cookies\owner@exitexchange[2].txt
C:\Documents and Settings\Owner\Cookies\owner@exitexchange[4].txt
C:\Documents and Settings\Owner\Cookies\owner@eyewonder[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ez-tracks[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ezzs.valueclick[1].txt
C:\Documents and Settings\Owner\Cookies\owner@fastclick[10].txt
C:\Documents and Settings\Owner\Cookies\owner@fastclick[11].txt
C:\Documents and Settings\Owner\Cookies\owner@fastclick[1].txt
C:\Documents and Settings\Owner\Cookies\owner@fastclick[2].txt
C:\Documents and Settings\Owner\Cookies\owner@fastclick[3].txt
C:\Documents and Settings\Owner\Cookies\owner@fastclick[4].txt
C:\Documents and Settings\Owner\Cookies\owner@fastclick[5].txt
C:\Documents and Settings\Owner\Cookies\owner@fastclick[6].txt
C:\Documents and Settings\Owner\Cookies\owner@fastclick[7].txt
C:\Documents and Settings\Owner\Cookies\owner@fastclick[8].txt
C:\Documents and Settings\Owner\Cookies\owner@fastclick[9].txt
C:\Documents and Settings\Owner\Cookies\owner@fastestpossiblemap.tripod[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ffxcam.cracker.com[2].txt
C:\Documents and Settings\Owner\Cookies\owner@findwhat[1].txt
C:\Documents and Settings\Owner\Cookies\owner@fl01.ct2.comclick[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ford.112.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@fortunecity[2].txt
C:\Documents and Settings\Owner\Cookies\owner@fortunecity[3].txt
C:\Documents and Settings\Owner\Cookies\owner@gamestats[1].txt
C:\Documents and Settings\Owner\Cookies\owner@gamestats[3].txt
C:\Documents and Settings\Owner\Cookies\owner@go.drivecleaner[2].txt
C:\Documents and Settings\Owner\Cookies\owner@go.winantispyware[1].txt
C:\Documents and Settings\Owner\Cookies\owner@go.winantivirus[1].txt
C:\Documents and Settings\Owner\Cookies\owner@gostats[2].txt
C:\Documents and Settings\Owner\Cookies\owner@h.starware[1].txt
C:\Documents and Settings\Owner\Cookies\owner@h.starware[2].txt
C:\Documents and Settings\Owner\Cookies\owner@h.starware[3].txt
C:\Documents and Settings\Owner\Cookies\owner@haynet.adbureau[2].txt
C:\Documents and Settings\Owner\Cookies\owner@hc2.humanclick[1].txt
C:\Documents and Settings\Owner\Cookies\owner@heavycom.122.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@heavycom.122.2o7[2].txt
C:\Documents and Settings\Owner\Cookies\owner@hentaicounter[1].txt
C:\Documents and Settings\Owner\Cookies\owner@hitbox[10].txt
C:\Documents and Settings\Owner\Cookies\owner@hitbox[1].txt
C:\Documents and Settings\Owner\Cookies\owner@hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@hitbox[3].txt
C:\Documents and Settings\Owner\Cookies\owner@hitbox[4].txt
C:\Documents and Settings\Owner\Cookies\owner@hitbox[5].txt
C:\Documents and Settings\Owner\Cookies\owner@hitbox[6].txt
C:\Documents and Settings\Owner\Cookies\owner@hitbox[7].txt
C:\Documents and Settings\Owner\Cookies\owner@hitbox[9].txt
C:\Documents and Settings\Owner\Cookies\owner@hotlog[1].txt
C:\Documents and Settings\Owner\Cookies\owner@hotlog[2].txt
C:\Documents and Settings\Owner\Cookies\owner@i.screensavers[1].txt

rainshield
2007-12-07, 07:52
C:\Documents and Settings\Owner\Cookies\owner@i.screensavers[2].txt
C:\Documents and Settings\Owner\Cookies\owner@icc.intellisrv[2].txt
C:\Documents and Settings\Owner\Cookies\owner@icc.intellisrv[3].txt
C:\Documents and Settings\Owner\Cookies\owner@icc.intellisrv[4].txt
C:\Documents and Settings\Owner\Cookies\owner@ice.112.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@image.masterstats[1].txt
C:\Documents and Settings\Owner\Cookies\owner@image.masterstats[2].txt
C:\Documents and Settings\Owner\Cookies\owner@image.masterstats[3].txt
C:\Documents and Settings\Owner\Cookies\owner@indexstats[2].txt
C:\Documents and Settings\Owner\Cookies\owner@indextools[2].txt
C:\Documents and Settings\Owner\Cookies\owner@inet-traffic[1].txt
C:\Documents and Settings\Owner\Cookies\owner@intaclick[2].txt
C:\Documents and Settings\Owner\Cookies\owner@interclick[11].txt
C:\Documents and Settings\Owner\Cookies\owner@interclick[1].txt
C:\Documents and Settings\Owner\Cookies\owner@interclick[2].txt
C:\Documents and Settings\Owner\Cookies\owner@interclick[3].txt
C:\Documents and Settings\Owner\Cookies\owner@interclick[4].txt
C:\Documents and Settings\Owner\Cookies\owner@interclick[5].txt
C:\Documents and Settings\Owner\Cookies\owner@interclick[6].txt
C:\Documents and Settings\Owner\Cookies\owner@interclick[7].txt
C:\Documents and Settings\Owner\Cookies\owner@interclick[8].txt
C:\Documents and Settings\Owner\Cookies\owner@interclick[9].txt
C:\Documents and Settings\Owner\Cookies\owner@itxt.vibrantmedia[1].txt
C:\Documents and Settings\Owner\Cookies\owner@jibjab.112.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@kaboose.112.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@kanoodle[1].txt
C:\Documents and Settings\Owner\Cookies\owner@kanoodle[2].txt
C:\Documents and Settings\Owner\Cookies\owner@kanoodle[3].txt
C:\Documents and Settings\Owner\Cookies\owner@keywordmax[1].txt
C:\Documents and Settings\Owner\Cookies\owner@kmpads[2].txt
C:\Documents and Settings\Owner\Cookies\owner@koadserver[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ladyshock.tripod[1].txt
C:\Documents and Settings\Owner\Cookies\owner@linksynergy[1].txt
C:\Documents and Settings\Owner\Cookies\owner@linksynergy[2].txt
C:\Documents and Settings\Owner\Cookies\owner@linksynergy[3].txt
C:\Documents and Settings\Owner\Cookies\owner@linksynergy[4].txt
C:\Documents and Settings\Owner\Cookies\owner@linksynergy[5].txt
C:\Documents and Settings\Owner\Cookies\owner@linkto.mediafire[2].txt
C:\Documents and Settings\Owner\Cookies\owner@login.revenueloop[2].txt
C:\Documents and Settings\Owner\Cookies\owner@login.tracking101[2].txt
C:\Documents and Settings\Owner\Cookies\owner@login.tracking101[3].txt
C:\Documents and Settings\Owner\Cookies\owner@login.tracking101[4].txt
C:\Documents and Settings\Owner\Cookies\owner@lstat.youku[2].txt
C:\Documents and Settings\Owner\Cookies\owner@m1.webstats4u[2].txt
C:\Documents and Settings\Owner\Cookies\owner@m1.webstats4u[3].txt
C:\Documents and Settings\Owner\Cookies\owner@m1.webstats4u[4].txt
C:\Documents and Settings\Owner\Cookies\owner@m1.webstats4u[5].txt
C:\Documents and Settings\Owner\Cookies\owner@marketworksinc.122.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@maxserving[1].txt
C:\Documents and Settings\Owner\Cookies\owner@maxserving[2].txt
C:\Documents and Settings\Owner\Cookies\owner@maxserving[3].txt
C:\Documents and Settings\Owner\Cookies\owner@maxserving[4].txt
C:\Documents and Settings\Owner\Cookies\owner@maxserving[5].txt
C:\Documents and Settings\Owner\Cookies\owner@media.adrevolver[1].txt
C:\Documents and Settings\Owner\Cookies\owner@media.fastclick[1].txt
C:\Documents and Settings\Owner\Cookies\owner@media.fastclick[3].txt
C:\Documents and Settings\Owner\Cookies\owner@media.www.dailytexanonline[1].txt
C:\Documents and Settings\Owner\Cookies\owner@mediafire[2].txt
C:\Documents and Settings\Owner\Cookies\owner@mediafire[3].txt
C:\Documents and Settings\Owner\Cookies\owner@mediaonenetwork[1].txt
C:\Documents and Settings\Owner\Cookies\owner@mediaonenetwork[2].txt
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[11].txt
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[12].txt
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[1].txt
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[2].txt
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[3].txt
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[4].txt
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[5].txt
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[6].txt
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[7].txt
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[8].txt
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[9].txt
C:\Documents and Settings\Owner\Cookies\owner@mediatraffic[2].txt
C:\Documents and Settings\Owner\Cookies\owner@mediatraffic[3].txt
C:\Documents and Settings\Owner\Cookies\owner@metacafe.122.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@metacafe.122.2o7[2].txt
C:\Documents and Settings\Owner\Cookies\owner@metacafe.122.2o7[3].txt
C:\Documents and Settings\Owner\Cookies\owner@metacafe.122.2o7[4].txt
C:\Documents and Settings\Owner\Cookies\owner@metacafe.122.2o7[5].txt
C:\Documents and Settings\Owner\Cookies\owner@microsofteup.112.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@microsofteup.112.2o7[2].txt
C:\Documents and Settings\Owner\Cookies\owner@microsofteup.112.2o7[3].txt
C:\Documents and Settings\Owner\Cookies\owner@microsoftwlmessengermkt.112.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@microsoftwlmessengermkt.112.2o7[2].txt
C:\Documents and Settings\Owner\Cookies\owner@msnportal.112.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@msnportal.112.2o7[2].txt
C:\Documents and Settings\Owner\Cookies\owner@msnportal.112.2o7[3].txt
C:\Documents and Settings\Owner\Cookies\owner@msnportal.112.2o7[4].txt
C:\Documents and Settings\Owner\Cookies\owner@msnportal.112.2o7[5].txt
C:\Documents and Settings\Owner\Cookies\owner@msnportal.112.2o7[6].txt
C:\Documents and Settings\Owner\Cookies\owner@msnportal.112.2o7[7].txt
C:\Documents and Settings\Owner\Cookies\owner@mystat.synch[2].txt
C:\Documents and Settings\Owner\Cookies\owner@nac.nasmedia.co[2].txt
C:\Documents and Settings\Owner\Cookies\owner@nbads[2].txt
C:\Documents and Settings\Owner\Cookies\owner@network.realmedia[1].txt
C:\Documents and Settings\Owner\Cookies\owner@nextag[1].txt
C:\Documents and Settings\Owner\Cookies\owner@nextag[2].txt
C:\Documents and Settings\Owner\Cookies\owner@nextag[3].txt
C:\Documents and Settings\Owner\Cookies\owner@nextag[4].txt
C:\Documents and Settings\Owner\Cookies\owner@nextclick.directtrack[2].txt
C:\Documents and Settings\Owner\Cookies\owner@nextclick.directtrack[3].txt
C:\Documents and Settings\Owner\Cookies\owner@nh1437.tripod[1].txt
C:\Documents and Settings\Owner\Cookies\owner@oasc06006.247realmedia[2].txt
C:\Documents and Settings\Owner\Cookies\owner@oddcast[1].txt
C:\Documents and Settings\Owner\Cookies\owner@onlinerewardcenter[2].txt
C:\Documents and Settings\Owner\Cookies\owner@optimize.indieclick[2].txt
C:\Documents and Settings\Owner\Cookies\owner@optimost[1].txt
C:\Documents and Settings\Owner\Cookies\owner@optimost[2].txt
C:\Documents and Settings\Owner\Cookies\owner@optimost[3].txt
C:\Documents and Settings\Owner\Cookies\owner@optimost[4].txt
C:\Documents and Settings\Owner\Cookies\owner@optimost[6].txt
C:\Documents and Settings\Owner\Cookies\owner@overture[10].txt
C:\Documents and Settings\Owner\Cookies\owner@overture[11].txt
C:\Documents and Settings\Owner\Cookies\owner@overture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@overture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@overture[3].txt
C:\Documents and Settings\Owner\Cookies\owner@overture[4].txt
C:\Documents and Settings\Owner\Cookies\owner@overture[5].txt
C:\Documents and Settings\Owner\Cookies\owner@overture[6].txt
C:\Documents and Settings\Owner\Cookies\owner@overture[7].txt
C:\Documents and Settings\Owner\Cookies\owner@overture[8].txt
C:\Documents and Settings\Owner\Cookies\owner@overture[9].txt
C:\Documents and Settings\Owner\Cookies\owner@pacificpoker[2].txt
C:\Documents and Settings\Owner\Cookies\owner@partner2profit[1].txt
C:\Documents and Settings\Owner\Cookies\owner@partners.adultadworld[2].txt
C:\Documents and Settings\Owner\Cookies\owner@partners.webmasterplan[1].txt
C:\Documents and Settings\Owner\Cookies\owner@partygaming.122.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@partygaming.122.2o7[2].txt
C:\Documents and Settings\Owner\Cookies\owner@partypoker[1].txt
C:\Documents and Settings\Owner\Cookies\owner@partypoker[2].txt
C:\Documents and Settings\Owner\Cookies\owner@paypal.112.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@paypal.112.2o7[2].txt
C:\Documents and Settings\Owner\Cookies\owner@paypal.112.2o7[3].txt
C:\Documents and Settings\Owner\Cookies\owner@paypal.112.2o7[4].txt
C:\Documents and Settings\Owner\Cookies\owner@paypal.112.2o7[5].txt
C:\Documents and Settings\Owner\Cookies\owner@perf.overture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@perf.overture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@perf.overture[3].txt
C:\Documents and Settings\Owner\Cookies\owner@perf.overture[4].txt
C:\Documents and Settings\Owner\Cookies\owner@perf.overture[5].txt
C:\Documents and Settings\Owner\Cookies\owner@perf.overture[6].txt
C:\Documents and Settings\Owner\Cookies\owner@perf.overture[7].txt
C:\Documents and Settings\Owner\Cookies\owner@phg.hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@podtrac.advertserve[1].txt
C:\Documents and Settings\Owner\Cookies\owner@popularmedia.directtrack[2].txt
C:\Documents and Settings\Owner\Cookies\owner@popularmedia.directtrack[3].txt
C:\Documents and Settings\Owner\Cookies\owner@pornotube[2].txt
C:\Documents and Settings\Owner\Cookies\owner@primedia.us.intellitxt[1].txt
C:\Documents and Settings\Owner\Cookies\owner@primediamags[1].txt
C:\Documents and Settings\Owner\Cookies\owner@publishers.clickbooth[1].txt
C:\Documents and Settings\Owner\Cookies\owner@qksrv[1].txt
C:\Documents and Settings\Owner\Cookies\owner@qksrv[2].txt
C:\Documents and Settings\Owner\Cookies\owner@qksrv[3].txt
C:\Documents and Settings\Owner\Cookies\owner@qksrv[4].txt
C:\Documents and Settings\Owner\Cookies\owner@qnsr[1].txt
C:\Documents and Settings\Owner\Cookies\owner@qnsr[2].txt
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[10].txt
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[12].txt
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[1].txt
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[2].txt
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[3].txt
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[4].txt
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[5].txt
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[6].txt
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[7].txt
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[8].txt
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[9].txt
C:\Documents and Settings\Owner\Cookies\owner@realmedia[10].txt
C:\Documents and Settings\Owner\Cookies\owner@realmedia[12].txt
C:\Documents and Settings\Owner\Cookies\owner@realmedia[1].txt
C:\Documents and Settings\Owner\Cookies\owner@realmedia[2].txt
C:\Documents and Settings\Owner\Cookies\owner@realmedia[3].txt
C:\Documents and Settings\Owner\Cookies\owner@realmedia[4].txt
C:\Documents and Settings\Owner\Cookies\owner@realmedia[5].txt
C:\Documents and Settings\Owner\Cookies\owner@realmedia[6].txt
C:\Documents and Settings\Owner\Cookies\owner@realmedia[7].txt
C:\Documents and Settings\Owner\Cookies\owner@realmedia[8].txt
C:\Documents and Settings\Owner\Cookies\owner@realmedia[9].txt
C:\Documents and Settings\Owner\Cookies\owner@realnetworks.112.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@realnetworks.112.2o7[2].txt
C:\Documents and Settings\Owner\Cookies\owner@realnetworks.112.2o7[3].txt
C:\Documents and Settings\Owner\Cookies\owner@redorbit[1].txt
C:\Documents and Settings\Owner\Cookies\owner@redorbit[2].txt
C:\Documents and Settings\Owner\Cookies\owner@reduxads.valuead[2].txt
C:\Documents and Settings\Owner\Cookies\owner@reduxads.valuead[3].txt
C:\Documents and Settings\Owner\Cookies\owner@reduxads.valuead[4].txt
C:\Documents and Settings\Owner\Cookies\owner@reduxads.valuead[5].txt
C:\Documents and Settings\Owner\Cookies\owner@reduxads.valuead[6].txt
C:\Documents and Settings\Owner\Cookies\owner@revenue[1].txt
C:\Documents and Settings\Owner\Cookies\owner@revenue[3].txt
C:\Documents and Settings\Owner\Cookies\owner@revenue[4].txt
C:\Documents and Settings\Owner\Cookies\owner@revenue[5].txt
C:\Documents and Settings\Owner\Cookies\owner@revenue[6].txt
C:\Documents and Settings\Owner\Cookies\owner@revsci[10].txt
C:\Documents and Settings\Owner\Cookies\owner@revsci[11].txt
C:\Documents and Settings\Owner\Cookies\owner@revsci[1].txt
C:\Documents and Settings\Owner\Cookies\owner@revsci[2].txt
C:\Documents and Settings\Owner\Cookies\owner@revsci[3].txt
C:\Documents and Settings\Owner\Cookies\owner@revsci[4].txt
C:\Documents and Settings\Owner\Cookies\owner@revsci[5].txt
C:\Documents and Settings\Owner\Cookies\owner@revsci[6].txt
C:\Documents and Settings\Owner\Cookies\owner@revsci[7].txt
C:\Documents and Settings\Owner\Cookies\owner@revsci[8].txt
C:\Documents and Settings\Owner\Cookies\owner@revsci[9].txt
C:\Documents and Settings\Owner\Cookies\owner@richmedia.yahoo[1].txt
C:\Documents and Settings\Owner\Cookies\owner@richmedia.yahoo[2].txt
C:\Documents and Settings\Owner\Cookies\owner@roiservice[1].txt
C:\Documents and Settings\Owner\Cookies\owner@rotator.adjuggler[1].txt
C:\Documents and Settings\Owner\Cookies\owner@rotator.adjuggler[3].txt
C:\Documents and Settings\Owner\Cookies\owner@sajemedia.directtrack[2].txt
C:\Documents and Settings\Owner\Cookies\owner@sales.liveperson[1].txt
C:\Documents and Settings\Owner\Cookies\owner@screensavers[2].txt
C:\Documents and Settings\Owner\Cookies\owner@screensavers[3].txt
C:\Documents and Settings\Owner\Cookies\owner@serialls[2].txt
C:\Documents and Settings\Owner\Cookies\owner@servedby.adxpower[2].txt
C:\Documents and Settings\Owner\Cookies\owner@server.cpmstar[1].txt
C:\Documents and Settings\Owner\Cookies\owner@server.iad.liveperson[1].txt
C:\Documents and Settings\Owner\Cookies\owner@server.iad.liveperson[2].txt
C:\Documents and Settings\Owner\Cookies\owner@server.iad.liveperson[3].txt
C:\Documents and Settings\Owner\Cookies\owner@server.iad.liveperson[4].txt
C:\Documents and Settings\Owner\Cookies\owner@server.lon.liveperson[1].txt
C:\Documents and Settings\Owner\Cookies\owner@server.lon.liveperson[2].txt
C:\Documents and Settings\Owner\Cookies\owner@serving-sys[10].txt
C:\Documents and Settings\Owner\Cookies\owner@serving-sys[1].txt
C:\Documents and Settings\Owner\Cookies\owner@serving-sys[2].txt
C:\Documents and Settings\Owner\Cookies\owner@serving-sys[3].txt
C:\Documents and Settings\Owner\Cookies\owner@serving-sys[4].txt
C:\Documents and Settings\Owner\Cookies\owner@serving-sys[5].txt
C:\Documents and Settings\Owner\Cookies\owner@serving-sys[6].txt
C:\Documents and Settings\Owner\Cookies\owner@serving-sys[7].txt
C:\Documents and Settings\Owner\Cookies\owner@serving-sys[8].txt
C:\Documents and Settings\Owner\Cookies\owner@serving.rpowermedia[1].txt
C:\Documents and Settings\Owner\Cookies\owner@serving.rpowermedia[2].txt
C:\Documents and Settings\Owner\Cookies\owner@serving.rpowermedia[4].txt
C:\Documents and Settings\Owner\Cookies\owner@sevenloadgmbh.112.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@sexlist[2].txt
C:\Documents and Settings\Owner\Cookies\owner@sextalk.sexviet[2].txt
C:\Documents and Settings\Owner\Cookies\owner@sextalk.sexviet[3].txt
C:\Documents and Settings\Owner\Cookies\owner@sextalk.sexviet[4].txt
C:\Documents and Settings\Owner\Cookies\owner@sextracker[1].txt
C:\Documents and Settings\Owner\Cookies\owner@sextracker[2].txt
C:\Documents and Settings\Owner\Cookies\owner@sextracker[3].txt
C:\Documents and Settings\Owner\Cookies\owner@sextracker[4].txt
C:\Documents and Settings\Owner\Cookies\owner@sexviet[2].txt
C:\Documents and Settings\Owner\Cookies\owner@sexviet[3].txt
C:\Documents and Settings\Owner\Cookies\owner@sexviet[4].txt
C:\Documents and Settings\Owner\Cookies\owner@smileycentral[2].txt
C:\Documents and Settings\Owner\Cookies\owner@smileycentral[3].txt
C:\Documents and Settings\Owner\Cookies\owner@soundclick[1].txt
C:\Documents and Settings\Owner\Cookies\owner@soundclick[2].txt
C:\Documents and Settings\Owner\Cookies\owner@spamblockerutility[2].txt

