PDA

View Full Version : Pre help help? Kaspersky and Spybot



Owlman
2008-02-18, 13:50
First off, thanks for providing such a valuable service, and for free too. As we say here in Oz "your blood's worth bottling!"

My wife's PC has acquired trojan-clicker.html.iframe.jr. Since I am the guru, compared to her anyway, she asked me to have a look to see if I could get rid of it. I tried another help forum, forums.techguy.org. They suggested I run a Panda scan, which I tried but it hung half way through and I had to cancel it. Now I get heaps of warnings from Kaspersky about IE (and Firefox, and Incredimail) attempting to load altered modules. I denied them all, and IE seems to be running. But now I'm afraid I've made things worse, so thought I'd try a different forum that didn't require me to run Panda.

That brings me to my problem. Kaspersky V7 is already installed on this PC. So I'm not sure if it is wise to install Spybot as well. Especially after my experience with Panda. Won't they trip over each other? Will I have to disable Kaspersky to run Spybot? Or can they happily coexist? Once the PC is cleaned, should Spybot be deinstalled, or should I be running both Spybot and Kaspersky?

Your assistance is greatly appreciated,
Ian

steamwiz
2008-02-23, 15:58
HI Ian

AS you have posted at techguy, you should return to your thread there, and see it through ... I and many others here also post at techguy, and I can tell you, there is nothing more irritating than starting to help some, then they disappear. they have very good experts posting there and will not let you down ... if you are having problems running a certain program, tell them, there are alternative programs which they will give you.

KASPERSKY is an anti-virus ... just because you have it installed does not mean you can't run the on-line KASPERSKY scan, they are 2 different programs, they will not conflict, but you should disable/turn off any resident av when running an on-line scan anyway.

Spybot is an anti-malware not an av, it will run quite happily alongside your KASPERSKY anti-virus. yes you can run both.

steam

Owlman
2008-02-24, 13:33
Thanks Steamwiz,

Well. it appears that techguy reads this thread too, maybe. My post there seems to have disappeared, as has my registration. After my disastrous experience with Panda, I tried to extract myself from that forum as politely as possible to try a different forum, but I guess my diplomatic skills are not as effective as I would have hoped. I tried to indicate that nobody should attempt to do any analysis of my problem as I hadn't been through all the steps, so hopefully I haven't wasted too much peoples' time.

Anyway, the next thing we are trying is to backup everything, reformat and reinstall. Everything seems to be infected, and it's the only option I know will remove all trace permanently. Probably a good thing anyway, as there are other problems I'd like to address as well, like the hard drive needlessly partitioned, and a clean install of Windows is always a good place to start (in my limited experience anyway). Her 20yo son has been using the computer too, so gawd knows what else is lurking in the bowels of the O/S.

Cheers,
Ian

steamwiz
2008-02-24, 14:24
HI Ian

Sometimes if we suspect someone is being helped on more than one forum (tying up more than one helper) we will do a check ... also following removal directions on more than one forum at the same time can be disastrous. so they may have checked ... I didn't.

I know you didn't do any of the above, & I'm very surprised at the actions of techguy, I've never heard of them doing that before, unless the poster was very abusive. They would normally have just locked your thread if you were being helped elsewhere...

From your first post, I think you are probably right to reinstall, whenever possible it's always the best option, as you get a guaranteed clean machine again .... just be careful, if you save any executable files, then run them on your new install, then if they are infected, you will also become reinfected...

upload them here first & have them scanned before running them :-

http://www.virustotal.com/flash/index_en.html

If you would like me to have a look at your computer first & see if it is recoverable, please follow the directions here :-

http://forums.spybot.info/showthread.php?t=288

Post the hijackthis log & the KAV log

thanks

steam

Owlman
2008-02-26, 12:30
Thanks Steamwiz,

I obviously have yet to get the hang of these forums. I posted a reply to you last night, but it seems to have vanished into the ether...

Anyway, thank you, yes please have a look at the logs to see if the system can be rescued. I had a look at this PC last night, and there is so much STUFF the idea of a complete rebuild is very daunting. Also, 'er ladyship has (of her own bat) downloaded and run Spybot which has "found and deleted lots of stuff" (that's as specific as she gets). Anyway, here are the logs you requested. The Kaspersky log created itself as an html document, so I've just pasted it in as text. Hope that's okay.

Thanks in advance,
Ian
----------------------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:23:01 PM, on 26/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\INCRED~1\bin\IMAPP.EXE
C:\Program Files\Skype\Plugin Manager\skypePM.exe
E:\Spybot - Search & Destroy\TeaTimer.exe
C:\Documents and Settings\User\Desktop\Internet Explorer2\IEXPLORE.EXE
C:\PROGRA~1\INCRED~1\bin\IncMail.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Documents and Settings\User\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

http://www.linkreferral.com/accountwel.pl?email=loseweight@juice-detox.com&password=iamrich
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay

Toolbar2\eBayTb.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} -

E:\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program

files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program

Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: eBay - {CD9B7762-DFBC-42B1-BB30-02A78287B456} - C:\PROGRA~1\PRICEP~1\IEBUTT~2.DLL (file

missing)
O2 - BHO: (no name) - {E2E9A890-7007-45E8-99C0-6B3CF110F7CB} - C:\WINDOWS\system32\mchgrcois.dll

(file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] E:\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL

SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: IncrediMail.lnk = C:\Program Files\IncrediMail\bin\IncMail.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat

7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet

Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay

Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration -

{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -

http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {77DD44BF-551D-4E3C-82CD-D637D5018D3C} -

http://www.surveys.com/promptcast/Installs/SURVEYS.COM%20PROMPTCAST%20SETUP.cab
O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} - http://advnt01.com/dialer/int_ver34.CAB
O16 - DPF: {CDCBE0F1-D13A-4F86-A963-3A272D3ABA7E} -

http://advnt01.com/dialer/internazionale_ver15.CAB
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -

http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5213/mcfscan.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -

C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky

Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program

Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google

Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common

Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
O23 - Service: NT LM Security Support Provider NtLmSspsrservice (NtLmSspsrservice) - Unknown owner -

C:\WINDOWS\system32\lr87.exe (file missing)
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common

Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)

--
End of file - 6544 bytes

Owlman
2008-02-26, 12:34
---------------------------------------------------------
The Kaspersky log
---------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, February 26, 2008 6:55:40 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/02/2008
Kaspersky Anti-Virus database records: 579710

Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\
F:\
G:\

Scan Statistics
Total number of scanned objects 315215
Number of viruses found 0
Number of infected objects 0
Number of suspicious objects 0
Duration of the scan process 04:39:25

Infected Object Name Virus Name Last Action
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox2.idx Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox2.dat Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{5D75961A-418A-44BD-919A-54095D6B4C35}.bin Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\report.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\eventlog.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\046f_File_Monitoring_eventlog.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\0471_Web_Monitoring_eventlog.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\0470_Mail_Monitoring_eventlog.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\detected.idx Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\detected.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\0476_PrivacyControl_eventcritlog.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\0476_PrivacyControl_eventlog.rpt Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\User\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\User\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\User\Local Settings\History\History.IE5\MSHist012008022520080226\index.dat Object is locked skipped
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\PC5IM2L7\resize[1].htm Object is locked skipped
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\User\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\User\Application Data\Skype\margocourtney\index2.dat Object is locked skipped
C:\Documents and Settings\User\Application Data\Skype\margocourtney\contactgroup256.dbb Object is locked skipped
C:\Documents and Settings\User\Application Data\Skype\margocourtney\chatmsg256.dbb Object is locked skipped
C:\Documents and Settings\User\Application Data\Skype\margocourtney\chat512.dbb Object is locked skipped
C:\Documents and Settings\User\Application Data\Skype\margocourtney\chatmsg512.dbb Object is locked skipped
C:\Documents and Settings\User\Application Data\Skype\margocourtney\chatmsg1024.dbb Object is locked skipped
C:\Documents and Settings\User\Application Data\Skype\margocourtney\callmember256.dbb Object is locked skipped
C:\Documents and Settings\User\Application Data\Skype\margocourtney\user16384.dbb Object is locked skipped
C:\Documents and Settings\User\Application Data\Skype\margocourtney\dyncontent\bundle.dat Object is locked skipped
C:\Documents and Settings\User\Application Data\Skype\margocourtney\chatmember256.dbb Object is locked skipped
C:\Documents and Settings\User\Application Data\Skype\margocourtney\user32768.dbb Object is locked skipped
C:\Documents and Settings\User\Application Data\Skype\margocourtney\chatmsg2048.dbb Object is locked skipped
C:\Documents and Settings\User\Application Data\Skype\margocourtney\profile4096.dbb Object is locked skipped
C:\Documents and Settings\User\Application Data\Skype\margocourtney\voicemail256.dbb Object is locked skipped
C:\Documents and Settings\User\Application Data\Skype\margocourtney\user4096.dbb Object is locked skipped
C:\Documents and Settings\User\Application Data\Skype\margocourtney\user1024.dbb Object is locked skipped
C:\Documents and Settings\User\Application Data\Skype\margocourtney\call256.dbb Object is locked skipped
C:\Documents and Settings\User\ntuser.dat.LOG Object is locked skipped

Scan process completed.