rainshield
2007-12-07, 07:53
C:\Documents and Settings\Owner\Cookies\owner@specificclick[1].txt
C:\Documents and Settings\Owner\Cookies\owner@specificclick[2].txt
C:\Documents and Settings\Owner\Cookies\owner@specificclick[3].txt
C:\Documents and Settings\Owner\Cookies\owner@specificclick[4].txt
C:\Documents and Settings\Owner\Cookies\owner@specificclick[6].txt
C:\Documents and Settings\Owner\Cookies\owner@spylog[1].txt
C:\Documents and Settings\Owner\Cookies\owner@spylog[2].txt
C:\Documents and Settings\Owner\Cookies\owner@spylog[3].txt
C:\Documents and Settings\Owner\Cookies\owner@spylog[5].txt
C:\Documents and Settings\Owner\Cookies\owner@stat.dealtime[1].txt
C:\Documents and Settings\Owner\Cookies\owner@stat.dealtime[2].txt
C:\Documents and Settings\Owner\Cookies\owner@stat.dealtime[3].txt
C:\Documents and Settings\Owner\Cookies\owner@stat.dealtime[5].txt
C:\Documents and Settings\Owner\Cookies\owner@stat.mystat[2].txt
C:\Documents and Settings\Owner\Cookies\owner@stat.onestat[1].txt
C:\Documents and Settings\Owner\Cookies\owner@stat.onestat[2].txt
C:\Documents and Settings\Owner\Cookies\owner@stat.onestat[3].txt
C:\Documents and Settings\Owner\Cookies\owner@stat.onestat[4].txt
C:\Documents and Settings\Owner\Cookies\owner@stat.onestat[6].txt
C:\Documents and Settings\Owner\Cookies\owner@statcounter[10].txt
C:\Documents and Settings\Owner\Cookies\owner@statcounter[1].txt
C:\Documents and Settings\Owner\Cookies\owner@statcounter[2].txt
C:\Documents and Settings\Owner\Cookies\owner@statcounter[3].txt
C:\Documents and Settings\Owner\Cookies\owner@statcounter[4].txt
C:\Documents and Settings\Owner\Cookies\owner@statcounter[5].txt
C:\Documents and Settings\Owner\Cookies\owner@statcounter[6].txt
C:\Documents and Settings\Owner\Cookies\owner@statcounter[7].txt
C:\Documents and Settings\Owner\Cookies\owner@statcounter[8].txt
C:\Documents and Settings\Owner\Cookies\owner@statcounter[9].txt
C:\Documents and Settings\Owner\Cookies\owner@stats.adbrite[1].txt
C:\Documents and Settings\Owner\Cookies\owner@stats.drivecleaner[2].txt
C:\Documents and Settings\Owner\Cookies\owner@stats.drivecleaner[3].txt
C:\Documents and Settings\Owner\Cookies\owner@stats.drivecleaner[4].txt
C:\Documents and Settings\Owner\Cookies\owner@stats1.reliablestats[1].txt
C:\Documents and Settings\Owner\Cookies\owner@stats1.reliablestats[2].txt
C:\Documents and Settings\Owner\Cookies\owner@stats1.reliablestats[3].txt
C:\Documents and Settings\Owner\Cookies\owner@stats1.reliablestats[4].txt
C:\Documents and Settings\Owner\Cookies\owner@stats1.reliablestats[5].txt
C:\Documents and Settings\Owner\Cookies\owner@stats1.reliablestats[6].txt
C:\Documents and Settings\Owner\Cookies\owner@stats2.reliablestats[1].txt
C:\Documents and Settings\Owner\Cookies\owner@statse.webtrendslive[1].txt
C:\Documents and Settings\Owner\Cookies\owner@statse.webtrendslive[2].txt
C:\Documents and Settings\Owner\Cookies\owner@statse.webtrendslive[4].txt
C:\Documents and Settings\Owner\Cookies\owner@statse.webtrendslive[5].txt
C:\Documents and Settings\Owner\Cookies\owner@statse.webtrendslive[6].txt
C:\Documents and Settings\Owner\Cookies\owner@stats[1].txt
C:\Documents and Settings\Owner\Cookies\owner@stats[2].txt
C:\Documents and Settings\Owner\Cookies\owner@stats[3].txt
C:\Documents and Settings\Owner\Cookies\owner@stats[4].txt
C:\Documents and Settings\Owner\Cookies\owner@stats[5].txt
C:\Documents and Settings\Owner\Cookies\owner@stats[7].txt
C:\Documents and Settings\Owner\Cookies\owner@store.primediamags[1].txt
C:\Documents and Settings\Owner\Cookies\owner@t1.trackalyzer[1].txt
C:\Documents and Settings\Owner\Cookies\owner@tacoda[1].txt
C:\Documents and Settings\Owner\Cookies\owner@tacoda[2].txt
C:\Documents and Settings\Owner\Cookies\owner@tacoda[3].txt
C:\Documents and Settings\Owner\Cookies\owner@tacoda[4].txt
C:\Documents and Settings\Owner\Cookies\owner@tacoda[5].txt
C:\Documents and Settings\Owner\Cookies\owner@tacoda[6].txt
C:\Documents and Settings\Owner\Cookies\owner@tacoda[7].txt
C:\Documents and Settings\Owner\Cookies\owner@tacoda[8].txt
C:\Documents and Settings\Owner\Cookies\owner@tacoda[9].txt
C:\Documents and Settings\Owner\Cookies\owner@tagworld[1].txt
C:\Documents and Settings\Owner\Cookies\owner@targetnet[1].txt
C:\Documents and Settings\Owner\Cookies\owner@targetnet[2].txt
C:\Documents and Settings\Owner\Cookies\owner@tdstats[1].txt
C:\Documents and Settings\Owner\Cookies\owner@tdstats[2].txt
C:\Documents and Settings\Owner\Cookies\owner@tgn.122.2o7[1].txt
C:\Documents and Settings\Owner\Cookies\owner@toplist[1].txt
C:\Documents and Settings\Owner\Cookies\owner@toplist[2].txt
C:\Documents and Settings\Owner\Cookies\owner@toplist[3].txt
C:\Documents and Settings\Owner\Cookies\owner@toplist[4].txt
C:\Documents and Settings\Owner\Cookies\owner@toplist[5].txt
C:\Documents and Settings\Owner\Cookies\owner@track.adrevolver[1].txt
C:\Documents and Settings\Owner\Cookies\owner@track.adrevolver[2].txt
C:\Documents and Settings\Owner\Cookies\owner@track.bestbuy[2].txt
C:\Documents and Settings\Owner\Cookies\owner@tracker.bitebbs[2].txt
C:\Documents and Settings\Owner\Cookies\owner@tradedoubler[1].txt
C:\Documents and Settings\Owner\Cookies\owner@tradedoubler[2].txt
C:\Documents and Settings\Owner\Cookies\owner@tradedoubler[3].txt
C:\Documents and Settings\Owner\Cookies\owner@traffic.buyservices[1].txt
C:\Documents and Settings\Owner\Cookies\owner@trafficmp[10].txt
C:\Documents and Settings\Owner\Cookies\owner@trafficmp[11].txt
C:\Documents and Settings\Owner\Cookies\owner@trafficmp[12].txt
C:\Documents and Settings\Owner\Cookies\owner@trafficmp[1].txt
C:\Documents and Settings\Owner\Cookies\owner@trafficmp[2].txt
C:\Documents and Settings\Owner\Cookies\owner@trafficmp[3].txt
C:\Documents and Settings\Owner\Cookies\owner@trafficmp[4].txt
C:\Documents and Settings\Owner\Cookies\owner@trafficmp[5].txt
C:\Documents and Settings\Owner\Cookies\owner@trafficmp[6].txt
C:\Documents and Settings\Owner\Cookies\owner@trafficmp[7].txt
C:\Documents and Settings\Owner\Cookies\owner@trafficmp[8].txt
C:\Documents and Settings\Owner\Cookies\owner@tremor.adbureau[1].txt
C:\Documents and Settings\Owner\Cookies\owner@tremor.adbureau[2].txt
C:\Documents and Settings\Owner\Cookies\owner@tremor.adbureau[3].txt
C:\Documents and Settings\Owner\Cookies\owner@tremor.adbureau[5].txt
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[11].txt
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[1].txt
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[2].txt
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[3].txt
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[4].txt
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[5].txt
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[6].txt
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[7].txt
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[8].txt
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[9].txt
C:\Documents and Settings\Owner\Cookies\owner@tripod.lycos[1].txt
C:\Documents and Settings\Owner\Cookies\owner@tripod[1].txt
C:\Documents and Settings\Owner\Cookies\owner@tripod[2].txt
C:\Documents and Settings\Owner\Cookies\owner@tripod[3].txt
C:\Documents and Settings\Owner\Cookies\owner@tripod[4].txt
C:\Documents and Settings\Owner\Cookies\owner@tripod[5].txt
C:\Documents and Settings\Owner\Cookies\owner@tripod[6].txt
C:\Documents and Settings\Owner\Cookies\owner@tripod[7].txt
C:\Documents and Settings\Owner\Cookies\owner@try.starware[1].txt
C:\Documents and Settings\Owner\Cookies\owner@try.starware[2].txt
C:\Documents and Settings\Owner\Cookies\owner@try.starware[3].txt
C:\Documents and Settings\Owner\Cookies\owner@Two_Round_Ass_Babes_getting_fucked_[1].txt
C:\Documents and Settings\Owner\Cookies\owner@upspiral[1].txt
C:\Documents and Settings\Owner\Cookies\owner@us.adrevenue[2].txt
C:\Documents and Settings\Owner\Cookies\owner@usenext[1].txt
C:\Documents and Settings\Owner\Cookies\owner@usenext[2].txt
C:\Documents and Settings\Owner\Cookies\owner@usenext[4].txt
C:\Documents and Settings\Owner\Cookies\owner@valueclick[1].txt
C:\Documents and Settings\Owner\Cookies\owner@valueclick[2].txt
C:\Documents and Settings\Owner\Cookies\owner@valueclick[3].txt
C:\Documents and Settings\Owner\Cookies\owner@valueclick[4].txt
C:\Documents and Settings\Owner\Cookies\owner@vhost.oddcast[2].txt
C:\Documents and Settings\Owner\Cookies\owner@vip.clickzs[2].txt
C:\Documents and Settings\Owner\Cookies\owner@w121.hitbox[1].txt
C:\Documents and Settings\Owner\Cookies\owner@warlog[1].txt
C:\Documents and Settings\Owner\Cookies\owner@warlog[2].txt
C:\Documents and Settings\Owner\Cookies\owner@web4.realtracker[1].txt
C:\Documents and Settings\Owner\Cookies\owner@weborama[1].txt
C:\Documents and Settings\Owner\Cookies\owner@weborama[2].txt
C:\Documents and Settings\Owner\Cookies\owner@weborama[3].txt
C:\Documents and Settings\Owner\Cookies\owner@winantispyware[1].txt
C:\Documents and Settings\Owner\Cookies\owner@winantispyware[2].txt
C:\Documents and Settings\Owner\Cookies\owner@winantispyware[3].txt
C:\Documents and Settings\Owner\Cookies\owner@winantispyware[4].txt
C:\Documents and Settings\Owner\Cookies\owner@winantivirus[1].txt
C:\Documents and Settings\Owner\Cookies\owner@winantivirus[2].txt
C:\Documents and Settings\Owner\Cookies\owner@winantivirus[3].txt
C:\Documents and Settings\Owner\Cookies\owner@winantivirus[4].txt
C:\Documents and Settings\Owner\Cookies\owner@winantivirus[5].txt
C:\Documents and Settings\Owner\Cookies\owner@winantivirus[6].txt
C:\Documents and Settings\Owner\Cookies\owner@windowsmedia[1].txt
C:\Documents and Settings\Owner\Cookies\owner@windowsmedia[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.0stats[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.0stats[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.3d-sexgames[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.burstbeacon[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.burstbeacon[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.burstbeacon[3].txt
C:\Documents and Settings\Owner\Cookies\owner@www.burstbeacon[4].txt
C:\Documents and Settings\Owner\Cookies\owner@www.burstbeacon[5].txt
C:\Documents and Settings\Owner\Cookies\owner@www.burstbeacon[7].txt
C:\Documents and Settings\Owner\Cookies\owner@www.burstnet[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.burstnet[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.burstnet[3].txt
C:\Documents and Settings\Owner\Cookies\owner@www.burstnet[4].txt
C:\Documents and Settings\Owner\Cookies\owner@www.burstnet[5].txt
C:\Documents and Settings\Owner\Cookies\owner@www.burstnet[6].txt
C:\Documents and Settings\Owner\Cookies\owner@www.burstnet[8].txt
C:\Documents and Settings\Owner\Cookies\owner@www.claxonmedia[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.clickadswork[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.comprabanner[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.counter-strike-hacks[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.drivecleaner[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.ez-tracks[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.fullreleases[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.fullreleases[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.fullreleases[3].txt
C:\Documents and Settings\Owner\Cookies\owner@www.gamestats[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.jackpotmadness[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.koadserver[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.mo-media[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.pacificpoker[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.pornotube[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.poweradvertising[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.precisioncounter[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.romnation[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.romnation[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.rowise[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.screensavers[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.screensavers[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.sexuploader[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.smartadserver[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.smartadserver[3].txt
C:\Documents and Settings\Owner\Cookies\owner@www.soundclick[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.statsquick[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.stopzilla[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.upspiral[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.warezenergy[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.warezenergy[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.winantispyware[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.winantispyware[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.winantiviruspro[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.winantiviruspro[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.winantivirus[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.winantivirus[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.winantivirus[3].txt
C:\Documents and Settings\Owner\Cookies\owner@www.xctrk[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.xxxloading[2].txt
C:\Documents and Settings\Owner\Cookies\owner@xiti[1].txt
C:\Documents and Settings\Owner\Cookies\owner@xiti[2].txt
C:\Documents and Settings\Owner\Cookies\owner@xiti[3].txt
C:\Documents and Settings\Owner\Cookies\owner@xiti[4].txt
C:\Documents and Settings\Owner\Cookies\owner@xiti[5].txt
C:\Documents and Settings\Owner\Cookies\owner@xiti[6].txt
C:\Documents and Settings\Owner\Cookies\owner@xml.bravenetmedianetwork[1].txt
C:\Documents and Settings\Owner\Cookies\owner@xxxcounter[1].txt
C:\Documents and Settings\Owner\Cookies\owner@xxxle[2].txt
C:\Documents and Settings\Owner\Cookies\owner@yadro[1].txt
C:\Documents and Settings\Owner\Cookies\owner@yadro[2].txt
C:\Documents and Settings\Owner\Cookies\owner@yadro[3].txt
C:\Documents and Settings\Owner\Cookies\owner@yadro[4].txt
C:\Documents and Settings\Owner\Cookies\owner@yadro[5].txt
C:\Documents and Settings\Owner\Cookies\owner@yadro[6].txt
C:\Documents and Settings\Owner\Cookies\owner@yadro[7].txt

rainshield
2007-12-07, 07:54
C:\Documents and Settings\Owner\Cookies\owner@z1.adserver[1].txt
C:\Documents and Settings\Owner\Cookies\owner@zbox.zanox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@zedo[10].txt
C:\Documents and Settings\Owner\Cookies\owner@zedo[11].txt
C:\Documents and Settings\Owner\Cookies\owner@zedo[1].txt
C:\Documents and Settings\Owner\Cookies\owner@zedo[2].txt
C:\Documents and Settings\Owner\Cookies\owner@zedo[3].txt
C:\Documents and Settings\Owner\Cookies\owner@zedo[4].txt
C:\Documents and Settings\Owner\Cookies\owner@zedo[5].txt
C:\Documents and Settings\Owner\Cookies\owner@zedo[6].txt
C:\Documents and Settings\Owner\Cookies\owner@zedo[7].txt
C:\Documents and Settings\Owner\Cookies\owner@zedo[8].txt
C:\Documents and Settings\Owner\Cookies\owner@zedo[9].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@1.primaryads[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@247realmedia[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@247realmedia[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@247realmedia[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@247realmedia[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@2o7[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@2o7[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@2o7[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@2o7[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@2o7[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@2o7[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@2o7[8].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@a.websponsors[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@a.websponsors[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@a.websponsors[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@a.websponsors[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@a.websponsors[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad-cross.co[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad-cross.co[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad-indicator[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad.admarketplace[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad.admarketplace[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad.jamster[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad.reunion[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad.yieldmanager[10].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad.yieldmanager[11].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad.yieldmanager[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad.yieldmanager[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad.yieldmanager[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad.yieldmanager[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad.yieldmanager[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad.yieldmanager[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad.yieldmanager[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad.yieldmanager[9].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad.zanox[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad1.clickhype[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ad2.pamedia.com[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adbrite[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@addynamix[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adecn[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adecn[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adecn[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adecn[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adknowledge[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adknowledge[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adknowledge[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adknowledge[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adknowledge[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adknowledge[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adlegend[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@admarketplace[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adopt.hbmediapro[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adopt.hbmediapro[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adopt.hbmediapro[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adopt.hbmediapro[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adopt.hbmediapro[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adopt.hbmediapro[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adopt.hbmediapro[8].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adopt.hotbar[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adopt.hotbar[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adopt.hotbar[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adopt.hotbar[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adopt.hotbar[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adopt.specificclick[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adopt.specificclick[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adopt.specificclick[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adopt.specificclick[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adopt.specificclick[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adopt.specificclick[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adprofile[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adprofile[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adprofile[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adrevolver[10].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adrevolver[11].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adrevolver[12].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adrevolver[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adrevolver[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adrevolver[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adrevolver[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adrevolver[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adrevolver[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adrevolver[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adrevolver[8].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adrevolver[9].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.addynamix[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.addynamix[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.addynamix[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.addynamix[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.addynamix[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.addynamix[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.addynamix[8].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.as4x.tmcs[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.cc214142[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.cc214142[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.cc214142[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.digitalpoint[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.digitalpoint[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.digitalpoint[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.i-am-bored[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.monster[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.monster[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.pointroll[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.pointroll[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.pointroll[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.pointroll[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.pointroll[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.pointroll[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.pwcr[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.realcastmedia[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.realcastmedia[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.realcastmedia[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.us.e-planning[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads.us.e-planning[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads1.megaupload[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads1.megaupload[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads1.playforum[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ads1.revenue[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adserver.adreactor[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adserver.adreactor[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adserver.adreactor[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adserver.adremedy[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adserver.filefront[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adserver.filefront[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adserver.filefront[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adserver.filefront[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adserver.mpogonline[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adserver.rdtg[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adserver.sharewareonline[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adserver[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adstat.4u[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adtech[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adtrak[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adultbouncer[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adultbouncer[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adultfriendfinder[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adultfriendfinder[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@advertising[1].txt

rainshield
2007-12-07, 07:55
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@advertising[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@advertising[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@advertising[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@advertising[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@advertising[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@advertising[8].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@apmebf[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@apmebf[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@apmebf[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@apmebf[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@apmebf[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ar.atwola[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ar.atwola[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ar.atwola[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ar.atwola[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@as-eu.falkag[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@as-eu.falkag[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@as-eu.falkag[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@as-eu.falkag[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@as-us.falkag[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@as-us.falkag[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@as-us.falkag[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@as-us.falkag[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@as-us.falkag[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@as-us.falkag[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@as-us.falkag[8].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@as1.falkag[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@as1.falkag[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@as1.falkag[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@as1.falkag[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@as1.falkag[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@as1.falkag[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@atdmt[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@atdmt[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@atdmt[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@atdmt[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@atdmt[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@atdmt[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@atdmt[8].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ath.belnk[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ath.belnk[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ath.belnk[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@atwola[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@atwola[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@atwola[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@atwola[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@atwola[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@atwola[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@atwola[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@azjmp[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@azjmp[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@azjmp[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@azjmp[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@azjmp[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@banner.casinolasvegas[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@banner.goldenpalace[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@bannerspace[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@banners[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@banners[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@banners[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@banners[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@banners[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@banners[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@banner[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@belnk[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@belnk[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@belnk[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@belnk[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@belnk[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@belnk[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@bizrate[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@bluestreak[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@bluestreak[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@bluestreak[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@bluestreak[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@bs.serving-sys[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@bs.serving-sys[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@btg.btgrab[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@burstnet[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@burstnet[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@burstnet[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@burstnet[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@burstnet[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@buycom.122.2o7[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@c.enhance[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@c.enhance[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@c.enhance[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@c.enhance[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@c.goclick[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@c4.zedo[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@c5.zedo[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@casalemedia[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@casalemedia[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@casalemedia[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@casalemedia[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@casalemedia[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@casalemedia[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@casalemedia[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@casinolasvegas[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@cassava[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@cb.adprofile[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@cb.adprofile[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@centralmedia[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@certified-safe-downloads[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@citi.bridgetrack[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@citi.bridgetrack[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@citi.bridgetrack[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@citi.bridgetrack[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@citi.bridgetrack[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@citi.bridgetrack[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@cityclub.gamingpromo[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@click.revsharecash[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@clickbank[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@clicksor[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@clicktorrent[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@cliks[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@cnn.122.2o7[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@counter-strike-dl[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@counter.hitslink[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@counter1.supercounter[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@counter16.sextracker[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@cpvfeed[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@cpvfeed[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@cpvfeed[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@cpvfeed[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@cracks[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@creativeby.viewpoint[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@creativeby.viewpoint[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@creativeby.viewpoint[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@creativeby.viewpoint[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@cs.sexcounter[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@cz3.clickzs[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@cz3.clickzs[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@cz7.clickzs[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@cz8.clickzs[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@data2.perf.overture[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@data4.perf.overture[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@data4.perf.overture[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@dealtime[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@dealtime[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@directtrack[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@dist.belnk[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@dist.belnk[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@dist.belnk[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@dist.belnk[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@dist.belnk[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@dist.belnk[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@doubleclick[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@doubleclick[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@doubleclick[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@doubleclick[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@doubleclick[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@doubleclick[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@doubleclick[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@edge.ru4[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@edge.ru4[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@edge.ru4[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@edge.ru4[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@edge.ru4[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@edge.ru4[6].txt

rainshield
2007-12-07, 07:56
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ehg-adteractive.hitbox[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ehg-adteractive.hitbox[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ehg-ati.hitbox[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ehg-bestbuy.hitbox[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ehg-clearchannel.hitbox[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ehg-communityconnect.hitbox[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ehg-eline.hitbox[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ehg-gamespyinc.hitbox[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ehg-idg.hitbox[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ehg-idgentertainment.hitbox[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ehg-nestleusainc.hitbox[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ehg-streamload.hitbox[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ehg.hitbox[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@elite[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@emarketmakers[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@emarketmakers[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@emarketmakers[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@emarketmakers[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@emarketmakers[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@entrepreneur.122.2o7[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@entrepreneur.122.2o7[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@entrepreneur.122.2o7[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@etype.adbureau[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@exitexchange[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@exitexchange[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@exitexchange[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@exitexchange[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@exitexchange[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@exitexchange[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@experclick[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ez-tracks[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@eztracks.aavalue[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@fastclick[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@fastclick[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@fastclick[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@fastclick[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@fastclick[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@fastclick[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@fastclick[8].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@findwhat[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@findwhat[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@fortunecity[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@fortunecity[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@freeze.directtrack[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@funwebproducts[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@gamingpromo[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@goclick[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@goclick[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@gtb1.acecounter[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@gtb2.acecounter[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@gtp1.acecounter[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@h.starware[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@h.starware[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@h.starware[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hbmediapro[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hbmediapro[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hc2.humanclick[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hc2.humanclick[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hc2.humanclick[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hentaicounter[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hg1.hitbox[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hitbox[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hitbox[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hitbox[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hitbox[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hits.clickandtrack[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hits.clickandtrack[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hits.clickandtrack[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hits.clickandtrack[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hits.clickandtrack[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hits.clickandtrack[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hurricanedigitalmedia[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hurricanedigitalmedia[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hypertracker[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hypertracker[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hypertracker[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hypertracker[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@hypertracker[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@i.screensavers[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@i.screensavers[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@i.screensavers[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@i.screensavers[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@icc.intellisrv[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@icc.intellisrv[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@icc.intellisrv[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@icc.intellisrv[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@idesktopmedia.directtrack[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@image.masterstats[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@image.masterstats[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@imp.partner2profit[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@interclick[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@interclick[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@interclick[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@interclick[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@internetfuel[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@internetfuel[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@internetfuel[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@jamster[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@jamster[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@jamster[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@kanoodle[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@kanoodle[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@kanoodle[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@kanoodle[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@keywordmax[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@kmpads[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@kmpads[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@leadgenetwork[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@leadgenetwork[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@leadgenetwork[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@leadgenetwork[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@linksynergy[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@linksynergy[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@linksynergy[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@login.tracking101[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@login.tracking101[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@lynxtrack[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@maxserving[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@maxserving[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@maxserving[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@maxserving[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@maxserving[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@media.adrevolver[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@media.onlinewelten[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@media.top-banners[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@media2.onlinewelten[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@mediaplex[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@mediaplex[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@mediaplex[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@mediaplex[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@mediaplex[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@mediaplex[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@mediaplex[8].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@metareward[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@metareward[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@microsofteup.112.2o7[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@microsofteup.112.2o7[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@mmm.media-motor[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@mmm.media-motor[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@moneyjunkey.directtrack[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@msnportal.112.2o7[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@mywebsearch[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@nextag[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@nextag[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@nextag[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@nextag[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@offeroptimizer[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@offeroptimizer[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@offeroptimizer[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@oinadserve[2].txt