Owlman
2008-02-26, 12:37
Well, I ended up not posting it as html, it was too long that way, figured how to save it as text. Couldn't edit the original post:sad:

steamwiz
2008-02-26, 23:39
Hi

Your logs are remarkable clean ... just 3 entries in hijackthis & the KAS scan is clean ...

I want you to fix the 3 entries in hijackthis then run 2 more programs for me ...

Disconnect from the internet Close ALL browser windows (including this one) - run hijackthis and tick to fix (check the box next to) the list below.........when all are ticked (checked) click the Fix Checked button at the bottom. :-

O2 - BHO: (no name) - {E2E9A890-7007-45E8-99C0-6B3CF110F7CB} - C:\WINDOWS\system32\mchgrcois.dll (file missing)

O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} - http://advnt01.com/dialer/int_ver34.CAB
O16 - DPF: {CDCBE0F1-D13A-4F86-A963-3A272D3ABA7E} - http://advnt01.com/dialer/internazionale_ver15.CAB


THEN ...

Download Superantispyware.

http://www.superantispyware.com/

Once downloaded and installed update the definitions
and then run a full system scan quarantine what it finds!

* Double-click SUPERAntiSypware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)

http://www.superantispyware.com/definitions.html

* Under "Configuration and Preferences", click the Preferences button.
* Click the Scanning Control tab.
* Under Scanner Options make sure the following are checked (leave all others unchecked):
o Close browsers before scanning.
o Scan for tracking cookies.
o Terminate memory threats before quarantining.
* Click the "Close" button to leave the control center screen.
* Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under "Complete Scan", choose Perform Complete Scan.
* Click "Next" to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
* Make sure everything has a checkmark next to it and click "Next".
* A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
* If asked if you want to reboot, click "Yes".
* To retrieve the removal information after reboot, launch SUPERAntispyware again.
o Click Preferences, then click the Statistics/Logs tab.
o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
o Please copy and paste the Scan Log results in your next reply.
* Click Close to exit the program.

THEN ...

1. Please follow these directions to run Combofix & post a log.

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

2. When finished, it will produce a logfile located at C:\ComboFix.txt.
3. Post the contents of that log in your next reply with a new hijackthis log.

Please remember to post :-

1. SUPERAntiSpyware Scan Log
2. C:\ComboFix.txt
3. a new hijackthis log.( run after everything else)

steam

Owlman
2008-03-01, 01:21
Confusion reigns. I posted a response with the superantispyware log here about an hour ago, but it's not here now. Second post I've lost...

And I don't know why combofix is saying I don't have recovery console installed. I installed it as per instructions, and when I rebooted the option to start it was displayed...:sad:

I'll try again...
--------------------------------------------------------
ComboFix 08-03-01 - User 2008-03-01 9:24:01.1 - FAT32x86
Running from: C:\Documents and Settings\User\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\User\g2mdlhlpx.exe
C:\WINDOWS\system32\drivers\rpjgaudq.dat
C:\WINDOWS\system32\mchgrcois.dll
C:\WINDOWS\system32\model.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_BTLFQBQW
-------\btlfqbqw


((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-29 )))))))))))))))))))))))))))))))
.

2008-02-29 21:45 . 2008-02-29 21:45 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-29 21:45 . 2008-02-29 21:45 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-29 21:45 . 2008-02-29 21:45 <DIR> d-------- C:\Documents and Settings\User\Application Data\SUPERAntiSpyware.com
2008-02-29 21:45 . 2008-02-29 21:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-25 22:36 . 2008-02-25 22:36 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-02-25 08:53 . 2008-02-25 08:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-25 08:32 . 2008-02-25 08:32 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-02-18 15:10 . 2008-02-18 16:48 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-02-18 15:10 . 2008-02-18 16:48 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-02-09 14:08 . 2008-02-09 14:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-09 14:08 . 2008-02-09 14:18 91,700 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-02-09 14:08 . 2008-02-09 14:18 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-02-09 14:08 . 2008-03-01 09:30 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-02-09 14:08 . 2008-03-01 09:30 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-02-09 14:08 . 2008-03-01 09:30 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-09 14:08 . 2008-03-01 09:30 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-09 14:07 . 2008-02-09 14:07 <DIR> d-------- C:\Program Files\Kaspersky Internet Security
2008-02-04 08:31 . 2008-02-04 08:31 <DIR> d--hs---- C:\FOUND.001
2008-02-03 21:18 . 2007-12-07 13:21 6,066,176 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-02-03 21:18 . 2007-07-01 14:31 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-02-03 21:18 . 2007-07-01 14:36 991,232 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-02-03 21:18 . 2007-12-07 13:21 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-02-03 21:18 . 2007-12-07 13:21 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-02-03 21:18 . 2007-12-07 13:21 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-02-03 21:18 . 2007-12-07 13:21 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2008-02-03 21:18 . 2007-12-07 13:21 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-02-03 21:18 . 2007-12-06 22:00 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-26 00:23 --------- d-----w C:\Program Files\SMPlayer
2008-01-25 23:43 --------- d-----w C:\Program Files\Browser Hijack Recover
2008-01-23 02:58 --------- d-----w C:\Program Files\Kaspersky Lab
2008-01-23 02:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-01-22 08:59 102,664 ----a-w C:\WINDOWS\system32\drivers\tmcomm.sys
2008-01-16 01:30 --------- d-----w C:\Program Files\Citrix
2008-01-11 14:42 29,409,880 ----a-w C:\kav7.0.1.321en.exe
2007-12-31 23:37 642 ----a-w C:\scl.dat
2007-12-23 22:21 20,540,817 ------w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_12_24_09_14_03_full.dmp.zip
2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-12 00:41 27,126 ----a-w C:\Documents and Settings\User\TB2Categories000.dat
2007-12-07 14:37 3,059,200 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-06 13:07 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-08-30 21:53 2,445,262 ------w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_08_31_08_46_32_full.dmp.zip
2007-08-30 21:53 116,183 ------w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_08_31_01_51_25_small.dmp.zip
2007-08-27 09:28 256 ----a-w C:\Documents and Settings\User\pool.bin
2006-06-08 18:58 40,089 ------w C:\WINDOWS\Internet Logs\zlclient_2nd_2006_06_05_07_10_58_small.dmp.zip
2007-07-06 23:00 109 --sha-w C:\WINDOWS\system32\686630094.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-08-31 17:40 22879528]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-02-07 13:18 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 14:56 15360]
"SpybotSD TeaTimer"="E:\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-28 14:23 1481968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-12-02 12:47 185896]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-05-15 08:22 35328]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-06-28 12:51 218376]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 14:56 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
"NoToolbarCustomize"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
"NoToolbarCustomize"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\xerox\\nwwia\\XrxFTPLt.exe"=
"C:\\Program Files\\IncrediMail\\BIN\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\BIN\\IMApp.exe"=
"E:\\NetObjects Fusion 7\\Fusion.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\IncrediMail\\BIN\\ImpCnt.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"53785:TCP"= 53785:TCP:PORT_53785