rainshield
2007-12-07, 07:57
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@onlinerewardcenter[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@onlinerewardcenter[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@onlinerewardcenter[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@onlinerewardcenter[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@onlinerewardcenter[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@overture[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@overture[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@pacificpoker[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@partner2profit[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@partner2profit[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@partygaming.122.2o7[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@partypoker.touchclarity[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@partypoker.touchclarity[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@partypoker[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@partypoker[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@partypoker[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@partypoker[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@partypoker[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@partypoker[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@paycounter[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@paypopup[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@paypopup[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@paypopup[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@perf.overture[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@perf.overture[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@perf.overture[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@perf.overture[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@perf.overture[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@perf.overture[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@perf.overture[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@pornaccess[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@pornaccess[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@pro-market[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@publishers.clickbooth[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@publishers.clickbooth[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@publishers.clickbooth[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@publishers.clickbooth[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@qksrv[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@qksrv[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@qksrv[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@qksrv[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@qksrv[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@qnsr[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@qnsr[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@qnsr[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@qnsr[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@qnsr[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@qnsr[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@qnsr[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@questionmarket[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@questionmarket[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@questionmarket[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@questionmarket[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@questionmarket[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@questionmarket[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@questionmarket[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@realmedia[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@realmedia[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@realmedia[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@realmedia[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@realmedia[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@realmedia[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@realmedia[8].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@redorbit[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@redorbit[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@reduxads.valuead[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@revenue[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@revenue[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@revenue[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@revenue[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@revenue[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@revenue[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@revsci[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@roiservice[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@roiservice[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@rotator.adjuggler[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@rotator.adjuggler[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@rotator.adjuggler[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@sales.liveperson[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@sav.coolsavings[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@searchbar.findthewebsiteyouneed[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@servedby.advertising[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@servedby.advertising[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@servedby.advertising[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@servedby.advertising[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@servedby.advertising[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@servedby.advertising[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@server.cpmstar[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@server.cpmstar[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@server.cpmstar[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@server.iad.liveperson[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@server.iad.liveperson[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@server.iad.liveperson[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@server.iad.liveperson[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@server.iad.liveperson[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@server.iad.liveperson[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@server2.bkvtrack[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@serving-sys[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@serving-sys[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@serving-sys[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@serving-sys[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@sexole[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@sextalk.sexviet[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@sextalk.sexviet[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@sextalk.sexviet[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@sextracker[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@sexviet[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@sexviet[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@sexviet[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@smileycentral[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@smileycentral[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@soundclick[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@specificclick[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@spylog[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@spylog[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@starware[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@starware[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@starware[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@starware[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@starware[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@stat.dealtime[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@stat.dealtime[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@stat.dealtime[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@stat.onestat[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@statcounter[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@statcounter[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@statcounter[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@statcounter[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@statcounter[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@statcounter[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@statcounter[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@stats1.reliablestats[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@stats1.reliablestats[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@stats1.reliablestats[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@statse.webtrendslive[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@statse.webtrendslive[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@statse.webtrendslive[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@statse.webtrendslive[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@stats[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@stats_[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@superstats[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@sxload[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tacoda[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tacoda[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tacoda[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tacoda[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tacoda[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tagworld[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@targetnet[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@targetnet[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@targetnet[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@targetnet[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@targetnet[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@targetnet[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@targetnet[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@toplist[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tour.splash.sexsearch[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tour.splash.sexsearch[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tour.splash.sexsearch[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tracking[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tracking[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tradedoubler[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tradedoubler[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tradedoubler[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tradedoubler[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tradedoubler[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tradedoubler[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@trafficdashboard[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@trafficmp[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@trafficmp[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@trafficmp[3].txt

rainshield
2007-12-07, 07:57
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@trafficmp[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@trafficmp[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@trafficmp[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@trafficmp[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@trafficmp[8].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tribalfusion[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tribalfusion[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tribalfusion[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tribalfusion[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tribalfusion[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tribalfusion[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tribalfusion[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tripod[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tripod[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@usenext[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@usenext[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@usenext[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@usenext[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@valueclick[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@valueclick[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@valueclick[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@valueclick[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@valueclick[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@warlog[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@warlog[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@web-nexus[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@web-nexus[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@web-nexus[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@web-nexus[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@web-nexus[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@web2.realtracker[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@webcam.sexole[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@webpower[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@windowsmedia[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@windowsmedia[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@windowsmedia[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@winfixer[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@winfixer[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@winfixer[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@winfixer[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.adserv[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.azoogleads[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.bannersandpopups[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.burstbeacon[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.burstbeacon[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.burstbeacon[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.burstbeacon[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.burstnet[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.clickedyclick[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.coolcounters[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.coolcounters[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.entrepreneur[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.entrepreneur[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.ez-tracks[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.findthewebsiteyouneed[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.glispatrack[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.penisbot[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.redorbit[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.screensavers[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.screensavers[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.screensavers[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.screensavers[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.screensavers[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.sexuploader[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.sexviet[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.sexviet[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.starware[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.starware[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.stopzilla[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.tagworld[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.winantiviruspro[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.winantivirus[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.winfixer[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.xctrk[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.xctrk[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.xctrk[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.zanox-affiliate[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www.zanox-affiliate[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@www9.dealtime[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@xiti[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@xxxcounter[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@xxxtoolbar[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@yadro[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@yadro[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@yadro[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@yieldmanager[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@yieldmanager[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@yieldmanager[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@yieldmanager[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@yieldmanager[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@yieldmanager[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@yourmedia[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ysbweb[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@ysbweb[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@z1.adserver[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@z1.adserver[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@z1.adserver[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@z1.adserver[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@z1.adserver[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@z1.adserver[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@z1.adserver[7].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@zedo[1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@zedo[2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@zedo[3].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@zedo[4].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@zedo[5].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@zedo[6].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@zedo[7].txt

Adware.AlfaCleaner
C:\WINDOWS\warnhp.html

Adware.WebHancer
C:\Program Files\whInstall\whAgent.inf
C:\Program Files\whInstall\whInstaller.ini
C:\Program Files\whInstall
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP52\A0036369.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP52\A0036370.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP52\A0036372.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP52\A0036373.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036896.EXE

Adware.MediaMotor
C:\WINDOWS\Downloaded Program Files\amm06.inf
C:\WINDOWS\mm06y.ini

Trojan.Malware
C:\asdf.txt

Trojan.Security Toolbar
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.url
C:\Documents and Settings\All Users\Start Menu\Security Troubleshooting.url

Trojan.WinAntiSpyware 2007
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiSpyware 2007\Contact customer support.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiSpyware 2007\Uninstall WinAntiSpyware 2007.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiSpyware 2007\WinAntiSpyware 2007 on the Web.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiSpyware 2007\WinAntiSpyware 2007 Online Manual.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiSpyware 2007\WinAntiSpyware 2007.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiSpyware 2007
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\WINANTISPYWARE 2007\WAS7MON.EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\WINANTISPYWARE 2007\WAS7.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037249.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037268.EXE

Adware.SurfSideKick
C:\DOCUMENTS AND SETTINGS\DEFAULT USER\APPLICATION DATA\SSKKNWRD.DLL

Trojan.SpySheriff
C:\DOCUMENTS AND SETTINGS\OWNER\JRQXDWNW.EXE

Trojan.BHOPlugin/Terp
C:\PROGRAM FILES\BHO PLUGIN\UNINSTALL.EXE

rainshield
2007-12-07, 07:59
Trojan.Unknown Origin
C:\PROGRAM FILES\COMMON FILES\RQZI\BAK\RQZIM.EXE
C:\PROGRAM FILES\COMMON FILES\RQZI\RQZIA.EXE
C:\PROGRAM FILES\COMMON FILES\RQZI\RQZIL.EXE
C:\PROGRAM FILES\COMMON FILES\RQZI\RQZIM.EXE
C:\PROGRAM FILES\MESSENGER\HOVYLIC22011.EXE
C:\QOOBOX\QUARANTINE\C\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\INSTALL.DAT.VIR
C:\QOOBOX\QUARANTINE\C\DOCUMENTS AND SETTINGS\DEFAULT USER\APPLICATION DATA\INSTALL.DAT.VIR
C:\QOOBOX\QUARANTINE\C\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\INSTALL.DAT.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\B104.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\B129.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\IA\KE.VBS.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPLICATION DATA\INSTALL.DAT.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\WCPSVTR.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP44\A0019931.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP46\A0027954.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP52\A0036346.VBS
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP54\A0036638.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036826.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037136.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037138.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037139.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037245.VBS
C:\WINDOWS\TEMPF.TXT

Unclassified.Unknown Origin/System
C:\PROGRAM FILES\COMMON FILES\RQZI\RQZID\RQZIC.DLL

Trojan.Downloader-Gen
C:\PROGRAM FILES\COMMON FILES\RQZI\RQZIP.EXE

Trojan.ZQuest
C:\PROGRAM FILES\COMPLUS APPLICATIONS\HONEVAFAN.DLL
C:\PROGRAM FILES\WINDOWS MEDIA PLAYER\LAZUP.DLL

Adware.ClickSpring
C:\qoobox\Quarantine\C\Documents and Settings\Owner\Application Data\CROSOF~1\PLORER~1.VIR
C:\QOOBOX\QUARANTINE\C\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\RACLE~1\DVDPLAY.EXE.VIR
C:\QOOBOX\QUARANTINE\C\DOCUMENTS AND SETTINGS\OWNER\MY DOCUMENTS\DOBE~1\WINWORD.EXE.VIR
C:\QOOBOX\QUARANTINE\C\DOCUMENTS AND SETTINGS\OWNER\MY DOCUMENTS\ICROSO~1.NET\CMD.EXE.VIR
C:\qoobox\Quarantine\C\Program Files\Common Files\FNTS~1\SOOL32~1.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\SEMBLY~1\LSASS.EXE.VIR
C:\qoobox\Quarantine\C\Program Files\WNSXS~1\JVAWEX~1.VIR
C:\qoobox\Quarantine\C\Program Files\WNSXS~1\WACLTE~1.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\PPATCH~1\IEXPLORE.EXE.VIR
C:\qoobox\Quarantine\C\WINDOWS\STEM32~1\POOLSV~1.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\OANNAS.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\SCURIT~1\WUACLT.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP44\A0019927.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP54\A0036636.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP54\A0036637.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036937.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037146.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037247.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037252.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037269.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037270.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037271.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037272.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037273.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037277.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037279.EXE

Adware.ClickSpring-Variant
C:\QOOBOX\QUARANTINE\C\DOCUMENTS AND SETTINGS\OWNER\MY DOCUMENTS\DOBE~1\BAK\WINWORD.EXE.VIR

Adware.888Toolbar/Installer
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\{34C80~1\ACTIVATE.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037284.EXE

Adware.Toolbar888
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\{34C80~1\BAR888.DLL.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037285.DLL

Adware.AdSponsor/ISM
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\ISM\BNDDRIVE.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\ISM\BNDLOADER.EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\ISM\ISM.EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\ISM\ISMMODULE2.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037238.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037239.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037240.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037241.EXE

Trojan.Downloader-Gen/Installer
C:\QOOBOX\QUARANTINE\C\WINDOWS\B103.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036837.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037137.EXE

Adware.Vundo Variant
C:\QOOBOX\QUARANTINE\C\WINDOWS\CBYVWW.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\AWTQQPP.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\DDCBXUU.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\GEBAWWX.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\HGGDBAA.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\IIFEEEB.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\MLJHFGD.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\TUVWXUS.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\WVUUUSP.DLL.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037158.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037164.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037171.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037180.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037181.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037184.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037193.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037216.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037221.DLL

Malware.DriveCleaner
C:\QOOBOX\QUARANTINE\C\WINDOWS\DOWNLOADED PROGRAM FILES\UDC6_0001_D19M1908NETINSTALLER.EXE.VIR

Trojan.WinAntiSpyware/WinAntiVirus 2006
C:\QOOBOX\QUARANTINE\C\WINDOWS\DOWNLOADED PROGRAM FILES\UWA6P_0001_N91M1807NETINSTALLER.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\DOWNLOADED PROGRAM FILES\UWAS6_0001_N91M1508NETINSTALLER.EXE.VIR
C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.1\UWA6P_0001_N91M1807NETINSTALLER.EXE
C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.2\UWA6P_0001_N91M1807NETINSTALLER.EXE

Adware.Adservs
C:\QOOBOX\QUARANTINE\C\WINDOWS\IA\ASAPPSRV.DLL.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037243.DLL

Unclassified.Unknown Origin
C:\QOOBOX\QUARANTINE\C\WINDOWS\IA\COMMAND.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037244.EXE

Trojan.Downloader-MonterreyA
C:\QOOBOX\QUARANTINE\C\WINDOWS\MONTERREYA_UNKNOWN.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037134.EXE

Adware.Vundo/Traff-2
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\AMJAJNNJ.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\DUQEAMOA.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\GHDTGQMM.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\KTBEHTDY.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\MXTSKOQL.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\ONTCHXJE.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\QJBGXMRN.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\SRLIXQMJ.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\UNBHMDOV.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\WIUHKDEH.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037147.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037148.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037149.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037150.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037151.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037152.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037153.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037154.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037155.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037156.EXE

Trojan.ZenoSearch
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\SWINKODS.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\SWINKODT.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036943.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037144.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037145.EXE

Trojan.ZQuest-Installer
C:\QOOBOX\QUARANTINE\C\WINDOWS\TK58.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037295.EXE

Trojan.Downloader-Gen/TSITRA
C:\QOOBOX\QUARANTINE\C\WINDOWS\TSITRA77.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037142.EXE
C:\WINDOWS\TSITRA572.EXE.TMP

Trojan.Update-Mcboo
C:\RECYCLER\S-1-5-18\DC1\UPDATE.EXE

Trojan.Downloader-Gen/GotTheNews
C:\SYSFZWV.EXE
C:\SYSINOO.EXE

Adware.eZula
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP44\A0019840.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP44\A0019859.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036847.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036848.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036849.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036850.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036851.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036853.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036854.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036855.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036856.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036857.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036859.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036860.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036861.EXE

rainshield
2007-12-07, 08:00
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036862.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036863.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036864.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036865.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036866.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036867.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036868.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036869.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036870.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036871.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036872.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036874.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036875.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036876.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036877.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036878.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036879.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036880.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036881.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036882.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036883.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036885.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036886.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036887.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036888.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036889.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036890.EXE

Adware.ClickSpring/Resident
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP46\A0027950.DLL

Trojan.Windows Installer
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP47\A0029960.EXE

Trojan.Services/Inet
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP52\A0036316.EXE

Trojan.NetMon/DNSChange
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP52\A0036347.EXE

Adware.ShopAtHomeSelect/CashBack
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP52\A0036348.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP52\A0036349.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP52\A0036350.EXE

Adware.SurfAccuracy-Installer
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP52\A0036357.EXE

Adware.UCmore Toolbar
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP52\A0036363.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP52\A0036366.DLL

Adware.Vundo-Variant/Small-A
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP55\A0036697.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP56\A0036753.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP56\A0036779.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036804.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036910.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP58\A0036989.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP60\A0037034.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP61\A0037084.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037160.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037162.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037170.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037172.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037191.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037195.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037198.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037200.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037207.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037218.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037222.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037225.DLL

Trojan.Downloader-Gen/TStamp
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036827.EXE

Adware.IPWins
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036831.EXE

Malware.VirusBurst
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036844.EXE

Malware.VirusBurster-Install
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036845.EXE

Trojan.Downloader-Gen/DDC
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036852.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036858.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036873.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036884.EXE
C:\WINDOWS\SYSTEM32\DJTKDRCW.EXE
C:\WINDOWS\SYSTEM32\ONBSNADE.EXE
C:\WINDOWS\SYSTEM32\VBDICGGU.EXE
C:\WINDOWS\Prefetch\ONBSNADE.EXE-32E00979.pf
C:\WINDOWS\Prefetch\VBDICGGU.EXE-20A41CE8.pf

Trojan.Downloader-Gen/Win
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036892.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036894.EXE
C:\WINDOWS\BAK\RETADPU77.EXE

Trojan.Downloader-Gen/RetAd
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036893.EXE

Adware.VSToolbar
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036895.DLL

Trojan.Downloader-Gen/WinAble-Installer
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036925.EXE

Adware.WINSHOW
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036926.EXE

Adware.ZenoSearch-NVON
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036940.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036941.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP57\A0036942.EXE

Adware.Vundo-Variant
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037176.DLL

Adware.Vundo-Variant/Small
C:\SYSTEM VOLUME INFORMATION\_RESTORE{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP63\A0037213.DLL

Adware.Mirar/NetNucleus
C:\WINDOWS\MIRAR.EXE

RelevantKnowledge Spyware Component
C:\WINDOWS\RLVKNLG.EXE

Trojan.Downloadter-TaskMng
C:\WINDOWS\TASKMNG.EXE

Adware.UCMore/The Search Accelerator
C:\WINDOWS\UCMOREIEX.EXE

Trojan.AlfaCleaner
C:\WINDOWS\X19B7D5190.TMP

rainshield
2007-12-07, 08:01
that's all i got from SAS log and combofix log

ken545
2007-12-07, 15:01
WOW :sad: This computer has had almost every infection known to man.

I want you to uninstall Combofix like this.

Go to Start > Run and copy and paste ComboFix /u into the box
Make sure there's a space between Combofix and /
Then hit enter.


This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.


This is what we are up against now, be patient as there is a lot more to do if you want this system to run correctly.


You have a downloader trojan called Downloader.Agent.awf or Downloader.Agent.ayy. This trojan replaces legitimate files that are common on most computers with an infected file. It then moves the legitimate file to a "bak" or backup folder. Please follow the directions below to run FindAWF so we can identify the files that have been infected and the backups then restore them.

Please download FindAWF (http://noahdfear.geekstogo.com/FindAWF.exe) and save it to your desktop

* Double-click FindAWF.exe to start the tool.


* Select option #2 - Restore files from bak folders by typing 2 and press 'Enter'
* A text file will open up. Please copy/paste the following bolded text into the text file:

C:\hp\KBD\bak\KBD.EXE
C:\Program Files\AIM\bak\aim.exe
C:\Program Files\Common Files\Ahead\Lib\bak\NeroCheck.exe
C:\Program Files\Common Files\Ahead\Lib\bak\NMBgMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe
C:\Program Files\Common Files\rqzi\bak\rqzim.exe
C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe
C:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe
C:\Program Files\Java\j2re1.4.2_03\bin\bak\jusched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\bak\mmtask.exe
C:\Program Files\Winamp\bak\winampa.exe
C:\WINDOWS\CREATOR\bak\Remind_XP.exe
C:\WINDOWS\SMINST\bak\RECGUARD.EXE
C:\WINDOWS\system\bak\hpsysdrv.exe

* Close the .txt file and click 'Yes' to save the changes.
* When the tool has completed, a report will open up in notepad.

Please post the results of the awf.txt here.

rainshield
2007-12-07, 20:58
thanks for ur respond. Here is the log:

Find AWF report by noahdfear ©2006
Version 1.40
Option 2 run successfully

The current date is: Fri 12/07/2007
The current time is: 12:47:49.04


bak folders found
~~~~~~~~~~~


Directory of C:\WINDOWS\BAK

0 File(s) 0 bytes

Directory of C:\HP\KBD\BAK

09/01/2007 10:04 PM 144,384 KBD.EXE
1 File(s) 144,384 bytes

Directory of C:\PROGRA~1\AIM\BAK

04/27/2004 02:18 PM 61,440 aim.exe
1 File(s) 61,440 bytes

Directory of C:\PROGRA~1\WINAMP\BAK

11/21/2006 09:38 AM 35,328 winampa.exe
1 File(s) 35,328 bytes

Directory of C:\WINDOWS\CREATOR\BAK

12/17/2003 11:31 PM 118,784 Remind_XP.exe
1 File(s) 118,784 bytes

Directory of C:\WINDOWS\SMINST\BAK

11/03/2003 04:50 PM 221,184 RECGUARD.EXE
1 File(s) 221,184 bytes

Directory of C:\WINDOWS\SYSTEM\BAK

05/07/1998 04:04 PM 52,736 hpsysdrv.exe
1 File(s) 52,736 bytes

Directory of C:\PROGRA~1\COMMON~1\RQZI\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\HP\{45B61~1\BAK

08/21/2003 03:23 AM 49,152 hphupd05.exe
1 File(s) 49,152 bytes

Directory of C:\PROGRA~1\MUSICM~1\MUSICM~1\BAK

12/11/2003 01:40 AM 53,248 mmtask.exe
1 File(s) 53,248 bytes

Directory of C:\PROGRA~1\COMMON~1\AHEAD\LIB\BAK

01/12/2006 03:40 PM 155,648 NeroCheck.exe
11/16/2006 07:04 PM 139,264 NMBgMonitor.exe
2 File(s) 294,912 bytes

Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK

01/26/2004 04:29 AM 151,597 realsched.exe
1 File(s) 151,597 bytes

Directory of C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK

08/19/2003 08:01 AM 110,592 sgtray.exe
1 File(s) 110,592 bytes

Directory of C:\PROGRA~1\JAVA\J2RE14~1.2_0\BIN\BAK

01/26/2004 02:24 AM 32,881 jusched.exe
1 File(s) 32,881 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

144384 Sep 1 2007 "C:\hp\KBD\KBD.EXE"
144384 Sep 1 2007 "C:\hp\KBD\bak\KBD.EXE"
61440 Jun 7 2004 "C:\Program Files\AIM\aim.exe"
61440 Apr 27 2004 "C:\Program Files\AIM\bak\aim.exe"
24080 Aug 21 2007 "C:\Program Files\Winamp\winampa.exe"
35328 Nov 21 2006 "C:\Program Files\Winamp\bak\winampa.exe"
118784 Dec 17 2003 "C:\WINDOWS\CREATOR\Remind_XP.exe"
118784 Dec 17 2003 "C:\WINDOWS\CREATOR\bak\Remind_XP.exe"
221184 Nov 3 2003 "C:\WINDOWS\SMINST\RECGUARD.EXE"
221184 Nov 3 2003 "C:\WINDOWS\SMINST\bak\RECGUARD.EXE"
52736 May 7 1998 "C:\WINDOWS\system\hpsysdrv.exe"
52736 May 7 1998 "C:\WINDOWS\system\bak\hpsysdrv.exe"
49152 Aug 21 2003 "C:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe"
49152 Aug 21 2003 "C:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe"
53248 Dec 11 2003 "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
53248 Dec 11 2003 "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\bak\mmtask.exe"
53248 Dec 11 2003 "C:\Program Files\MUSICMATCH\MUSICMATCH Update\MMJB\mmtask.exe"
36927 Mar 6 2007 "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
155648 Jan 12 2006 "C:\Program Files\Common Files\Ahead\Lib\bak\NeroCheck.exe"
36927 Mar 6 2007 "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
139264 Nov 16 2006 "C:\Program Files\Common Files\Ahead\Lib\bak\NMBgMonitor.exe"
185632 Aug 17 2007 "C:\Program Files\Common Files\Real\Update_OB\realsched.exe1187744756"
151597 Jan 26 2004 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
110592 Aug 19 2003 "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe"
110592 Aug 19 2003 "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe"
32881 Jan 26 2004 "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"
83608 Mar 14 2007 "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
32881 Jan 26 2004 "C:\Program Files\Java\j2re1.4.2_03\bin\bak\jusched.exe"


end of report

ken545
2007-12-07, 21:57
I should have pointed this out after I saw all the reports, but this system is so heavily infected with all kinds of garbage that if it was my system I would have reformated and reinstalled a clean copy of windows. The reason we call it malware ( malicious ware ) is because even after a system is clean it could sometimes leave some damage on your system. This infection we are working on now has basically backed up all the programs on this list and supplied its own infected version. Hopefully things will work ok when we are done but I cant guarantee it. I also want to point out that even after your clean that I would hesitate to use this system for any online transactions like shopping with your credit card or online banking.

With that said, if you want to proceed then lets move on.

Double-click FindAWF.exe to start the tool.

* Select option #3 - Remove bak folders by typing 3 and press 'Enter'
* A text file will open up. Please copy/paste the following bolded text into the text file:

C:\hp\KBD\bak
C:\Program Files\AIM\bak
C:\Program Files\Common Files\Ahead\Lib\bak
C:\Program Files\Common Files\Real\Update_OB\bak
C:\Program Files\Common Files\rqzi\bak
C:\Program Files\Common Files\Sonic\Update Manager\bak
C:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak
C:\Program Files\Java\j2re1.4.2_03\bin\bak
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\bak
C:\Program Files\Winamp\bak
C:\WINDOWS\CREATOR\bak
C:\WINDOWS\SMINST\bak
C:\WINDOWS\system\bak
C:\WINDOWS\BAK

* Close the .txt file and click 'Yes' to save the changes.
* When the tool has completed, a report will open up in notepad.

Please post the results of the awf.txt here

rainshield
2007-12-07, 22:18
Thanks for ur respond, actually after gave me this pc, my older bro did buy a new pc for his own, so i think i still can do some transactions on his pc sometimes. I just want this pc run smoothly as much as it can.
Here is the awf log u need:

Find AWF report by noahdfear ©2006
Version 1.40
Option 3 run successfully

The current date is: Fri 12/07/2007
The current time is: 14:14:28.57


bak folders found
~~~~~~~~~~~



Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~



end of report

ken545
2007-12-07, 22:28
Great , that went off without a hitch. :bigthumb:


Download: DelDomains (http://mvps.org/winhelp2002/DelDomains.inf) and save it to the desktop.

Close all open windows and your browser
Right Click DelDomains.inf and select > Install
Reboot your computer



Internet Explorer is needed to run this properly.

What I would like you to do is to run Combofix again and post the New Combofix log and a New HJT log please

rainshield
2007-12-07, 23:04
thanks a lot for ur helps. I reinstall the combofix n here's the log :
ComboFix 07-12-07.3 - Owner 2007-12-07 14:53:19.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.260 [GMT -8:00]
Running from: C:\DOCUME~1\Owner\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\svchost.com

.
((((((((((((((((((((((((( Files Created from 2007-11-07 to 2007-12-07 )))))))))))))))))))))))))))))))
.

2007-12-06 11:47 . 2007-12-07 13:09 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-12-06 11:47 . 2007-12-06 11:47 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2007-12-06 11:47 . 2007-12-06 11:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-06 11:45 . 2007-12-06 11:45 <DIR> d-------- C:\Program Files\CCleaner
2007-12-05 17:39 . 2007-12-06 10:53 807,528 ---hs---- C:\WINDOWS\system32\xdcmtxhf.ini
2007-12-05 03:45 . 2004-01-26 05:10 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2007-12-05 03:45 . 2005-08-01 15:59 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2007-12-05 03:45 . 2005-08-01 15:51 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Yahoo! Messenger
2007-12-05 03:45 . 2005-09-12 22:13 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Yahoo!
2007-12-05 03:45 . 2005-12-04 02:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Ventrilo
2007-12-05 03:45 . 2004-01-27 02:21 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2007-12-05 03:45 . 2004-01-26 04:28 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2007-12-05 03:45 . 2006-01-30 16:11 <DIR> dr-h----- C:\Documents and Settings\Administrator\Application Data\SecuROM
2007-12-05 03:45 . 2004-01-26 05:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2007-12-05 03:45 . 2005-12-05 15:58 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Motive
2007-12-05 03:45 . 2005-08-16 23:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Kazaa Lite
2007-12-05 03:45 . 2004-01-27 02:26 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\interMute
2007-12-05 03:45 . 2005-08-20 20:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\FotoWire
2007-12-05 03:45 . 2005-10-22 11:54 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Aim
2007-12-05 03:45 . 2005-09-15 09:45 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AdobeUM
2007-12-05 03:45 . 2005-10-31 18:05 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\.bt2
2007-12-05 03:45 . 2005-10-09 02:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\.BitTornado
2007-12-04 23:46 . 2007-12-05 12:43 2,076,049 ---hs---- C:\WINDOWS\system32\lrfojqbb.ini
2007-12-04 23:21 . 2007-12-04 23:21 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-04 23:21 . 2007-12-04 23:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-04 23:02 . 2007-12-04 23:02 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-04 22:46 . 2007-12-04 23:44 1,471,158 ---hs---- C:\WINDOWS\system32\cjynxpts.ini
2007-12-04 22:42 . 2004-05-27 18:53 237,568 -ra------ C:\WINDOWS\system32\SiSWPars.dll
2007-12-04 22:42 . 2004-05-27 18:53 155,648 -ra------ C:\WINDOWS\system32\SiSWInst.dll
2007-12-04 22:42 . 2004-05-27 19:49 154,112 -ra------ C:\WINDOWS\system32\drivers\sis162u.sys
2007-12-04 22:42 . 2004-05-27 18:53 49,152 -ra------ C:\WINDOWS\system32\SiSWBase.dll
2007-12-04 15:10 . 2007-12-04 22:38 848,777 ---hs---- C:\WINDOWS\system32\mkwhomsv.ini
2007-12-03 15:32 . 2007-12-04 15:05 794,770 ---hs---- C:\WINDOWS\system32\ulbmfrpa.ini
2007-12-02 21:35 . 2007-12-03 15:30 794,325 ---hs---- C:\WINDOWS\system32\exmkqfsi.ini
2007-12-01 23:58 . 2007-12-01 23:59 <DIR> d-------- C:\Program Files\7-Zip
2007-12-01 23:08 . 2007-12-01 23:08 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-12-01 23:08 . 2007-12-01 23:08 268 --ah----- C:\sqmdata03.sqm
2007-12-01 23:08 . 2007-12-01 23:08 244 --ah----- C:\sqmnoopt03.sqm
2007-12-01 21:27 . 2007-12-02 21:30 794,205 ---hs---- C:\WINDOWS\system32\eqvioqie.ini
2007-11-30 14:16 . 2007-11-30 14:16 2,238 --a------ C:\WINDOWS\system32\GClogo_32x32.ico
2007-11-30 11:10 . 2007-12-01 21:22 794,085 ---hs---- C:\WINDOWS\system32\vpgxequf.ini
2007-11-29 21:42 . 2007-11-30 11:02 789,960 ---hs---- C:\WINDOWS\system32\yidiauvd.ini
2007-11-26 16:05 . 2007-11-30 13:43 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Avant Profiles

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-07 22:14 --------- d-----w C:\Program Files\Winamp
2007-12-07 22:14 --------- d-----w C:\Program Files\Common Files\rqzi
2007-12-07 22:14 --------- d-----w C:\Program Files\AIM
2007-12-06 22:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-06 19:46 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-02 07:07 --------- d-----w C:\Program Files\MSN Messenger
2007-11-30 23:12 --------- d-----w C:\Program Files\Starcraft
2007-10-19 08:46 --------- d-----w C:\Program Files\Avant Browser
2007-10-19 03:43 --------- d-----w C:\Program Files\Norton AntiVirus
2007-10-19 01:51 --------- d-----w C:\Documents and Settings\Owner\Application Data\Avant Browser
2007-10-13 23:09 75,840 ----a-w C:\WINDOWS\system32\awooswon.dll
2007-10-13 10:57 75,840 ----a-w C:\WINDOWS\system32\lsbajwxf.dll
2007-10-08 06:05 --------- d-----w C:\Program Files\LD-Anime
2007-09-23 07:25 7,806 ----a-w C:\syssylo.exe
2007-09-19 06:14 4,096 ----a-w C:\WINDOWS\system32\tcpsvcs.dll
2007-09-18 06:14 133,632 --s-a-r C:\WINDOWS\system32\sys32time.dll
2007-09-02 10:50 304,453 ----a-w C:\Documents and Settings\Owner\mcc.exe
2007-09-02 06:01 160,768 ----a-w C:\Documents and Settings\Owner\gotgo.exe
2006-01-02 08:03 300,760 --sh--w C:\WINDOWS\mshostsr.exe
1989-12-12 16:10 404,208 --sh--r C:\WINDOWS\orqeenq.exe
2006-02-23 07:31 19,456 --sh--r C:\WINDOWS\system\svchost.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95CB3857-A0E7-F21B-EE5B-FD8A45862C97}]
C:\WINDOWS\System32\cnsi.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RecordNow!"="" []
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-03-28 14:10]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" []
"Notn"="C:\WINDOWS\System32\SCURIT~1\wuaclt.exe" []
"Omht"="C:\WINDOWS\??stem32\?poolsv.exe" [2003-08-15 18:40]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-01-26 02:24]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 16:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-11-18 07:11]
"HPHUPD05"="c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 03:23]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-08-21 03:15]
"KBD"="C:\HP\KBD\KBD.EXE" [2007-12-07 14:46]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 08:01]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-01-26 04:29]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2003-11-03 16:50]
"VTTimer"=" " []
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 00:59]
"LTMSG"="LTMSG.exe" [2003-07-14 17:52 C:\WINDOWS\ltmsg.exe]
"PS2"=" " []
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-03 20:35 C:\WINDOWS\ALCXMNTR.EXE]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe" [2003-03-12 04:23]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-03-28 14:10]
"QuickTime Task"="C:\PROGRA~1\QUICKT~1\qttask.exe" [2007-09-24 23:37]

C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSub.exe [2004-01-27 02:26:18]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSub.exe [2004-01-27 02:26:18]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-01-26 05:20:47]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 12:19:24]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-01-19 00:44:15]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2003-07-30 04:49:48]
SBC Self Support Tool.lnk - C:\Program Files\SBC Self Support Tool\bin\matcli.exe [2006-07-11 13:16:00]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


.
Contents of the 'Scheduled Tasks' folder
"2007-10-19 00:33:48 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-07 14:58:20
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