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-01 09:32:38
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\savedump.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\PROGRA~1\INCRED~1\bin\IMAPP.EXE
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-03-01 9:36:14 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-29 22:35:56
.
2008-02-29 16:02:05 --- E O F ---

Owlman
2008-03-01, 01:22
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:49:11 AM, on 1/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
E:\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\INCRED~1\bin\IMAPP.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\User\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.linkreferral.com/accountwel.pl?email=loseweight@juice-detox.com&password=iamrich
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: eBay - {CD9B7762-DFBC-42B1-BB30-02A78287B456} - C:\PROGRA~1\PRICEP~1\IEBUTT~2.DLL (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] E:\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: IncrediMail.lnk = C:\Program Files\IncrediMail\bin\IncMail.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {77DD44BF-551D-4E3C-82CD-D637D5018D3C} - http://www.surveys.com/promptcast/Installs/SURVEYS.COM%20PROMPTCAST%20SETUP.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5213/mcfscan.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
O23 - Service: NT LM Security Support Provider NtLmSspsrservice (NtLmSspsrservice) - Unknown owner - C:\WINDOWS\system32\lr87.exe (file missing)
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)

--
End of file - 6487 bytes

Owlman
2008-03-01, 01:26
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/29/2008 at 11:34 PM

Application Version : 4.0.1152

Core Rules Database Version : 3412
Trace Rules Database Version: 1404

Scan type : Complete Scan
Total Scan Time : 01:44:55

Memory items scanned : 401
Memory threats detected : 0
Registry items scanned : 5281
Registry threats detected : 2
File items scanned : 28428
File threats detected : 849