**************************************************************************
.
Completion time: 2007-12-07 14:59:36
C:\ComboFix2.txt ... 2007-12-06 12:50
.
--- E O F ---

rainshield
2007-12-07, 23:05
and here is the hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:04:48 PM, on 12/7/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\Java\J2RE14~1.2_0\bin\jusched.exe
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\LTMSG.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\PROGRA~1\Yahoo!\SEARCH~1\SEARCH~1.EXE
C:\PROGRA~1\SUPERA~1\SUPERA~1.EXE
C:\PROGRA~1\COMPAQ~1\1940576\Program\BACKWE~1.EXE
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe
C:\PROGRA~1\INTERM~1\SPAMSU~1\SpamSub.exe
C:\PROGRA~1\SBCSEL~1\bin\mpbtn.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Avant Browser\avant.exe
C:\Program Files\Trend Micro\HijackThis\scanner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn7\yt.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {95CB3857-A0E7-F21B-EE5B-FD8A45862C97} - C:\WINDOWS\System32\cnsi.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn7\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer]
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PS2]
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\qttask.exe" -atboottime
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Notn] "C:\WINDOWS\System32\SCURIT~1\wuaclt.exe" -vt yazb
O4 - HKCU\..\Run: [Omht] C:\WINDOWS\??stem32\?poolsv.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - S-1-5-18 Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'Default user')
O4 - .DEFAULT User Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (User 'Default user')
O4 - .DEFAULT User Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'Default user')
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe

--
End of file - 8120 bytes

rainshield
2007-12-07, 23:09
im just wondering why everytimes i ran the combofix, there's a window called service/cmd.exe pop up all the times n just being there, so i had to close it myself. just wondering if that's ok to do so

ken545
2007-12-07, 23:45
Open Notepad and copy all the text inside the quote box by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::



File::
C:\syssylo.exe
C:\WINDOWS\mshostsr.exe
C:\WINDOWS\orqeenq.exe
C:\WINDOWS\system\svchost.dll
C:\WINDOWS\system32\xdcmtxhf.ini
C:\WINDOWS\system32\lrfojqbb.ini
C:\WINDOWS\system32\cjynxpts.ini
C:\WINDOWS\system32\mkwhomsv.ini
C:\WINDOWS\system32\ulbmfrpa.ini
C:\WINDOWS\system32\exmkqfsi.ini
C:\WINDOWS\system32\eqvioqie.ini
C:\WINDOWS\system32\vpgxequf.ini
C:\WINDOWS\system32\yidiauvd.ini
C:\WINDOWS\system32\awooswon.dll
C:\WINDOWS\system32\lsbajwxf.dll
C:\WINDOWS\system32\tcpsvcs.dll
C:\WINDOWS\system32\sys32time.dll
C:\WINDOWS\System32\cnsi.dll

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95CB3857-A0E7-F21B-EE5B-FD8A45862C97}]


Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

http://i24.photobucket.com/albums/c30/ken545/CFScript.gif


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

rainshield
2007-12-08, 06:42
thanks for ur fast respond. Here is the combofix log:
ComboFix 07-12-07.3 - Owner 2007-12-07 22:27:53.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.240 [GMT -8:00]
Running from: C:\DOCUME~1\Owner\LOCALS~1\Temp\3582-490\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\svchost.com

.
((((((((((((((((((((((((( Files Created from 2007-11-08 to 2007-12-08 )))))))))))))))))))))))))))))))
.

2007-12-06 11:47 . 2007-12-07 13:09 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-12-06 11:47 . 2007-12-06 11:47 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2007-12-06 11:47 . 2007-12-06 11:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-06 11:45 . 2007-12-06 11:45 <DIR> d-------- C:\Program Files\CCleaner
2007-12-05 17:39 . 2007-12-06 10:53 807,528 ---hs---- C:\WINDOWS\system32\xdcmtxhf.ini
2007-12-05 03:45 . 2004-01-26 05:10 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2007-12-05 03:45 . 2005-08-01 15:59 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2007-12-05 03:45 . 2005-08-01 15:51 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Yahoo! Messenger
2007-12-05 03:45 . 2005-09-12 22:13 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Yahoo!
2007-12-05 03:45 . 2005-12-04 02:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Ventrilo
2007-12-05 03:45 . 2004-01-27 02:21 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2007-12-05 03:45 . 2004-01-26 04:28 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2007-12-05 03:45 . 2006-01-30 16:11 <DIR> dr-h----- C:\Documents and Settings\Administrator\Application Data\SecuROM
2007-12-05 03:45 . 2004-01-26 05:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2007-12-05 03:45 . 2005-12-05 15:58 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Motive
2007-12-05 03:45 . 2005-08-16 23:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Kazaa Lite
2007-12-05 03:45 . 2004-01-27 02:26 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\interMute
2007-12-05 03:45 . 2005-08-20 20:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\FotoWire
2007-12-05 03:45 . 2005-10-22 11:54 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Aim
2007-12-05 03:45 . 2005-09-15 09:45 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AdobeUM
2007-12-05 03:45 . 2005-10-31 18:05 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\.bt2
2007-12-05 03:45 . 2005-10-09 02:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\.BitTornado
2007-12-04 23:46 . 2007-12-05 12:43 2,076,049 ---hs---- C:\WINDOWS\system32\lrfojqbb.ini
2007-12-04 23:21 . 2007-12-04 23:21 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-04 23:21 . 2007-12-04 23:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-04 23:02 . 2007-12-04 23:02 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-04 22:46 . 2007-12-04 23:44 1,471,158 ---hs---- C:\WINDOWS\system32\cjynxpts.ini
2007-12-04 22:42 . 2004-05-27 18:53 237,568 -ra------ C:\WINDOWS\system32\SiSWPars.dll
2007-12-04 22:42 . 2004-05-27 18:53 155,648 -ra------ C:\WINDOWS\system32\SiSWInst.dll
2007-12-04 22:42 . 2004-05-27 19:49 154,112 -ra------ C:\WINDOWS\system32\drivers\sis162u.sys
2007-12-04 22:42 . 2004-05-27 18:53 49,152 -ra------ C:\WINDOWS\system32\SiSWBase.dll
2007-12-04 15:10 . 2007-12-04 22:38 848,777 ---hs---- C:\WINDOWS\system32\mkwhomsv.ini
2007-12-03 15:32 . 2007-12-04 15:05 794,770 ---hs---- C:\WINDOWS\system32\ulbmfrpa.ini
2007-12-02 21:35 . 2007-12-03 15:30 794,325 ---hs---- C:\WINDOWS\system32\exmkqfsi.ini
2007-12-01 23:58 . 2007-12-01 23:59 <DIR> d-------- C:\Program Files\7-Zip
2007-12-01 23:08 . 2007-12-01 23:08 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-12-01 23:08 . 2007-12-01 23:08 268 --ah----- C:\sqmdata03.sqm
2007-12-01 23:08 . 2007-12-01 23:08 244 --ah----- C:\sqmnoopt03.sqm
2007-12-01 21:27 . 2007-12-02 21:30 794,205 ---hs---- C:\WINDOWS\system32\eqvioqie.ini
2007-11-30 14:16 . 2007-11-30 14:16 2,238 --a------ C:\WINDOWS\system32\GClogo_32x32.ico
2007-11-30 11:10 . 2007-12-01 21:22 794,085 ---hs---- C:\WINDOWS\system32\vpgxequf.ini
2007-11-29 21:42 . 2007-11-30 11:02 789,960 ---hs---- C:\WINDOWS\system32\yidiauvd.ini
2007-11-26 16:05 . 2007-11-30 13:43 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Avant Profiles

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-07 22:14 --------- d-----w C:\Program Files\Winamp
2007-12-07 22:14 --------- d-----w C:\Program Files\Common Files\rqzi
2007-12-07 22:14 --------- d-----w C:\Program Files\AIM
2007-12-06 22:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-06 19:46 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-02 07:07 --------- d-----w C:\Program Files\MSN Messenger
2007-11-30 23:12 --------- d-----w C:\Program Files\Starcraft
2007-10-19 08:46 --------- d-----w C:\Program Files\Avant Browser
2007-10-19 03:43 --------- d-----w C:\Program Files\Norton AntiVirus
2007-10-19 01:51 --------- d-----w C:\Documents and Settings\Owner\Application Data\Avant Browser
2007-10-13 23:09 75,840 ----a-w C:\WINDOWS\system32\awooswon.dll
2007-10-13 10:57 75,840 ----a-w C:\WINDOWS\system32\lsbajwxf.dll
2007-10-08 06:05 --------- d-----w C:\Program Files\LD-Anime
2007-09-23 07:25 7,806 ----a-w C:\syssylo.exe
2007-09-19 06:14 4,096 ----a-w C:\WINDOWS\system32\tcpsvcs.dll
2007-09-18 06:14 133,632 --s-a-r C:\WINDOWS\system32\sys32time.dll
2007-09-02 10:50 304,453 ----a-w C:\Documents and Settings\Owner\mcc.exe
2007-09-02 06:01 160,768 ----a-w C:\Documents and Settings\Owner\gotgo.exe
2006-01-02 08:03 300,760 --sh--w C:\WINDOWS\mshostsr.exe
1989-12-12 16:10 404,208 --sh--r C:\WINDOWS\orqeenq.exe
2006-02-23 07:31 19,456 --sh--r C:\WINDOWS\system\svchost.dll
.

((((((((((((((((((((((((((((( snapshot@2007-12-07_14.58.32.14 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-07 22:53:12 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\ntuser.dat
+ 2007-12-08 06:27:46 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95CB3857-A0E7-F21B-EE5B-FD8A45862C97}]
C:\WINDOWS\System32\cnsi.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RecordNow!"="" []
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-03-28 14:10]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" []
"Notn"="C:\WINDOWS\System32\SCURIT~1\wuaclt.exe" []
"Omht"="C:\WINDOWS\??stem32\?poolsv.exe" [2003-08-15 18:40]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-01-26 02:24]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 16:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-11-18 07:11]
"HPHUPD05"="c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 03:23]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-08-21 03:15]
"KBD"="C:\HP\KBD\KBD.EXE" [2007-12-07 14:46]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 08:01]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-01-26 04:29]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2003-11-03 16:50]
"VTTimer"=" " []
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 00:59]
"LTMSG"="LTMSG.exe" [2003-07-14 17:52 C:\WINDOWS\ltmsg.exe]
"PS2"=" " []
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-03 20:35 C:\WINDOWS\ALCXMNTR.EXE]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe" [2003-03-12 04:23]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-03-28 14:10]
"QuickTime Task"="C:\PROGRA~1\QUICKT~1\qttask.exe" [2007-09-24 23:37]

C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSub.exe [2004-01-27 02:26:18]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSub.exe [2004-01-27 02:26:18]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-01-26 05:20:47]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 12:19:24]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-01-19 00:44:15]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2003-07-30 04:49:48]
SBC Self Support Tool.lnk - C:\Program Files\SBC Self Support Tool\bin\matcli.exe [2006-07-11 13:16:00]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


.
Contents of the 'Scheduled Tasks' folder
"2007-10-19 00:33:48 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-07 22:30:26
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

**************************************************************************
.
Completion time: 2007-12-07 22:31:40
C:\ComboFix2.txt ... 2007-12-07 14:59
C:\ComboFix3.txt ... 2007-12-06 12:50
.
--- E O F ---

rainshield
2007-12-08, 07:06
Here's the HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:05:02 PM, on 12/7/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\PROGRA~1\Java\J2RE14~1.2_0\bin\jusched.exe
C:\PROGRA~1\COMMON~1\Sonic\UPDATE~1\sgtray.exe
C:\WINDOWS\LTMSG.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\PROGRA~1\Yahoo!\SEARCH~1\SEARCH~1.EXE
C:\PROGRA~1\SUPERA~1\SUPERA~1.EXE
C:\PROGRA~1\COMPAQ~1\1940576\Program\BACKWE~1.EXE
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe
C:\PROGRA~1\INTERM~1\SPAMSU~1\SpamSub.exe
C:\PROGRA~1\SBCSEL~1\bin\mpbtn.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\scanner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn7\yt.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {95CB3857-A0E7-F21B-EE5B-FD8A45862C97} - C:\WINDOWS\System32\cnsi.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn7\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer]
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PS2]
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\qttask.exe" -atboottime
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Notn] "C:\WINDOWS\System32\SCURIT~1\wuaclt.exe" -vt yazb
O4 - HKCU\..\Run: [Omht] C:\WINDOWS\??stem32\?poolsv.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - S-1-5-18 Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'Default user')
O4 - .DEFAULT User Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (User 'Default user')
O4 - .DEFAULT User Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'Default user')
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe

--
End of file - 8055 bytes

ken545
2007-12-08, 14:33
Your running Combofix from a temp directory , it needs to run from your desktop, those files where not removed.

Open Notepad and copy all the text inside the quote box by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::



File::
C:\syssylo.exe
C:\WINDOWS\mshostsr.exe
C:\WINDOWS\orqeenq.exe
C:\WINDOWS\system\svchost.dll
C:\WINDOWS\system32\xdcmtxhf.ini
C:\WINDOWS\system32\lrfojqbb.ini
C:\WINDOWS\system32\cjynxpts.ini
C:\WINDOWS\system32\mkwhomsv.ini
C:\WINDOWS\system32\ulbmfrpa.ini
C:\WINDOWS\system32\exmkqfsi.ini
C:\WINDOWS\system32\eqvioqie.ini
C:\WINDOWS\system32\vpgxequf.ini
C:\WINDOWS\system32\yidiauvd.ini
C:\WINDOWS\system32\awooswon.dll
C:\WINDOWS\system32\lsbajwxf.dll
C:\WINDOWS\system32\tcpsvcs.dll
C:\WINDOWS\system32\sys32time.dll
C:\WINDOWS\System32\cnsi.dll

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95CB3857-A0E7-F21B-EE5B-FD8A45862C97}]


Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

http://i24.photobucket.com/albums/c30/ken545/CFScript.gif


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

rainshield
2007-12-09, 07:05
I did follow ur instruction n this is wat i got from combofix log:
ComboFix 07-12-09.1 - Owner 2007-12-08 22:30:09.7 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.242 [GMT -8:00]
Running from: C:\DOCUME~1\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\svchost.com

.
((((((((((((((((((((((((( Files Created from 2007-11-09 to 2007-12-09 )))))))))))))))))))))))))))))))
.

2007-12-06 11:47 . 2007-12-07 13:09 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-12-06 11:47 . 2007-12-06 11:47 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2007-12-06 11:47 . 2007-12-06 11:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-06 11:45 . 2007-12-06 11:45 <DIR> d-------- C:\Program Files\CCleaner
2007-12-05 17:39 . 2007-12-06 10:53 807,528 ---hs---- C:\WINDOWS\system32\xdcmtxhf.ini
2007-12-05 03:45 . 2004-01-26 05:10 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2007-12-05 03:45 . 2005-08-01 15:59 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2007-12-05 03:45 . 2005-08-01 15:51 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Yahoo! Messenger
2007-12-05 03:45 . 2005-09-12 22:13 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Yahoo!
2007-12-05 03:45 . 2005-12-04 02:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Ventrilo
2007-12-05 03:45 . 2004-01-27 02:21 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2007-12-05 03:45 . 2004-01-26 04:28 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2007-12-05 03:45 . 2006-01-30 16:11 <DIR> dr-h----- C:\Documents and Settings\Administrator\Application Data\SecuROM
2007-12-05 03:45 . 2004-01-26 05:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2007-12-05 03:45 . 2005-12-05 15:58 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Motive
2007-12-05 03:45 . 2005-08-16 23:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Kazaa Lite
2007-12-05 03:45 . 2004-01-27 02:26 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\interMute
2007-12-05 03:45 . 2005-08-20 20:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\FotoWire
2007-12-05 03:45 . 2005-10-22 11:54 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Aim
2007-12-05 03:45 . 2005-09-15 09:45 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AdobeUM
2007-12-05 03:45 . 2005-10-31 18:05 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\.bt2
2007-12-05 03:45 . 2005-10-09 02:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\.BitTornado
2007-12-04 23:46 . 2007-12-05 12:43 2,076,049 ---hs---- C:\WINDOWS\system32\lrfojqbb.ini
2007-12-04 23:21 . 2007-12-04 23:21 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-04 23:21 . 2007-12-04 23:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-04 23:02 . 2007-12-04 23:02 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-04 22:46 . 2007-12-04 23:44 1,471,158 ---hs---- C:\WINDOWS\system32\cjynxpts.ini
2007-12-04 22:42 . 2004-05-27 18:53 237,568 -ra------ C:\WINDOWS\system32\SiSWPars.dll
2007-12-04 22:42 . 2004-05-27 18:53 155,648 -ra------ C:\WINDOWS\system32\SiSWInst.dll
2007-12-04 22:42 . 2004-05-27 19:49 154,112 -ra------ C:\WINDOWS\system32\drivers\sis162u.sys
2007-12-04 22:42 . 2004-05-27 18:53 49,152 -ra------ C:\WINDOWS\system32\SiSWBase.dll
2007-12-04 15:10 . 2007-12-04 22:38 848,777 ---hs---- C:\WINDOWS\system32\mkwhomsv.ini
2007-12-03 15:32 . 2007-12-04 15:05 794,770 ---hs---- C:\WINDOWS\system32\ulbmfrpa.ini
2007-12-02 21:35 . 2007-12-03 15:30 794,325 ---hs---- C:\WINDOWS\system32\exmkqfsi.ini
2007-12-01 23:58 . 2007-12-01 23:59 <DIR> d-------- C:\Program Files\7-Zip
2007-12-01 23:08 . 2007-12-01 23:08 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-12-01 23:08 . 2007-12-01 23:08 268 --ah----- C:\sqmdata03.sqm
2007-12-01 23:08 . 2007-12-01 23:08 244 --ah----- C:\sqmnoopt03.sqm
2007-12-01 21:27 . 2007-12-02 21:30 794,205 ---hs---- C:\WINDOWS\system32\eqvioqie.ini
2007-11-30 14:16 . 2007-11-30 14:16 2,238 --a------ C:\WINDOWS\system32\GClogo_32x32.ico
2007-11-30 11:10 . 2007-12-01 21:22 794,085 ---hs---- C:\WINDOWS\system32\vpgxequf.ini
2007-11-29 21:42 . 2007-11-30 11:02 789,960 ---hs---- C:\WINDOWS\system32\yidiauvd.ini
2007-11-26 16:05 . 2007-11-30 13:43 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Avant Profiles

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-07 22:14 --------- d-----w C:\Program Files\Winamp
2007-12-07 22:14 --------- d-----w C:\Program Files\Common Files\rqzi
2007-12-07 22:14 --------- d-----w C:\Program Files\AIM
2007-12-06 22:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-06 19:46 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-02 07:07 --------- d-----w C:\Program Files\MSN Messenger
2007-11-30 23:12 --------- d-----w C:\Program Files\Starcraft
2007-10-19 08:46 --------- d-----w C:\Program Files\Avant Browser
2007-10-19 03:43 --------- d-----w C:\Program Files\Norton AntiVirus
2007-10-19 01:51 --------- d-----w C:\Documents and Settings\Owner\Application Data\Avant Browser
2007-10-13 23:09 75,840 ----a-w C:\WINDOWS\system32\awooswon.dll
2007-10-13 10:57 75,840 ----a-w C:\WINDOWS\system32\lsbajwxf.dll
2007-09-23 07:25 7,806 ----a-w C:\syssylo.exe
2007-09-19 06:14 4,096 ----a-w C:\WINDOWS\system32\tcpsvcs.dll
2007-09-18 06:14 133,632 --s-a-r C:\WINDOWS\system32\sys32time.dll
2007-09-02 10:50 304,453 ----a-w C:\Documents and Settings\Owner\mcc.exe
2007-09-02 06:01 160,768 ----a-w C:\Documents and Settings\Owner\gotgo.exe
2006-01-02 08:03 300,760 --sh--w C:\WINDOWS\mshostsr.exe
1989-12-12 16:10 404,208 --sh--r C:\WINDOWS\orqeenq.exe
2006-02-23 07:31 19,456 --sh--r C:\WINDOWS\system\svchost.dll
.

((((((((((((((((((((((((((((( snapshot@2007-12-07_14.58.32.14 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-27 11:58:11 140,288 ----a-w C:\WINDOWS\catchme.exe
+ 2007-12-08 11:32:45 141,824 ----a-w C:\WINDOWS\catchme.exe
- 2007-12-07 22:45:48 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-12-09 06:25:57 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-12-07 22:45:48 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-09 06:25:57 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-12-07 22:45:48 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-09 06:25:57 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-07 22:53:12 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\ntuser.dat
+ 2007-12-09 06:11:53 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95CB3857-A0E7-F21B-EE5B-FD8A45862C97}]
C:\WINDOWS\System32\cnsi.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RecordNow!"="" []
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-03-28 14:10]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" []
"Notn"="C:\WINDOWS\System32\SCURIT~1\wuaclt.exe" []
"Omht"="C:\WINDOWS\??stem32\?poolsv.exe" [2003-08-15 18:40]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-01-26 02:24]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 16:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-11-18 07:11]
"HPHUPD05"="c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 03:23]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-08-21 03:15]
"KBD"="C:\HP\KBD\KBD.EXE" [2007-12-08 22:01]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 08:01]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-01-26 04:29]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2003-11-03 16:50]
"VTTimer"=" " []
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 00:59]
"LTMSG"="LTMSG.exe" [2003-07-14 17:52 C:\WINDOWS\ltmsg.exe]
"PS2"=" " []
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-03 20:35 C:\WINDOWS\ALCXMNTR.EXE]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe" [2003-03-12 04:23]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-03-28 14:10]
"QuickTime Task"="C:\PROGRA~1\QUICKT~1\qttask.exe" [2007-09-24 23:37]

C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSub.exe [2004-01-27 02:26:18]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSub.exe [2004-01-27 02:26:18]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-01-26 05:20:47]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 12:19:24]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-01-19 00:44:15]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2003-07-30 04:49:48]
SBC Self Support Tool.lnk - C:\Program Files\SBC Self Support Tool\bin\matcli.exe [2006-07-11 13:16:00]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


.
Contents of the 'Scheduled Tasks' folder
"2007-10-19 00:33:48 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-08 22:33:14
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-08 22:34:05
C:\ComboFix2.txt ... 2007-12-08 22:18
C:\ComboFix3.txt ... 2007-12-07 22:31
.
--- E O F ---

rainshield
2007-12-09, 07:06
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:03:26 PM, on 12/8/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\LTMSG.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\PROGRA~1\Yahoo!\SEARCH~1\SEARCH~1.EXE
C:\PROGRA~1\SUPERA~1\SUPERA~1.EXE
C:\PROGRA~1\COMPAQ~1\1940576\Program\BACKWE~1.EXE
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe
C:\PROGRA~1\INTERM~1\SPAMSU~1\SpamSub.exe
C:\PROGRA~1\SBCSEL~1\bin\mpbtn.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\scanner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn7\yt.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {95CB3857-A0E7-F21B-EE5B-FD8A45862C97} - C:\WINDOWS\System32\cnsi.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn7\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer]
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PS2]
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\qttask.exe" -atboottime
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Notn] "C:\WINDOWS\System32\SCURIT~1\wuaclt.exe" -vt yazb
O4 - HKCU\..\Run: [Omht] C:\WINDOWS\??stem32\?poolsv.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - S-1-5-18 Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'Default user')
O4 - .DEFAULT User Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (User 'Default user')
O4 - .DEFAULT User Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'Default user')
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe

--
End of file - 8055 bytes

ken545
2007-12-09, 15:01
OK, lets do it this way.


Remove this entry with HJT.
O2 - BHO: (no name) - {95CB3857-A0E7-F21B-EE5B-FD8A45862C97} - C:\WINDOWS\System32\cnsi.dll (file missing)



Please download OTMoveIt (http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe) by OldTimer.


Save it to your desktop.
Please double-click OTMoveIt.exe to run it.
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):



C:\syssylo.exe
C:\WINDOWS\mshostsr.exe
C:\WINDOWS\orqeenq.exe
C:\WINDOWS\system\svchost.dll
C:\WINDOWS\system32\xdcmtxhf.ini
C:\WINDOWS\system32\lrfojqbb.ini
C:\WINDOWS\system32\cjynxpts.ini
C:\WINDOWS\system32\mkwhomsv.ini
C:\WINDOWS\system32\ulbmfrpa.ini
C:\WINDOWS\system32\exmkqfsi.ini
C:\WINDOWS\system32\eqvioqie.ini
C:\WINDOWS\system32\vpgxequf.ini
C:\WINDOWS\system32\yidiauvd.ini
C:\WINDOWS\system32\awooswon.dll
C:\WINDOWS\system32\lsbajwxf.dll
C:\WINDOWS\system32\tcpsvcs.dll
C:\WINDOWS\system32\sys32time.dll
C:\WINDOWS\System32\cnsi.dll

Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
Click the red Moveit! button.
Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
Close OTMoveIt


If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Post the OtMoveIt log and a new HJT log please

rainshield
2007-12-10, 06:33
thanks for ur respond. I did follow ur instruction but all i got from Otmoveit is :
File/Folder C:\syssylo.exe not found.
File/Folder C:\WINDOWS\mshostsr.exe not found.
File/Folder C:\WINDOWS\orqeenq.exe not found.
File/Folder C:\WINDOWS\system\svchost.dll not found.
File/Folder C:\WINDOWS\system32\xdcmtxhf.ini not found.
File/Folder C:\WINDOWS\system32\lrfojqbb.ini not found.
File/Folder C:\WINDOWS\system32\cjynxpts.ini not found.
File/Folder C:\WINDOWS\system32\mkwhomsv.ini not found.
File/Folder C:\WINDOWS\system32\ulbmfrpa.ini not found.
File/Folder C:\WINDOWS\system32\exmkqfsi.ini not found.
File/Folder C:\WINDOWS\system32\eqvioqie.ini not found.
File/Folder C:\WINDOWS\system32\vpgxequf.ini not found.
File/Folder C:\WINDOWS\system32\yidiauvd.ini not found.
File/Folder C:\WINDOWS\system32\awooswon.dll not found.
File/Folder C:\WINDOWS\system32\lsbajwxf.dll not found.
File/Folder C:\WINDOWS\system32\tcpsvcs.dll not found.
File/Folder C:\WINDOWS\system32\sys32time.dll not found.
File/Folder C:\WINDOWS\System32\cnsi.dll not found.

Created on 12/09/2007 22:30:56

rainshield
2007-12-10, 06:35
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:35:10 PM, on 12/9/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\windows\system\hpsysdrv.exe
C:\PROGRA~1\Java\J2RE14~1.2_0\bin\jusched.exe
C:\WINDOWS\LTMSG.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\PROGRA~1\Yahoo!\SEARCH~1\SEARCH~1.EXE
C:\PROGRA~1\SUPERA~1\SUPERA~1.EXE
C:\PROGRA~1\COMPAQ~1\1940576\Program\BACKWE~1.EXE
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe
C:\PROGRA~1\INTERM~1\SPAMSU~1\SpamSub.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\scanner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn7\yt.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {95CB3857-A0E7-F21B-EE5B-FD8A45862C97} - C:\WINDOWS\System32\cnsi.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn7\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer]
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PS2]
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\qttask.exe" -atboottime
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Notn] "C:\WINDOWS\System32\SCURIT~1\wuaclt.exe" -vt yazb
O4 - HKCU\..\Run: [Omht] C:\WINDOWS\??stem32\?poolsv.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - S-1-5-18 Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'Default user')
O4 - .DEFAULT User Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (User 'Default user')
O4 - .DEFAULT User Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'Default user')
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe

--
End of file - 7976 bytes

rainshield
2007-12-10, 07:04
im sorry, after checking in Motmoveit folder i found there's another logs n here it is :
File/Folder C:\syssylo.exe not found.
File/Folder C:\WINDOWS\mshostsr.exe not found.
File/Folder C:\WINDOWS\orqeenq.exe not found.
File/Folder C:\WINDOWS\system\svchost.dll not found.
File/Folder C:\WINDOWS\system32\xdcmtxhf.ini not found.
File/Folder C:\WINDOWS\system32\lrfojqbb.ini not found.
File/Folder C:\WINDOWS\system32\cjynxpts.ini not found.
File/Folder C:\WINDOWS\system32\mkwhomsv.ini not found.
File/Folder C:\WINDOWS\system32\ulbmfrpa.ini not found.
File/Folder C:\WINDOWS\system32\exmkqfsi.ini not found.
File/Folder C:\WINDOWS\system32\eqvioqie.ini not found.
File/Folder C:\WINDOWS\system32\vpgxequf.ini not found.
File/Folder C:\WINDOWS\system32\yidiauvd.ini not found.
LoadLibrary failed for C:\WINDOWS\system32\awooswon.dll
C:\WINDOWS\system32\awooswon.dll NOT unregistered.
C:\WINDOWS\system32\awooswon.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\lsbajwxf.dll
C:\WINDOWS\system32\lsbajwxf.dll NOT unregistered.
C:\WINDOWS\system32\lsbajwxf.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\tcpsvcs.dll
C:\WINDOWS\system32\tcpsvcs.dll NOT unregistered.
C:\WINDOWS\system32\tcpsvcs.dll moved successfully.
C:\WINDOWS\system32\sys32time.dll unregistered successfully.
C:\WINDOWS\system32\sys32time.dll moved successfully.
File/Folder C:\WINDOWS\System32\cnsi.dll not found.

Created on 12/09/2007 22:25:07

ken545
2007-12-10, 11:49
Remove these with HJT and post a new HJT log please

O2 - BHO: (no name) - {95CB3857-A0E7-F21B-EE5B-FD8A45862C97} - C:\WINDOWS\System32\cnsi.dll (file missing)
O4 - HKCU\..\Run: [Notn] "C:\WINDOWS\System32\SCURIT~1\wuaclt.exe" -vt yazb
O4 - HKCU\..\Run: [Omht] C:\WINDOWS\??stem32\?poolsv.exe
O4 - .DEFAULT User Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (User 'Default user')

C:\Program Files\MyWebSearch <--Delete this folder



Download SDFix (http://downloads.andymanchesta.com/RemovalTools/SDFix.exe) and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, the Advanced Options Menu should appear;
Select the first option, to run Windows in Safe Mode, then press Enter.
Choose your usual account.