Adware.Tracking Cookie
C:\Documents and Settings\User\Cookies\user@_pt14[2].txt
C:\Documents and Settings\User\Cookies\user@iacas.adbureau[1].txt
C:\Documents and Settings\User\Cookies\user@hc2.humanclick[2].txt
C:\Documents and Settings\User\Cookies\user@stat.3bepb[2].txt
C:\Documents and Settings\User\Cookies\user@54459822[2].txt
C:\Documents and Settings\User\Cookies\user@yadro[6].txt
C:\Documents and Settings\User\Cookies\user@cgi-bin[22].txt
C:\Documents and Settings\User\Cookies\user@media.skyauction[1].txt
C:\Documents and Settings\User\Cookies\user@amazing1clickcovers[2].txt
C:\Documents and Settings\User\Cookies\user@serving-sys[1].txt
C:\Documents and Settings\User\Cookies\user@secure.advancedcleaner[2].txt
C:\Documents and Settings\User\Cookies\user@4.adbrite[1].txt
C:\Documents and Settings\User\Cookies\user@server.iad.liveperson[3].txt
C:\Documents and Settings\User\Cookies\user@adbrite[5].txt
C:\Documents and Settings\User\Cookies\user@fdau.adbureau[2].txt
C:\Documents and Settings\User\Cookies\user@ecnext.advertserve[1].txt
C:\Documents and Settings\User\Cookies\user@paypal.112.2o7[4].txt
C:\Documents and Settings\User\Cookies\user@semdirector.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@findarticles[1].txt
C:\Documents and Settings\User\Cookies\user@ads.revsci[1].txt
C:\Documents and Settings\User\Cookies\user@mediaonenetwork[6].txt
C:\Documents and Settings\User\Cookies\user@brightbuilders.122.2o7[2].txt
C:\Documents and Settings\User\Cookies\user@ads.adbrite[3].txt
C:\Documents and Settings\User\Cookies\user@56081914[2].txt
C:\Documents and Settings\User\Cookies\user@traffic.buyservices[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wgkyepdpwlo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@revenue[2].txt
C:\Documents and Settings\User\Cookies\user@sales.liveperson[1].txt
C:\Documents and Settings\User\Cookies\user@74613876[3].txt
C:\Documents and Settings\User\Cookies\user@ad.yieldmanager[2].txt
C:\Documents and Settings\User\Cookies\user@atwola[2].txt
C:\Documents and Settings\User\Cookies\user@tribalfusion[2].txt
C:\Documents and Settings\User\Cookies\user@ffxcam.cracker.com[6].txt
C:\Documents and Settings\User\Cookies\user@web-stat[5].txt
C:\Documents and Settings\User\Cookies\user@questionmarket[2].txt
C:\Documents and Settings\User\Cookies\user@hotitemfinder[3].txt
C:\Documents and Settings\User\Cookies\user@enhance[3].txt
C:\Documents and Settings\User\Cookies\user@atdmt[2].txt
C:\Documents and Settings\User\Cookies\user@clicks.smartbizsearch[2].txt
C:\Documents and Settings\User\Cookies\user@dealtime[3].txt
C:\Documents and Settings\User\Cookies\user@wholesalemarketer.122.2o7[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjnyoiazkcp.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjmyogd5efo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@skyauction.122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@media.sensis.com[5].txt
C:\Documents and Settings\User\Cookies\user@clickbank[2].txt
C:\Documents and Settings\User\Cookies\user@bs.serving-sys[3].txt
C:\Documents and Settings\User\Cookies\user@nielsen.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@www.ezytrack[5].txt
C:\Documents and Settings\User\Cookies\user@www.stopzilla[2].txt
C:\Documents and Settings\User\Cookies\user@adopt.euroclick[3].txt
C:\Documents and Settings\User\Cookies\user@msnportal.112.2o7[2].txt
C:\Documents and Settings\User\Cookies\user@www.hotitemfinder[4].txt
C:\Documents and Settings\User\Cookies\user@stats.sitesuite[4].txt
C:\Documents and Settings\User\Cookies\user@qksrv[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6whkogndziho.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@sitestat.mayoclinic[1].txt
C:\Documents and Settings\User\Cookies\user@interclick[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wbmywhajgbo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@web4.realtracker[1].txt
C:\Documents and Settings\User\Cookies\user@ads.as4x.tmcs[1].txt
C:\Documents and Settings\User\Cookies\user@__frm5[1].txt
C:\Documents and Settings\User\Cookies\user@advertising[2].txt
C:\Documents and Settings\User\Cookies\user@bizrate[6].txt
C:\Documents and Settings\User\Cookies\user@server.iad.liveperson[2].txt
C:\Documents and Settings\User\Cookies\user@virginmobile.122.2o7[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfkocod5kgo.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@buycom.122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@stat.dealtime[5].txt
C:\Documents and Settings\User\Cookies\user@infopia.112.2o7[2].txt
C:\Documents and Settings\User\Cookies\user@tracker.mediatracker.co[3].txt
C:\Documents and Settings\User\Cookies\user@122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@metacafe.122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@ad.zanox[1].txt
C:\Documents and Settings\User\Cookies\user@gomyron[1].txt
C:\Documents and Settings\User\Cookies\user@advancedcleaner[1].txt
C:\Documents and Settings\User\Cookies\user@www.clickxchange[1].txt
C:\Documents and Settings\User\Cookies\user@2o7[2].txt
C:\Documents and Settings\User\Cookies\user@www.googleadservices[1].txt
C:\Documents and Settings\User\Cookies\user@thriftyaustralia.122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@pro-market[1].txt
C:\Documents and Settings\User\Cookies\user@mpire.112.2o7[2].txt
C:\Documents and Settings\User\Cookies\user@roiservice[6].txt
C:\Documents and Settings\User\Cookies\user@www.googleadservices[4].txt
C:\Documents and Settings\User\Cookies\user@ads.as4x.tmcs.ticketmaster[2].txt
C:\Documents and Settings\User\Cookies\user@summitmedia.com[2].txt
C:\Documents and Settings\User\Cookies\user@perf.overture[1].txt
C:\Documents and Settings\User\Cookies\user@banners.empoweredcomms.com[1].txt
C:\Documents and Settings\User\Cookies\user@equs.liveperson[1].txt
C:\Documents and Settings\User\Cookies\user@revsci[1].txt
C:\Documents and Settings\User\Cookies\user@www.pcantiviruspro[2].txt
C:\Documents and Settings\User\Cookies\user@1072645447[1].txt
C:\Documents and Settings\User\Cookies\user@112.2o7[8].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjmigjczkko.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@overture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wclokhc5gkp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@partner2profit[1].txt
C:\Documents and Settings\User\Cookies\user@www.googleadservices[2].txt
C:\Documents and Settings\User\Cookies\user@harpo.122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@cracker.com[7].txt
C:\Documents and Settings\User\Cookies\user@www.eztrackz[1].txt
C:\Documents and Settings\User\Cookies\user@nbcuniversal.122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@elitemarketeer[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wbkowndpgkp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@sensismediasmart.com[1].txt
C:\Documents and Settings\User\Cookies\user@specificclick[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfliagc5gep.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@cbclicks[1].txt
C:\Documents and Settings\User\Cookies\user@cgi-bin[12].txt
C:\Documents and Settings\User\Cookies\user@adlegend[1].txt
C:\Documents and Settings\User\Cookies\user@www.ppctracking[2].txt
C:\Documents and Settings\User\Cookies\user@brightcove.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@tourismwesternaustralia.112.2o7[2].txt
C:\Documents and Settings\User\Cookies\user@content.clickbank[2].txt
C:\Documents and Settings\User\Cookies\user@www.googleadservices[5].txt
C:\Documents and Settings\User\Cookies\user@xiti[3].txt
C:\Documents and Settings\User\Cookies\user@server.iad.liveperson[4].txt
C:\Documents and Settings\User\Cookies\user@jamster.com[3].txt
C:\Documents and Settings\User\Cookies\user@adserver.toptenreviews[2].txt
C:\Documents and Settings\User\Cookies\user@ads.techguy[2].txt
C:\Documents and Settings\User\Cookies\user@1068188284[1].txt
C:\Documents and Settings\User\Cookies\user@eas.apm.emediate[2].txt
C:\Documents and Settings\User\Cookies\user@tripod[2].txt
C:\Documents and Settings\User\Cookies\user@adopt.specificclick[2].txt
C:\Documents and Settings\User\Cookies\user@realmedia[2].txt
C:\Documents and Settings\User\Cookies\user@thomsoneducationdirect.122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@tracked[1].txt
C:\Documents and Settings\User\Cookies\user@tacoda[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjkyojcjado.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@clickaider[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjk4und5sfo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@www.googleadservices[3].txt
C:\Documents and Settings\User\Cookies\user@pandasoftware.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@optus.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@www.clickbank[2].txt
C:\Documents and Settings\User\Cookies\user@www.halstats[2].txt
C:\Documents and Settings\User\Cookies\user@toplist[1].txt
C:\Documents and Settings\User\Cookies\user@microsoftwga.112.2o7[3].txt
C:\Documents and Settings\User\Cookies\user@ads.pointroll[2].txt
C:\Documents and Settings\User\Local Settings\Temp\Cookies\user@adbrite[2].txt
C:\Documents and Settings\User\Local Settings\Temp\Cookies\user@paypal.112.2o7[1].txt
C:\Documents and Settings\User\Local Settings\Temp\Cookies\user@ads.adbrite[1].txt
C:\Documents and Settings\User\Local Settings\Temp\Cookies\user@4.adbrite[1].txt
C:\Documents and Settings\User\Local Settings\Temp\Cookies\user@wholesalemarketer.122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@indextools[2].txt
C:\Documents and Settings\User\Cookies\user@clickaudit[1].txt
C:\Documents and Settings\User\Cookies\user@www.dgm2[1].txt
C:\Documents and Settings\User\Cookies\user@wordtracker[2].txt
C:\Documents and Settings\User\Cookies\user@www.wordtracker[1].txt
C:\Documents and Settings\User\Cookies\user@stats.sitesuite[1].txt
C:\Documents and Settings\User\Cookies\user@banner.32vegas[1].txt
C:\Documents and Settings\User\Cookies\user@112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@printmediakit.economist[1].txt
C:\Documents and Settings\User\Cookies\user@www.clickxchange[3].txt
C:\Documents and Settings\User\Cookies\user@ads.optusnet.com[2].txt
C:\Documents and Settings\User\Cookies\user@www.checkmystats.com[2].txt
C:\Documents and Settings\User\Cookies\user@checkmystats.com[2].txt
C:\Documents and Settings\User\Cookies\user@track1.uptilt[2].txt
C:\Documents and Settings\User\Cookies\user@ad.sensismediasmart.com[1].txt
C:\Documents and Settings\User\Cookies\user@dynamicsitestats[1].txt
C:\Documents and Settings\User\Cookies\user@adsense[7].txt
C:\Documents and Settings\User\Cookies\user@roiservice[3].txt
C:\Documents and Settings\User\Cookies\user@paypal.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@www.firecrackerdays[1].txt
C:\Documents and Settings\User\Cookies\user@adbrite[2].txt
C:\Documents and Settings\User\Cookies\user@gostats[1].txt
C:\Documents and Settings\User\Cookies\user@websponsors[1].txt
C:\Documents and Settings\User\Cookies\user@www.websponsors[2].txt
C:\Documents and Settings\User\Cookies\user@112.2o7[2].txt
C:\Documents and Settings\User\Cookies\user@roiservice[1].txt
C:\Documents and Settings\User\Cookies\user@usatoday1.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@vhost.oddcast[2].txt
C:\Documents and Settings\User\Cookies\user@au.hwstats[1].txt
C:\Documents and Settings\User\Cookies\user@www.ezytrack[1].txt
C:\Documents and Settings\User\Cookies\user@media.sensis.com[1].txt
C:\Documents and Settings\User\Cookies\user@media3.sitebrand[2].txt
C:\Documents and Settings\User\Cookies\user@mediaonenetwork[3].txt
C:\Documents and Settings\User\Cookies\user@ads.active[1].txt
C:\Documents and Settings\User\Cookies\user@paypal.112.2o7[3].txt
C:\Documents and Settings\User\Cookies\user@cancertreatmentcenter.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@yadro[2].txt
C:\Documents and Settings\User\Cookies\user@ads.cnn[2].txt
C:\Documents and Settings\User\Cookies\user@112.2o7[3].txt
C:\Documents and Settings\User\Cookies\user@incredimailltd.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@www.checkmystats.com[3].txt
C:\Documents and Settings\User\Cookies\user@www.roiconversiontracker[2].txt
C:\Documents and Settings\User\Cookies\user@clickbank[3].txt
C:\Documents and Settings\User\Cookies\user@www.trafficswarm[2].txt
C:\Documents and Settings\User\Cookies\user@yadro[4].txt
C:\Documents and Settings\User\Cookies\user@www.clickmanage[2].txt
C:\Documents and Settings\User\Cookies\user@banner.usacasino[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wgkismdpmhq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@cracker.com[2].txt
C:\Documents and Settings\User\Cookies\user@ffxcam.cracker.com[3].txt
C:\Documents and Settings\User\Cookies\user@linkstattrack[1].txt
C:\Documents and Settings\User\Cookies\user@indextools[5].txt
C:\Documents and Settings\User\Cookies\user@ath.belnk[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfloejc5wbq.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfl4ondzmgo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wglowgdzmco.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@counter[1].txt
C:\Documents and Settings\User\Cookies\user@1.primaryads[1].txt
C:\Documents and Settings\User\Cookies\user@meetupcom.122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@xiti[1].txt
C:\Documents and Settings\User\Cookies\user@ebay.admarketplace[1].txt
C:\Documents and Settings\User\Cookies\user@aotgroup.122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@cracker.com[1].txt
C:\Documents and Settings\User\Cookies\user@www.santadealtime[1].txt
C:\Documents and Settings\User\Cookies\user@paypal.112.2o7[2].txt
C:\Documents and Settings\User\Cookies\user@bizrate[1].txt
C:\Documents and Settings\User\Cookies\user@checkmystats.com[3].txt
C:\Documents and Settings\User\Cookies\user@indextools[1].txt
C:\Documents and Settings\User\Cookies\user@adsense[9].txt
C:\Documents and Settings\User\Cookies\user@counter.fateback[2].txt
C:\Documents and Settings\User\Cookies\user@clicksor[1].txt
C:\Documents and Settings\User\Cookies\user@stat.onestat[2].txt
C:\Documents and Settings\User\Cookies\user@bizrate[2].txt
C:\Documents and Settings\User\Cookies\user@mpire.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@webstats[1].txt
C:\Documents and Settings\User\Cookies\user@mycounter.tinycounter[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjmykncpedo.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@wordtracker[5].txt
C:\Documents and Settings\User\Cookies\user@newsinteractive.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@directtrack[2].txt
C:\Documents and Settings\User\Cookies\user@seoelite[2].txt
C:\Documents and Settings\User\Cookies\user@cracker.com[5].txt
C:\Documents and Settings\User\Cookies\user@aff.primaryads[2].txt
C:\Documents and Settings\User\Cookies\user@statswhere[1].txt
C:\Documents and Settings\User\Cookies\user@ads.realtechnetwork[1].txt
C:\Documents and Settings\User\Cookies\user@www.etracker[1].txt
C:\Documents and Settings\User\Cookies\user@kanoodle[2].txt
C:\Documents and Settings\User\Cookies\user@vhost.oddcast[4].txt
C:\Documents and Settings\User\Cookies\user@tracking.marketunited[1].txt
C:\Documents and Settings\User\Cookies\user@lists.wordtracker[3].txt
C:\Documents and Settings\User\Cookies\user@click.cashengines[2].txt
C:\Documents and Settings\User\Cookies\user@bidzcom.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wgkicpczgdo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjlocmdzsfp.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfk4chcpogo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfl4cgd5mcp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wflyeidjmlp.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@blizzardtracker[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6whlycodpiko.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@incredimailltd.112.2o7[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfmiakajccp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wgkyekdzekq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wgkoglc5kkp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6whlyencpiko.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjmispcjmep.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wgkyapc5klp.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6whl4gkazkbq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@wealthtraders.directtrack[1].txt
C:\Documents and Settings\User\Cookies\user@virginmobile.122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@www.ppctracking[1].txt
C:\Documents and Settings\User\Cookies\user@adsense[1].txt
C:\Documents and Settings\User\Cookies\user@stat.dealtime[2].txt
C:\Documents and Settings\User\Cookies\user@wotifcom.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@trafficwave[1].txt
C:\Documents and Settings\User\Cookies\user@www.trafficswarm[1].txt
C:\Documents and Settings\User\Cookies\user@instantclickfusion[1].txt
C:\Documents and Settings\User\Cookies\user@smileycentral[2].txt
C:\Documents and Settings\User\Cookies\user@ffxcam.cracker.com[2].txt
C:\Documents and Settings\User\Cookies\user@www.cracker.com[2].txt
C:\Documents and Settings\User\Cookies\user@dealtime[1].txt
C:\Documents and Settings\User\Cookies\user@bidtool.overture[1].txt
C:\Documents and Settings\User\Cookies\user@stat.dealtime[4].txt
C:\Documents and Settings\User\Cookies\user@pamedia.com[1].txt
C:\Documents and Settings\User\Cookies\user@digitalhomediscountptyltd.122.2o7[1].txt

Owlman
2008-03-01, 01:28
C:\Documents and Settings\User\Cookies\user@bigpond.122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@tracker.mediatracker.co[1].txt
C:\Documents and Settings\User\Cookies\user@wordtracker[1].txt
C:\Documents and Settings\User\Cookies\user@mediaonenetwork[4].txt
C:\Documents and Settings\User\Cookies\user@ientry[1].txt
C:\Documents and Settings\User\Cookies\user@mediamax[1].txt
C:\Documents and Settings\User\Cookies\user@tracker.tbkresources[2].txt
C:\Documents and Settings\User\Cookies\user@fcstats.bcentral[1].txt
C:\Documents and Settings\User\Cookies\user@sensismediasmart.com[2].txt
C:\Documents and Settings\User\Cookies\user@incredimailltd.112.2o7[3].txt
C:\Documents and Settings\User\Cookies\user@www.trafficdominatetricks[2].txt
C:\Documents and Settings\User\Cookies\user@chitika[1].txt
C:\Documents and Settings\User\Cookies\user@ads.digitalpoint[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wamiukajwhp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@www.findaproperty.co[2].txt
C:\Documents and Settings\User\Cookies\user@wordtracker[3].txt
C:\Documents and Settings\User\Cookies\user@counter.plugin[1].txt
C:\Documents and Settings\User\Cookies\user@adsensechat[2].txt
C:\Documents and Settings\User\Cookies\user@www.clickbanktoolkit[2].txt
C:\Documents and Settings\User\Cookies\user@www.redorbit[2].txt
C:\Documents and Settings\User\Cookies\user@adsense[2].txt
C:\Documents and Settings\User\Cookies\user@blizzardtracker[3].txt
C:\Documents and Settings\User\Cookies\user@mediaonenetwork[1].txt
C:\Documents and Settings\User\Cookies\user@media3.sitebrand[1].txt
C:\Documents and Settings\User\Cookies\user@vhost.oddcast[3].txt
C:\Documents and Settings\User\Cookies\user@adsense[5].txt
C:\Documents and Settings\User\Cookies\user@click-here-4[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfkoqkdzwco.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@stat.onestat[4].txt
C:\Documents and Settings\User\Cookies\user@seoelite[1].txt
C:\Documents and Settings\User\Cookies\user@3.adbrite[2].txt
C:\Documents and Settings\User\Cookies\user@www.seoelite[2].txt
C:\Documents and Settings\User\Cookies\user@listandtraffic[1].txt
C:\Documents and Settings\User\Cookies\user@richjerk.sitetracker[2].txt
C:\Documents and Settings\User\Cookies\user@bannersgomlm[1].txt
C:\Documents and Settings\User\Cookies\user@track.websitetrafficreport[1].txt
C:\Documents and Settings\User\Cookies\user@www.websitetrafficbuilder[1].txt
C:\Documents and Settings\User\Cookies\user@clickz[1].txt
C:\Documents and Settings\User\Cookies\user@sitestats[1].txt
C:\Documents and Settings\User\Cookies\user@www.findmyhosting[1].txt
C:\Documents and Settings\User\Cookies\user@www.cracker.com[1].txt
C:\Documents and Settings\User\Cookies\user@track[1].txt
C:\Documents and Settings\User\Cookies\user@www.trafficswarm[3].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjk4umajiho.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@www.maxistats.co[1].txt
C:\Documents and Settings\User\Cookies\user@qnsr[2].txt
C:\Documents and Settings\User\Cookies\user@www.findit.com[2].txt
C:\Documents and Settings\User\Cookies\user@clicktorrent[1].txt
C:\Documents and Settings\User\Cookies\user@microsoftwga.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@microsofteup.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@linkstattrack[2].txt
C:\Documents and Settings\User\Cookies\user@snagajob.122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@ads.monster[1].txt
C:\Documents and Settings\User\Cookies\user@singleswhoclick.com[1].txt
C:\Documents and Settings\User\Cookies\user@www.eliteinspectors[1].txt
C:\Documents and Settings\User\Cookies\user@fcstats.bcentral[2].txt
C:\Documents and Settings\User\Cookies\user@websponsors[2].txt
C:\Documents and Settings\User\Cookies\user@admarketplace[2].txt
C:\Documents and Settings\User\Cookies\user@icc.intellisrv[2].txt
C:\Documents and Settings\User\Cookies\user@yadro[5].txt
C:\Documents and Settings\User\Cookies\user@ath.belnk[1].txt
C:\Documents and Settings\User\Cookies\user@dynamicsitestats[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjloegczgfp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfkoejd5ogo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@stats.adbrite[2].txt
C:\Documents and Settings\User\Cookies\user@www.bestpayjobfinder[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjlyugajedp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@stats.liutilities[1].txt
C:\Documents and Settings\User\Cookies\user@redorbit[1].txt
C:\Documents and Settings\User\Cookies\user@jamster.com[1].txt
C:\Documents and Settings\User\Cookies\user@stat.onestat[3].txt
C:\Documents and Settings\User\Cookies\user@www.counters[1].txt
C:\Documents and Settings\User\Cookies\user@www.winfixer[2].txt
C:\Documents and Settings\User\Cookies\user@www.trafficgogetter[1].txt
C:\Documents and Settings\User\Cookies\user@ocean.directtrack[2].txt
C:\Documents and Settings\User\Cookies\user@anad.tacoda[2].txt
C:\Documents and Settings\User\Cookies\user@www.websponsors[1].txt
C:\Documents and Settings\User\Cookies\user@ads.kanoodle[1].txt
C:\Documents and Settings\User\Cookies\user@www.clickatell[1].txt
C:\Documents and Settings\User\Cookies\user@searchfeed[2].txt
C:\Documents and Settings\User\Cookies\user@clickbank[1].txt
C:\Documents and Settings\User\Cookies\user@roiservice[2].txt
C:\Documents and Settings\User\Cookies\user@counter.fateback[1].txt
C:\Documents and Settings\User\Cookies\user@sales.liveperson[2].txt
C:\Documents and Settings\User\Cookies\user@www.wordtracker[3].txt
C:\Documents and Settings\User\Cookies\user@lists.wordtracker[2].txt
C:\Documents and Settings\User\Cookies\user@bidtool.overture[2].txt
C:\Documents and Settings\User\Cookies\user@cracker.com[3].txt
C:\Documents and Settings\User\Cookies\user@1.primaryads[3].txt
C:\Documents and Settings\User\Cookies\user@adrevolver[2].txt
C:\Documents and Settings\User\Cookies\user@bigpond.122.2o7[2].txt
C:\Documents and Settings\User\Cookies\user@data3.perf.overture[1].txt
C:\Documents and Settings\User\Cookies\user@indextools[4].txt
C:\Documents and Settings\User\Cookies\user@yadro[3].txt
C:\Documents and Settings\User\Cookies\user@pamedia.com[3].txt
C:\Documents and Settings\User\Cookies\user@www.oddcast[2].txt
C:\Documents and Settings\User\Cookies\user@oddcast[1].txt
C:\Documents and Settings\User\Cookies\user@ientry[2].txt
C:\Documents and Settings\User\Cookies\user@Stats[3].txt
C:\Documents and Settings\User\Cookies\user@countercentral[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjlowgazaao.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjnyghcjieo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjlikmajigo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@ads.realtechnetwork[3].txt
C:\Documents and Settings\User\Cookies\user@adsense[4].txt
C:\Documents and Settings\User\Cookies\user@www.incentaclick[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjkyshdzchp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjlismd5wfo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@sensismediasmart.com[3].txt
C:\Documents and Settings\User\Cookies\user@flatmatefinders.com[1].txt
C:\Documents and Settings\User\Cookies\user@heavyhammerinc.122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@stat.dealtime[3].txt
C:\Documents and Settings\User\Cookies\user@stats.sitesuite[2].txt
C:\Documents and Settings\User\Cookies\user@ffxcam.cracker.com[1].txt
C:\Documents and Settings\User\Cookies\user@checkmystats.com[1].txt
C:\Documents and Settings\User\Cookies\user@hotitemfinder[2].txt
C:\Documents and Settings\User\Cookies\user@ads.cnn[1].txt
C:\Documents and Settings\User\Cookies\user@netronline.freestats[2].txt
C:\Documents and Settings\User\Cookies\user@ads.belointeractive[1].txt
C:\Documents and Settings\User\Cookies\user@counter.sparklit[2].txt
C:\Documents and Settings\User\Cookies\user@adsense[3].txt
C:\Documents and Settings\User\Cookies\user@m1.webstats4u[1].txt
C:\Documents and Settings\User\Cookies\user@surveys.spotsitemedia[1].txt
C:\Documents and Settings\User\Cookies\user@clicktoconvert[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6whliald5wep.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@www.clickxchange[2].txt
C:\Documents and Settings\User\Cookies\user@impressions.mediatracker.co[1].txt
C:\Documents and Settings\User\Cookies\user@c001.101webstats[1].txt
C:\Documents and Settings\User\Cookies\user@112.2o7[4].txt
C:\Documents and Settings\User\Cookies\user@data1.perf.overture[1].txt
C:\Documents and Settings\User\Cookies\user@www.ezytrack[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfmyopczeep.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@acvs.mediaonenetwork[1].txt
C:\Documents and Settings\User\Cookies\user@adtrackz[1].txt
C:\Documents and Settings\User\Cookies\user@112.2o7[6].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfkoqhcpmep.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@www.whatsclicking[2].txt
C:\Documents and Settings\User\Cookies\user@yourtrafficexplosion[1].txt
C:\Documents and Settings\User\Cookies\user@www.webtrafficvideos[2].txt
C:\Documents and Settings\User\Cookies\user@primequk.directtrack[2].txt
C:\Documents and Settings\User\Cookies\user@hotitemfinder[1].txt
C:\Documents and Settings\User\Cookies\user@acvs.mediaonenetwork[3].txt
C:\Documents and Settings\User\Cookies\user@www.statssheet[1].txt
C:\Documents and Settings\User\Cookies\user@www.ezytrack[4].txt
C:\Documents and Settings\User\Cookies\user@ientry[4].txt
C:\Documents and Settings\User\Cookies\user@traffic[1].txt
C:\Documents and Settings\User\Cookies\user@banner.eurogrand[2].txt
C:\Documents and Settings\User\Cookies\user@adv.webmd[1].txt
C:\Documents and Settings\User\Cookies\user@nextag[1].txt
C:\Documents and Settings\User\Cookies\user@www.hotitemfinder[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfkyaicpedo.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@adbrite[1].txt
C:\Documents and Settings\User\Cookies\user@www.firecrackerdays[3].txt
C:\Documents and Settings\User\Cookies\user@media.sensis.com[2].txt
C:\Documents and Settings\User\Cookies\user@stat.sunrobot[2].txt
C:\Documents and Settings\User\Cookies\user@gostats[3].txt
C:\Documents and Settings\User\Cookies\user@findloveandlight[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wak4qjazobo.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@freekeywords.wordtracker[1].txt
C:\Documents and Settings\User\Cookies\user@countercentral[2].txt
C:\Documents and Settings\User\Cookies\user@ez-tracks[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6whkoklazwdo.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@emailpromosexposed[1].txt
C:\Documents and Settings\User\Cookies\user@adsense[8].txt
C:\Documents and Settings\User\Cookies\user@indextools[6].txt
C:\Documents and Settings\User\Cookies\user@clickproduce[2].txt
C:\Documents and Settings\User\Cookies\user@www.w3counter[1].txt
C:\Documents and Settings\User\Cookies\user@adinterax[1].txt
C:\Documents and Settings\User\Cookies\user@indexstats[2].txt
C:\Documents and Settings\User\Cookies\user@bizrate[4].txt
C:\Documents and Settings\User\Cookies\user@www.ez-tracks[1].txt
C:\Documents and Settings\User\Cookies\user@jumps.ez-tracks[1].txt
C:\Documents and Settings\User\Cookies\user@eztracks.aavalue[1].txt
C:\Documents and Settings\User\Cookies\user@gostats[4].txt
C:\Documents and Settings\User\Cookies\user@track.webgains[1].txt
C:\Documents and Settings\User\Cookies\user@ffxcam.cracker.com[4].txt
C:\Documents and Settings\User\Cookies\user@serif.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@bs.serving-sys[2].txt
C:\Documents and Settings\User\Cookies\user@silo.thefind[1].txt
C:\Documents and Settings\User\Cookies\user@www.clickxchange[4].txt
C:\Documents and Settings\User\Cookies\user@lab88inc.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjmyqlazoho.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjmiwidzobo.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjkychc5ghp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjkywgcpikq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjlialdpcko.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjnyohcpakp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wgmiggdpofq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@www.clickbank[1].txt
C:\Documents and Settings\User\Cookies\user@ads.fairfax.com[1].txt
C:\Documents and Settings\User\Cookies\user@c1.zedo[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wflikidjecp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wflocpdpwao.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wgligkcjcbo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjnyekdpsbp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjkyqocjkeq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjloejc5kkp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@www.statssheet[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wgmigkdjklp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@ads.adbrite[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfkispcpwep.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@www.dealtime[1].txt
C:\Documents and Settings\User\Cookies\user@stampscom.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@ad.directanetworks[2].txt
C:\Documents and Settings\User\Cookies\user@adsense[10].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wal4uiczgep.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@cnetaustralia.122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@t0.counter43[2].txt
C:\Documents and Settings\User\Cookies\user@ientry[5].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfloeodzmlp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjny-1icpma.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@brightbuilders.122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@thefind[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfkieoczedo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@ads.associatedcontent[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjmionazwfp.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@findit.com[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjmyukcpogq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6whkiuidzsao.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfl4epczwcq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@adsense[11].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wbkococ5ogo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjliagc5ggo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@carvatures.freestats[2].txt
C:\Documents and Settings\User\Cookies\user@ads.mediamayhemcorp[2].txt
C:\Documents and Settings\User\Cookies\user@stat.onestat[1].txt
C:\Documents and Settings\User\Cookies\user@members.tripod[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfkoknc5sfo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjkoghdjaap.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@xiti[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfliuidzgkp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjkyehczgao.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6whkykndzelo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@adtrackz[3].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjmycncpcgo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@philips.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@clickduckebooks[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjlokgcjkbo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@tourismwesternaustralia.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfkigkczkdo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjlookdzeeq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjkyqjc5afo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@enhance[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjloapdpobq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjl4opajolo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjkosgczoep.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@microsoftwga.112.2o7[2].txt
C:\Documents and Settings\User\Cookies\user@gemoney.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@www.hotitemfinder[3].txt
C:\Documents and Settings\User\Cookies\user@sales.liveperson[3].txt
C:\Documents and Settings\User\Cookies\user@statsone[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjl4cmcjilo.stats.esomniture[2].txt

Owlman
2008-03-01, 01:29
C:\Documents and Settings\User\Cookies\user@clicks.aweber[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wblicjd5cgo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@www.clickxchange[5].txt
C:\Documents and Settings\User\Cookies\user@serif.112.2o7[2].txt
C:\Documents and Settings\User\Cookies\user@adopt.euroclick[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjkospdpwdo.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfl4upcpoeo.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6whkyqgajabo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfloohdzmlo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@infopia.112.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wgliqpczceo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@cracker.com[4].txt
C:\Documents and Settings\User\Cookies\user@dealtime[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6whloeldjceo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfkiupazocq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjnyaiajafp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6walocndjocq.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfk4chcpogo.stats.esomniture[3].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjnygicpslo.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjmiepc5cgo.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wgkykpczwkq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@oasc02.247realmedia[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjmyujajsho.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@ad.thewheelof[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjnyahajeko.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6whlyahcjgao.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfmispdpmhq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfliwocpclp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjliojcjkcp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjliehcpahp.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjl4kmdzmho.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjl4gjazcdo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjnywoczifp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjliegcjieo.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjkoolcjoho.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfk4skcjglq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfligmcpido.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@stats.sitesuite[3].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6walioocjsdp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@aotgroup.122.2o7[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6whkiqjcjsfp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@wholesalemarketer.122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@www.ezytrack[3].txt
C:\Documents and Settings\User\Cookies\user@clickshift[1].txt
C:\Documents and Settings\User\Cookies\user@expedia.gravitytrack[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfliklazmdp.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@bs.serving-sys[1].txt
C:\Documents and Settings\User\Cookies\user@www.precisioncounter[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6whmyshcpaeo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@stat.dealtime[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wgkyapc5klp.stats.esomniture[3].txt
C:\Documents and Settings\User\Cookies\user@www.ticketsnow[1].txt
C:\Documents and Settings\User\Cookies\user@adbrite[4].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfmisocjkfp.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6whkyuodjmeq.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@roiservice[5].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjloolazgkp.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjl4egajgbo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfliooczilo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wflosmajeeq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6whlycpc5acp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wgmiulcjmlq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wbk4opczmlo.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjmyciajmap.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfkikmc5sfp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfk4sncjkbo.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wgl4qldjmlo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjny-1jdped.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@ffxcam.cracker.com[5].txt
C:\Documents and Settings\User\Cookies\user@usatoday1.112.2o7[2].txt
C:\Documents and Settings\User\Cookies\user@ads.addesktop[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjk4wgc5mgo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@mediaonenetwork[5].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjloogcpagp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjmiqid5chp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfk4enczglp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfkoomcpsgp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@stats.campaignvision.com[2].txt
C:\Documents and Settings\User\Cookies\user@viator.122.2o7[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjk4sgcjsaq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@adrevenue[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfloqiajwfo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wglocmdzkgo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6waliunajglo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wgl4kjcjaho.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjmicgajmbp.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjlykpd5mcq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfmigiazmfp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@bizrate[5].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wgkicicpidp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wak4sicjsep.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wbkoggcjicq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjlyqic5iho.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjkosoc5kcp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfkoqgdjggo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6walychcpagp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wflocmajmdo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjkyajczmbq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjlyqoczwlo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@4.adbrite[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjmiglcjcgq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfmyejdpwbp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6whloghajokp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjlysidpsbq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjl4uidzigq.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wgkigjd5ido.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wckyghcpslo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wblykjdpico.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjl4eidjmkp.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6whkoslazmhq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfk4klczgko.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjmywmc5cco.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfmighcpgco.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfliskd5kgp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjk4ojd5iao.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wakowlczalp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@indextools[3].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfmiagcjkao.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjlyamczshq.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@advertstream[2].txt
C:\Documents and Settings\User\Cookies\user@112.2o7[5].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6whmywlajiko.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wflyundzsgp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfl4wgdzmao.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wblowkcjskp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@www.cibleclick[2].txt
C:\Documents and Settings\User\Cookies\user@ad.cibleclick[2].txt
C:\Documents and Settings\User\Cookies\user@media7.sitebrand[2].txt
C:\Documents and Settings\User\Cookies\user@incutrack.getprice.com[2].txt
C:\Documents and Settings\User\Cookies\user@tracker.mediatracker.co[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfl4epdjwfo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfliqiazekp.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wjmyqicpweo.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wamikld5ocp.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@acvs.mediaonenetwork[2].txt
C:\Documents and Settings\User\Cookies\user@media.sensis.com[4].txt
C:\Documents and Settings\User\Cookies\user@vhost.oddcast[5].txt
C:\Documents and Settings\User\Cookies\user@eas.apm.emediate[1].txt
C:\Documents and Settings\User\Cookies\user@www.eztrackz[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfkikmdzgkp.stats.esomniture[2].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfmiakajccp.stats.esomniture[3].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfk4oidjofo.stats.esomniture[1].txt
C:\Documents and Settings\User\Cookies\user@e-2dj6wfkysid5wco.stats.esomniture[2].txt
D:\WINDOWS\TEMP\Cookies\ian@ad2.pamedia.com[1].txt
D:\WINDOWS\Cookies\user@ads.optusnet.com[1].txt
D:\WINDOWS\Cookies\margo@addynamix[1].txt
D:\WINDOWS\Cookies\user@ad2.pamedia.com[1].txt
D:\WINDOWS\Cookies\user@windowsmedia[1].txt
D:\WINDOWS\Cookies\user@stats.klsoft[1].txt
D:\WINDOWS\Cookies\margo@ad.showbizz[1].txt
D:\WINDOWS\Cookies\margo@tribalfusion[1].txt
D:\WINDOWS\Cookies\margo@macromedia[1].txt
D:\WINDOWS\Cookies\margo@www.mediamazing[1].txt
D:\WINDOWS\Cookies\margo@ads.adsag[2].txt
D:\WINDOWS\Cookies\margo@exitexchange[1].txt
D:\WINDOWS\Cookies\margo@overture[1].txt
D:\WINDOWS\Cookies\margo@ad2.pamedia.com[1].txt
D:\WINDOWS\Cookies\margo@asm.roitrack[1].txt
D:\WINDOWS\Cookies\margo@windowsmedia[1].txt
D:\WINDOWS\Cookies\margo@zedo[1].txt
D:\WINDOWS\Cookies\margo@pathfinder[1].txt
D:\WINDOWS\Cookies\margo@www.popuptraffic[2].txt
D:\WINDOWS\Cookies\margo@livestats.mediaclay[1].txt
D:\WINDOWS\Cookies\margo@www.clickxchange[1].txt
D:\WINDOWS\Cookies\margo@tripod[1].txt
D:\WINDOWS\Cookies\margo@2o7[2].txt
D:\WINDOWS\Cookies\margo@ads19.hyperbanner[2].txt
D:\WINDOWS\Cookies\margo@overture[2].txt
D:\WINDOWS\Cookies\margo@stats.klsoft[1].txt
D:\WINDOWS\Cookies\margo@ad.sensismediasmart.com[1].txt
D:\WINDOWS\Cookies\margo@ad2.pamedia.com[2].txt
D:\WINDOWS\Cookies\margo@zedo[3].txt
D:\WINDOWS\Cookies\margo@windowsmedia[2].txt
D:\WINDOWS\Cookies\margo@www.clickxchange[3].txt
D:\WINDOWS\Cookies\anyuser@ad2.pamedia.com[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\user@ads.optusnet.com[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@addynamix[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@windowsmedia[3].txt
D:\WINDOWS\Profiles\Margo\Cookies\user@ad2.pamedia.com[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\user@windowsmedia[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\user@stats.klsoft[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ad.showbizz[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@tribalfusion[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@tribalfusion[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@macromedia[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.mediamazing[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ads.adsag[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@exitexchange[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@overture[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ad2.pamedia.com[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@asm.roitrack[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ad.sensismediasmart.com[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@windowsmedia[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@zedo[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@pathfinder[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.popuptraffic[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@livestats.mediaclay[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.clickxchange[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@tripod[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@2o7[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@bannerspace[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@2o7[3].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ads19.hyperbanner[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@overture[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@stats.klsoft[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ad.sensismediasmart.com[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ad2.pamedia.com[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@zedo[3].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@windowsmedia[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.clickxchange[3].txt
D:\WINDOWS\Profiles\Margo\Cookies\anyuser@ad2.pamedia.com[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@pro-market[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.popuptraffic[3].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@livestats.mediaclay[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.teensbymail[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@findwhat[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@windowsmedia[4].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@toplist[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@as1.falkag[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@stats.sitesuite[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.pinkfishmedia[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@2o7[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ad2.pamedia.com[3].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@maxserving[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@questionmarket[3].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@mediamgr.ugo[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@toplist[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ads.addynamix[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.popuptraffic[4].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@apmebf[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ad.adition[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@tribalfusion[4].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ad.adition[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@zedo[4].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.adultmatchmaker.com[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www1.paypopup[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@c2.gostats[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.findarticles[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@c2.gostats[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@windowsmedia[5].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@bannerserver.adpost[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@atwola[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@server.iad.liveperson[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@stat.onestat[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ad.sensismediasmart.com[4].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ad2.pamedia.com[4].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@2o7[4].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@rccl.bridgetrack[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@statcounter[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@questionmarket[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ads.pointroll[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.auspropertyfinders[2].txt

Owlman
2008-03-01, 01:29
D:\WINDOWS\Profiles\Margo\Cookies\margo@www8.paypopup[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@cracks[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ads.tripod.lycos.co[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@casalemedia[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www10.paypopup[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@cracker.com[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@atwola[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@xxxtoolbar[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ad.sensismediasmart.com[3].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@2o7[5].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.clickbusinesscards[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@revenue[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@trafficmp[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@zedo[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@tribalfusion[3].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.s-tracking[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@windowsmedia[6].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@bannertracker[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ads.addynamix[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@banners.incredigames[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@azjmp[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@clickagents[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ad2.pamedia.com[5].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@casalemedia[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@atdmt[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@2o7[7].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@perf.overture[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@realmedia[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@banner[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@adrevolver[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@dist.belnk[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@tripod[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@fastclick[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@revenue[3].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@paycounter[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.cyberneticmedia[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlowpd5wcoq6dj6x9ny-1seq-2-2.stats.esomniture[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlyehcpogqq2dj6x9ny-1seq-2-2.stats.esomniture[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@c2.gostats[4].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@metareward[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.clickheretofind[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@vhost.oddcast[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@focalex[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@image.masterstats[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@z1.adserver[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@stats1.webmetrics[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@serving-sys[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.popuptraffic[5].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@bizrate[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@ads.pointroll[3].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@stats.esomniture[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@stats.sitesuite[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkokhc5wbpg2dj6x9ny-1seq-2-2.stats.esomniture[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@statcounter[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.ezytrack[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@apmebf[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@as-us.falkag[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.findyoga.com[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@112.2o7[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@doubleclick[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@oddcast[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@rightmedia[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@adtech[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@banners.avatarsearch[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@banner.casinofortune[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@server.iad.liveperson[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@overture[4].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@sensismediasmart.com[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@pamedia.com[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@bs.serving-sys[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@mediaplex[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@tribalfusion[5].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@zedo[6].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@burstnet[1].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@tradedoubler[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@www.burstbeacon[2].txt
D:\WINDOWS\Profiles\Margo\Cookies\margo@brain.roistats[1].txt

Rootkit.Unclassified/SysDamp-Traces
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Reserved
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Reserved

Owlman
2008-03-01, 01:36
Hi Steam,

Just a thought. My wife thinks that Kaspersky is not working properly, as it appears it did not stop or disinfect anything, even though there is definitely an infection there. Is it possible Kaspersky could have been compromised? If so, can the Kaspersky scan be relied on? Should I be reinstalling Kaspersky from scratch?

Thanks,
Ian

steamwiz
2008-03-03, 21:10
HI

Sorry for the late reply, been away for a few days ...

First fix this in hijackthis :-

O23 - Service: NT LM Security Support Provider NtLmSspsrservice (NtLmSspsrservice) - Unknown owner - C:\WINDOWS\system32\lr87.exe (file missing)

All SUPERAntiSpyware found were tracking cookies ...part of everyday surfing, but they want deleting when found...

-
Kas on-line scan was clean ...

KASPERSKY ONLINE SCANNER REPORT

Number of viruses found 0
Number of infected objects 0
Number of suspicious objects 0

So what is your installed version of KASPERSKY finding ? which you are concerned about ?

& anything else you are concerned about ?

steam

Owlman
2008-03-09, 23:19
Hello Steam,

Apologies, been very busy at work, haven't had time to scratch my derriere, never mind attend to 'er ladyship's computer.

It seems to be running okay now, other than one small quirk. Every time she does a Google search, Kaspersky pops up a dialog saying something like "modified riskware, hidden data sending". It seems to be IE that's been modified (if the message is accurate). The popup disappears within a few seconds, and all seems well, but it's a bit of a concern that it is detecting something, especially sending hidden data.

Any clues?

Cheers,
Ian

steamwiz
2008-03-17, 22:24
Hi

Sounds like the Google Toolbar checking for updates ... or it could be when you go to a site you are allready logged into, for you to be instantly logged in, your login details are kept in a cookie on your computer, the site checks your cookie which in effect sends your user name & password and logs you in, this could be interpretted as "sending hidden data" as it does this in the background without asking you first.

But I can't rule out 100% that is is not malware doing it ...

Is this the warning you are getting ?

http://forum.kaspersky.com/index.php?act=attach&type=post&id=29519

Please do this :-

In KIS go to > Privacy Control > Configure > Protection of Confidential Data and change the action to prompt for sending confidential data.

You should then het this popup :-

http://images.kaspersky.com/en/vlpub/0706_privacy_control_graph6_en.png

In your case the running process is this ?

C:\Program Files\Internet Explorer\iexplore.exe

When you get the second popup "the yellow one" click the "details at the top & post what ot says ...

steam