Open the extracted SDFix folder and double click RunThis.bat to start the script.
Type Y to begin the cleanup process.
It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
Press any Key and it will restart the PC.
When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
Finally paste the contents of the Report.txt back on the forum with a new HijackThis log


Need to see the SDfix log and a new HJT log

rainshield
2007-12-10, 18:41
Thanks for ur respond. Here is the SDfix log:

SDFix: Version 1.117

Run by Owner on Mon 12/10/2007 at 10:14 AM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:

C:\BF.TMP - Deleted
C:\C1.TMP - Deleted
C:\PROGRA~1\WINDOW~2\PROJYD~1.HTM - Deleted
C:\PROGRA~1\WINDOW~2\LAZUP - Deleted
C:\WINDOWS\directx.sys - Deleted
C:\WINDOWS\svchost.com - Deleted




Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-10 10:26:08
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\WINDOWS\\explorer.exe"="C:\\WINDOWS\\Explorer.EXE:*:Enabled:@xpsp2res.dll,-22008"
"C:\\WINDOWS\\System32\\svchost.exe"="C:\\WINDOWS\\System32\\svchost.exe:*:Enabled:@xpsp2res.dll,-22008"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

Remaining Files:
---------------

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Sun 2 Sep 2007 196 A.SHR --- "C:\BOOT.BAK"
Tue 3 Jan 2006 14 A..H. --- "C:\klttd323.dll"
Mon 14 May 2007 175,694 A..H. --- "C:\WINDOWS\system\dnscom.dll"
Fri 17 Nov 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 2 Jan 2006 300,760 A.SH. --- "C:\_OTMoveIt\MovedFiles\WINDOWS\mshostsr.exe"
Tue 12 Dec 1989 404,208 A.SHR --- "C:\_OTMoveIt\MovedFiles\WINDOWS\orqeenq.exe"
Sat 1 Sep 2007 5,377,024 A..H. --- "C:\hp\patches\42WW1REC\src\App00153.exe"
Sat 1 Sep 2007 535,040 A..H. --- "C:\hp\patches\42WW1REC\src\App00292.exe"
Sun 2 Sep 2007 610,304 A..H. --- "C:\hp\patches\42WW1REC\src\App00491.exe"
Sat 1 Sep 2007 1,921,536 A..H. --- "C:\hp\patches\42WW1REC\src\App02995.exe"
Sun 2 Sep 2007 658,432 A..H. --- "C:\hp\patches\42WW1REC\src\App04827.exe"
Sat 1 Sep 2007 1,484,800 A..H. --- "C:\hp\patches\42WW1REC\src\App05447.exe"
Sun 2 Sep 2007 606,208 A..H. --- "C:\hp\patches\42WW1REC\src\App05705.exe"
Sat 1 Sep 2007 545,792 A..H. --- "C:\hp\patches\42WW1REC\src\App09961.exe"
Sat 7 Feb 2004 15,596,032 A..H. --- "C:\hp\patches\42WW1REC\src\App14604.exe"
Sun 2 Sep 2007 5,422,592 A..H. --- "C:\hp\patches\42WW1REC\src\App16827.exe"
Sat 1 Sep 2007 3,751,936 A..H. --- "C:\hp\patches\42WW1REC\src\App17421.exe"
Sat 1 Sep 2007 779,776 A..H. --- "C:\hp\patches\42WW1REC\src\App18716.exe"
Sat 1 Sep 2007 506,880 A..H. --- "C:\hp\patches\42WW1REC\src\App19169.exe"
Sat 1 Sep 2007 1,240,576 A..H. --- "C:\hp\patches\42WW1REC\src\App19718.exe"
Sun 2 Sep 2007 1,119,744 A..H. --- "C:\hp\patches\42WW1REC\src\App19895.exe"
Sat 1 Sep 2007 536,576 A..H. --- "C:\hp\patches\42WW1REC\src\App23281.exe"
Sun 2 Sep 2007 619,520 A..H. --- "C:\hp\patches\42WW1REC\src\App24464.exe"
Sun 2 Sep 2007 2,417,664 A..H. --- "C:\hp\patches\42WW1REC\src\App26962.exe"
Sat 1 Sep 2007 564,736 A..H. --- "C:\hp\patches\42WW1REC\src\App29358.exe"
Sat 7 Feb 2004 12,426,752 A..H. --- "C:\hp\patches\42WW1REC\src\App32391.exe"
Sat 7 Feb 2004 12,426,752 A..H. --- "C:\hp\patches\42WW1REC\src\App99990.exe"
Sat 7 Feb 2004 15,596,032 A..H. --- "C:\hp\patches\42WW1REC\src\App99992.exe"
Sun 2 Sep 2007 5,422,592 A..H. --- "C:\hp\patches\42WW1REC\src\App99993.exe"
Sat 1 Sep 2007 5,339,648 A..H. --- "C:\hp\patches\42WW1REC\src\xApp14604.exe"
Wed 22 Feb 2006 19,456 A.SHR --- "C:\_OTMoveIt\MovedFiles\WINDOWS\system\svchost.dll"
Mon 30 Jan 2006 444 A..HR --- "C:\Documents and Settings\Administrator\Application Data\SecuROM\UserData\securom_v7_01.bak"
Mon 30 Jan 2006 444 A..HR --- "C:\Documents and Settings\Default User\Application Data\SecuROM\UserData\securom_v7_01.bak"
Mon 30 Jan 2006 444 ...HR --- "C:\Documents and Settings\Owner\Application Data\SecuROM\UserData\securom_v7_01.bak"
Mon 30 Jan 2006 444 A..HR --- "C:\WINDOWS\system32\config\systemprofile\Application Data\SecuROM\UserData\securom_v7_01.bak"

Finished!

rainshield
2007-12-10, 18:42
and here is the new HJT log after i tried to delete those files that u list:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:39:38 AM, on 12/10/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\ccApp.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\PROGRA~1\Yahoo!\SEARCH~1\SEARCH~1.EXE
C:\PROGRA~1\SUPERA~1\SUPERA~1.EXE
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe
C:\PROGRA~1\COMPAQ~1\1940576\Program\BACKWE~1.EXE
C:\PROGRA~1\INTERM~1\SPAMSU~1\SpamSub.exe
C:\PROGRA~1\SBCSEL~1\bin\mpbtn.exe
C:\PROGRA~1\AVANTB~1\avant.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\scanner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn7\yt.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn7\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer]
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PS2]
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\qttask.exe" -atboottime
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - S-1-5-18 Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'Default user')
O4 - .DEFAULT User Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (User 'Default user')
O4 - .DEFAULT User Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'Default user')
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe

--
End of file - 7865 bytes

ken545
2007-12-10, 20:43
This is all we have left to fix, the rest of your log looks fine:bigthumb:


Open Notepad and copy all the text inside the quote box by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad



Folder::
C:\Program Files\MyWebSearch


Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

http://i24.photobucket.com/albums/c30/ken545/CFScript.gif



This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.


Then remove this with HJT
O4 - .DEFAULT User Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (User 'Default user')

Post the new Combofix log and hopefully one last HJT log

rainshield
2007-12-10, 22:09
thanks for ur respond. here is the combofix log:
ComboFix 07-12-09.1 - Owner 2007-12-08 22:30:09.7 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.242 [GMT -8:00]
Running from: C:\DOCUME~1\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\svchost.com

.
((((((((((((((((((((((((( Files Created from 2007-11-09 to 2007-12-09 )))))))))))))))))))))))))))))))
.

2007-12-06 11:47 . 2007-12-07 13:09 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-12-06 11:47 . 2007-12-06 11:47 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2007-12-06 11:47 . 2007-12-06 11:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-06 11:45 . 2007-12-06 11:45 <DIR> d-------- C:\Program Files\CCleaner
2007-12-05 17:39 . 2007-12-06 10:53 807,528 ---hs---- C:\WINDOWS\system32\xdcmtxhf.ini
2007-12-05 03:45 . 2004-01-26 05:10 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2007-12-05 03:45 . 2005-08-01 15:59 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2007-12-05 03:45 . 2005-08-01 15:51 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Yahoo! Messenger
2007-12-05 03:45 . 2005-09-12 22:13 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Yahoo!
2007-12-05 03:45 . 2005-12-04 02:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Ventrilo
2007-12-05 03:45 . 2004-01-27 02:21 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2007-12-05 03:45 . 2004-01-26 04:28 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2007-12-05 03:45 . 2006-01-30 16:11 <DIR> dr-h----- C:\Documents and Settings\Administrator\Application Data\SecuROM
2007-12-05 03:45 . 2004-01-26 05:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2007-12-05 03:45 . 2005-12-05 15:58 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Motive
2007-12-05 03:45 . 2005-08-16 23:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Kazaa Lite
2007-12-05 03:45 . 2004-01-27 02:26 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\interMute
2007-12-05 03:45 . 2005-08-20 20:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\FotoWire
2007-12-05 03:45 . 2005-10-22 11:54 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Aim
2007-12-05 03:45 . 2005-09-15 09:45 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AdobeUM
2007-12-05 03:45 . 2005-10-31 18:05 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\.bt2
2007-12-05 03:45 . 2005-10-09 02:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\.BitTornado
2007-12-04 23:46 . 2007-12-05 12:43 2,076,049 ---hs---- C:\WINDOWS\system32\lrfojqbb.ini
2007-12-04 23:21 . 2007-12-04 23:21 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-04 23:21 . 2007-12-04 23:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-04 23:02 . 2007-12-04 23:02 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-04 22:46 . 2007-12-04 23:44 1,471,158 ---hs---- C:\WINDOWS\system32\cjynxpts.ini
2007-12-04 22:42 . 2004-05-27 18:53 237,568 -ra------ C:\WINDOWS\system32\SiSWPars.dll
2007-12-04 22:42 . 2004-05-27 18:53 155,648 -ra------ C:\WINDOWS\system32\SiSWInst.dll
2007-12-04 22:42 . 2004-05-27 19:49 154,112 -ra------ C:\WINDOWS\system32\drivers\sis162u.sys
2007-12-04 22:42 . 2004-05-27 18:53 49,152 -ra------ C:\WINDOWS\system32\SiSWBase.dll
2007-12-04 15:10 . 2007-12-04 22:38 848,777 ---hs---- C:\WINDOWS\system32\mkwhomsv.ini
2007-12-03 15:32 . 2007-12-04 15:05 794,770 ---hs---- C:\WINDOWS\system32\ulbmfrpa.ini
2007-12-02 21:35 . 2007-12-03 15:30 794,325 ---hs---- C:\WINDOWS\system32\exmkqfsi.ini
2007-12-01 23:58 . 2007-12-01 23:59 <DIR> d-------- C:\Program Files\7-Zip
2007-12-01 23:08 . 2007-12-01 23:08 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-12-01 23:08 . 2007-12-01 23:08 268 --ah----- C:\sqmdata03.sqm
2007-12-01 23:08 . 2007-12-01 23:08 244 --ah----- C:\sqmnoopt03.sqm
2007-12-01 21:27 . 2007-12-02 21:30 794,205 ---hs---- C:\WINDOWS\system32\eqvioqie.ini
2007-11-30 14:16 . 2007-11-30 14:16 2,238 --a------ C:\WINDOWS\system32\GClogo_32x32.ico
2007-11-30 11:10 . 2007-12-01 21:22 794,085 ---hs---- C:\WINDOWS\system32\vpgxequf.ini
2007-11-29 21:42 . 2007-11-30 11:02 789,960 ---hs---- C:\WINDOWS\system32\yidiauvd.ini
2007-11-26 16:05 . 2007-11-30 13:43 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Avant Profiles

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-07 22:14 --------- d-----w C:\Program Files\Winamp
2007-12-07 22:14 --------- d-----w C:\Program Files\Common Files\rqzi
2007-12-07 22:14 --------- d-----w C:\Program Files\AIM
2007-12-06 22:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-06 19:46 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-02 07:07 --------- d-----w C:\Program Files\MSN Messenger
2007-11-30 23:12 --------- d-----w C:\Program Files\Starcraft
2007-10-19 08:46 --------- d-----w C:\Program Files\Avant Browser
2007-10-19 03:43 --------- d-----w C:\Program Files\Norton AntiVirus
2007-10-19 01:51 --------- d-----w C:\Documents and Settings\Owner\Application Data\Avant Browser
2007-10-13 23:09 75,840 ----a-w C:\WINDOWS\system32\awooswon.dll
2007-10-13 10:57 75,840 ----a-w C:\WINDOWS\system32\lsbajwxf.dll
2007-09-23 07:25 7,806 ----a-w C:\syssylo.exe
2007-09-19 06:14 4,096 ----a-w C:\WINDOWS\system32\tcpsvcs.dll
2007-09-18 06:14 133,632 --s-a-r C:\WINDOWS\system32\sys32time.dll
2007-09-02 10:50 304,453 ----a-w C:\Documents and Settings\Owner\mcc.exe
2007-09-02 06:01 160,768 ----a-w C:\Documents and Settings\Owner\gotgo.exe
2006-01-02 08:03 300,760 --sh--w C:\WINDOWS\mshostsr.exe
1989-12-12 16:10 404,208 --sh--r C:\WINDOWS\orqeenq.exe
2006-02-23 07:31 19,456 --sh--r C:\WINDOWS\system\svchost.dll
.

((((((((((((((((((((((((((((( snapshot@2007-12-07_14.58.32.14 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-27 11:58:11 140,288 ----a-w C:\WINDOWS\catchme.exe
+ 2007-12-08 11:32:45 141,824 ----a-w C:\WINDOWS\catchme.exe
- 2007-12-07 22:45:48 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-12-09 06:25:57 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-12-07 22:45:48 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-09 06:25:57 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-12-07 22:45:48 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-09 06:25:57 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-07 22:53:12 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\ntuser.dat
+ 2007-12-09 06:11:53 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95CB3857-A0E7-F21B-EE5B-FD8A45862C97}]
C:\WINDOWS\System32\cnsi.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RecordNow!"="" []
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-03-28 14:10]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" []
"Notn"="C:\WINDOWS\System32\SCURIT~1\wuaclt.exe" []
"Omht"="C:\WINDOWS\??stem32\?poolsv.exe" [2003-08-15 18:40]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-01-26 02:24]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 16:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-11-18 07:11]
"HPHUPD05"="c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 03:23]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-08-21 03:15]
"KBD"="C:\HP\KBD\KBD.EXE" [2007-12-08 22:01]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 08:01]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-01-26 04:29]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2003-11-03 16:50]
"VTTimer"=" " []
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 00:59]
"LTMSG"="LTMSG.exe" [2003-07-14 17:52 C:\WINDOWS\ltmsg.exe]
"PS2"=" " []
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-03 20:35 C:\WINDOWS\ALCXMNTR.EXE]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe" [2003-03-12 04:23]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-03-28 14:10]
"QuickTime Task"="C:\PROGRA~1\QUICKT~1\qttask.exe" [2007-09-24 23:37]

C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSub.exe [2004-01-27 02:26:18]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSub.exe [2004-01-27 02:26:18]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-01-26 05:20:47]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 12:19:24]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-01-19 00:44:15]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2003-07-30 04:49:48]
SBC Self Support Tool.lnk - C:\Program Files\SBC Self Support Tool\bin\matcli.exe [2006-07-11 13:16:00]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


.
Contents of the 'Scheduled Tasks' folder
"2007-10-19 00:33:48 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-08 22:33:14
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-08 22:34:05
C:\ComboFix2.txt ... 2007-12-08 22:18
C:\ComboFix3.txt ... 2007-12-07 22:31
.
--- E O F ---

rainshield
2007-12-10, 22:10
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:03:28 PM, on 12/10/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\3582-490\KBD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\PROGRA~1\Yahoo!\SEARCH~1\SEARCH~1.EXE
C:\PROGRA~1\SUPERA~1\SUPERA~1.EXE
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe
C:\PROGRA~1\COMPAQ~1\1940576\Program\BACKWE~1.EXE
C:\PROGRA~1\INTERM~1\SPAMSU~1\SpamSub.exe
C:\PROGRA~1\SBCSEL~1\bin\mpbtn.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\scanner.exe
C:\WINDOWS\svchost.com
C:\DOCUME~1\Owner\LOCALS~1\Temp\3582-490\KBD.EXE
C:\WINDOWS\svchost.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn7\yt.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn7\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer]
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PS2]
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\qttask.exe" -atboottime
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - S-1-5-18 Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'Default user')
O4 - .DEFAULT User Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (User 'Default user')
O4 - .DEFAULT User Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'Default user')
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe

--
End of file - 8015 bytes

ken545
2007-12-10, 22:14
Your log looks fine :bigthumb:

C:\Program Files\MyWebSearch <-- Delete this if its still present.

How is your system running now??

rainshield
2007-12-10, 22:20
thanks alot for ur helps. i already removed C:/programfile/mywebsearch folder and i can say that my pc run much more smoothly than before alot. Im really appreciated of that. Im just wondering which program i should use to protect my pc against all the virus, trojans n spyware...

ken545
2007-12-10, 22:30
You want to open up Internet Explorer and go to Tools> Windows Updates and download and install all critical updates including Service Pack 2 and beyond. You can download it directly from here if you like and you can also order it on a CD free from Microsoft and also get free support installing it if you need to.

http://www.microsoft.com/windowsxp/sp2/default.mspx


After you install Service Pack 2 and not before, then update your Java.


Your Java is out of date and leaving your system vulnerable.
Go to your Add-Remove Programs in the Control Panel and uninstall any previous versions of Java (J2SE Runtime Environment)
It should have an icon next to it:
http://users.telenet.be/bluepatchy/miekiemoes/images/javaicon.jpg
Select it and click Remove.
Reboot your system.
Then go to the Sun Microsystems (http://www.java.com/en/download/manual.jsp) and install the update
Java Runtime Environment Version 6 Update 3 <--This is what you need to download and install.
If you chose the online installation, it will prompt you to run the program.
If you chose the offline installation, you will be prompted to save the file and you can run it from wherever you saved it.
Then after install you can verify your installation here Sun Java Verify (http://www.java.com/en/download/manual.jsp)
I like to to do the offline installation and save the setup file in case I may need it in the future

ComboFix /u <-- Highlight this with your mouse
Go to start > run and copy and paste in the field:
Then hit enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.


You can drag all the other tools we used to the trash.


How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
Tutorial for System Restore (http://www.bleepingcomputer.com/tutorials/tutorial56.html) <-- Do this first to prevent yourself from being reinfected.
WhattheTech (http://forums.whatthetech.com/So_how_did_I_get_infected_in_the_first_place_t57817.html)
TonyKlein CastleCops (http://www.castlecops.com/postlite7736-.html)
Grinler BleepingComputer (http://www.bleepingcomputer.com/forums/topic2520.html)
Geeks To Go (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
Dslreports (http://www.dslreports.com/faq/10002)


Glad things are well

Ken :santa: