Jump to content


Photo

Popups


  • This topic is locked This topic is locked
27 replies to this topic

#1 Joe_Smith

Joe_Smith

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 22 April 2007 - 08:13 PM

About 3 weeks ago I started seeing a ton of popups that had nothing to do with the sites I was seeing. I ran Spybot Search and destroy and the only thing it wasn't able to remove was something called Command Service. I booted up in Safemode and it did appear that I was able to remove it. However, I'm still receiving the same amount (a ton) of popups that I did before.

When I run Spybot now, it usually picks up entries such as Advertising.com, Avenue A, Inc., DirectTrack and about 5 others. Although Spybot informs me that it has removed them, I still get the popups and when I run Spybot again those items reappear.

I also noticed that on certain web pages I am viewing that numerous words are underlined (hyperlinked), but they all appear to redirect me to the same site (1800buyer or something like that). Meaning that whatever I have is also imbedding fake links on the pages I'm seeing.

Any help would be GREATLY appreciated. The popups are driving me insane.

Please read our Forum FAQ in order to find out what info we need (HijackThislog) so we can help you.

Edited by miekiemoes, 23 April 2007 - 03:56 AM.


#2 Joe_Smith

Joe_Smith

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 23 April 2007 - 08:07 PM

My HijackThis log and AVG Anti-Spyware report are below. Thanks!


Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:11:17 PM, on 4/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\aol\ACS\AOLacsd.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\{A0E9FA26-095A-1033-0507-030416030001}\Update.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Ipwindows\ipwins.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\pasystem\pasystem.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Documents and Settings\Richard Wiegand\Desktop\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://localhost/:80
O2 - BHO: Web Assistant - {04DCB78C-AB45-83AD-A86A-6DFB90277939} - C:\Program Files\psquery\psquery.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {45A4902E-4479-4EAE-A186-8D0F7E4C78DE} - C:\Program Files\Starware316\bin\Starware316.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: Starware316 - {9FB3908C-6565-4CB0-95F8-E9F85258723C} - C:\Program Files\Starware316\bin\Starware316.dll (file missing)
O3 - Toolbar: (no name) - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [{A0E9FA26-095A-1033-0507-030416030001}] "C:\Program Files\Common Files\{A0E9FA26-095A-1033-0507-030416030001}\Update.exe" te-110-12-0000213
O4 - HKLM\..\Run: [{A0E9FA26-0959-1033-0507-030416030001}] "C:\Program Files\Common Files\{A0E9FA26-0959-1033-0507-030416030001}\Update.exe" te-110-12-0000213
O4 - HKLM\..\Run: [Lexmark 4200 Series] "C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark 4200 Series\Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [SFP] C:\Program Files\Common Files\Verizon Online\SFP\vzSFPWin.EXE /s
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [zqzu] C:\PROGRA~1\COMMON~1\zqzu\zqzum.exe
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PaSystem] "C:\Program Files\pasystem\pasystem.exe"
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.clarkcolo...larkActivia.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\aol\ACS\AOLacsd.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 10061 bytes




---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 9:04:50 PM 4/23/2007

+ Scan result:



C:\Program Files\psquery\psquery.sys -> Adware.Agent : No action taken.
C:\Program Files\psquery\psquery.exe -> Adware.CASClient : No action taken.
C:\Program Files\Screensavers.com\SSSInst\bin\SSSInst.dll -> Adware.Comet : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001029.dll -> Adware.Comet : No action taken.
C:\WINDOWS\UmljaGFyZCBXaWVnYW5k\asappsrv.dll -> Adware.CommAd : No action taken.
C:\WINDOWS\UmljaGFyZCBXaWVnYW5k\command.exe -> Adware.CommAd : No action taken.
C:\Program Files\Common Files\{30E9FA26-095A-1033-0507-030416030001}\UnInstall.exe -> Adware.IWantSearch : No action taken.
C:\RECYCLER\S-1-5-21-3293177330-830341180-1122393778-1006\Dc523\ipwins.dll -> Adware.Maxifiles : No action taken.
C:\RECYCLER\S-1-5-21-3293177330-830341180-1122393778-1006\Dc523\ipwins.exe -> Adware.Maxifiles : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temp\ze.exe -> Adware.MaxSearch : No action taken.
C:\Program Files\Common Files\{30E9FA26-095A-1033-0507-030416030001}\Bar888.dll -> Adware.MaxSearch : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temp\b116.exe -> Adware.Softomate : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temp\b122.exe -> Adware.Softomate : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temp\b134.exe -> Adware.Softomate : No action taken.
C:\Program Files\Common Files\{A0E9FA26-0959-1033-0507-030416030001}\Update.exe -> Adware.Softomate : No action taken.
C:\Program Files\Common Files\{A0E9FA26-0959-1033-0507-030416030001}\system.dll -> Adware.Softomate : No action taken.
C:\Program Files\Common Files\{A0E9FA26-095A-1033-0507-030416030001}\Update.exe -> Adware.Softomate : No action taken.
C:\Program Files\Common Files\{A0E9FA26-095A-1033-0507-030416030001}\system.dll -> Adware.Softomate : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001028.dll -> Adware.TargetServer : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temp\b129.exe -> Adware.WebHancer : No action taken.
C:\WINDOWS\SYSTEM32\svchosts.exe -> Downloader.Agent.bca : No action taken.
C:\Documents and Settings\Kyle\Local Settings\Temporary Internet Files\Content.IE5\4BSPEZOF\index[1].htm -> Downloader.Psyme.di : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temp\b128.exe -> Downloader.PurityScan.eh : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temporary Internet Files\Content.IE5\VR84XMWV\128[1].net -> Downloader.PurityScan.eh : No action taken.
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe -> Downloader.PurityScan.eh : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temp\b104.exe -> Downloader.Small.buy : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temp\metasploit.exe -> Downloader.Tiny.fy : No action taken.
C:\Program Files\Common Files\zqzu\zqzup.exe -> Downloader.TSUpdate.f : No action taken.
C:\Program Files\Common Files\zqzu\zqzud\vocabulary -> Downloader.TSUpdate.j : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001027.exe -> Downloader.TSUpdate.l : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001026.exe -> Downloader.TSUpdate.n : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temp\b103.exe -> Downloader.TSUpdate.o : No action taken.
C:\Program Files\Common Files\zqzu\zqzul.exe -> Downloader.TSUpdate.r : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temp\qr.exe -> Dropper.VB.nn : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temporary Internet Files\Content.IE5\6GVDG060\hh[1].htm -> Not-A-Virus.Exploit.JS.ADODB.Stream.t : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temporary Internet Files\Content.IE5\0GHYXUZZ\portal[1].htm -> Not-A-Virus.Exploit.MhtRedir : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temporary Internet Files\Content.IE5\0GHYXUZZ\portal[2].htm -> Not-A-Virus.Exploit.MhtRedir : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temporary Internet Files\Content.IE5\0GHYXUZZ\portal[6].htm -> Not-A-Virus.Exploit.MhtRedir : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temporary Internet Files\Content.IE5\0GHYXUZZ\portal[7].htm -> Not-A-Virus.Exploit.MhtRedir : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temporary Internet Files\Content.IE5\2JOWRWA2\portal[10].htm -> Not-A-Virus.Exploit.MhtRedir : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temporary Internet Files\Content.IE5\2JOWRWA2\portal[11].htm -> Not-A-Virus.Exploit.MhtRedir : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temporary Internet Files\Content.IE5\2JOWRWA2\portal[1].htm -> Not-A-Virus.Exploit.MhtRedir : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temporary Internet Files\Content.IE5\2JOWRWA2\portal[4].htm -> Not-A-Virus.Exploit.MhtRedir : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temporary Internet Files\Content.IE5\2JOWRWA2\portal[9].htm -> Not-A-Virus.Exploit.MhtRedir : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temporary Internet Files\Content.IE5\6GVDG060\portal[3].htm -> Not-A-Virus.Exploit.MhtRedir : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temporary Internet Files\Content.IE5\6GVDG060\portal[6].htm -> Not-A-Virus.Exploit.MhtRedir : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temporary Internet Files\Content.IE5\6GVDG060\portal[7].htm -> Not-A-Virus.Exploit.MhtRedir : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temporary Internet Files\Content.IE5\VR84XMWV\portal[2].htm -> Not-A-Virus.Exploit.MhtRedir : No action taken.
:mozilla.359:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.14:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\i5a4h0v8.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.17:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\i5a4h0v8.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.17:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.302:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.303:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.304:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.320:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.385:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.62:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.66:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.691:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.692:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.693:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.694:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.695:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.696:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.697:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.698:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.699:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.6:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.700:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.701:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.702:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.703:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.704:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.705:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.706:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.707:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.708:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.709:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.710:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.720:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.78:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.7:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.8:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Kelsey\Cookies\kelsey@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Kyle\Cookies\kyle@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Kyle\Cookies\kyle@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\LocalService\Cookies\system@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\LocalService\Cookies\system@babyuniverse.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\LocalService\Cookies\system@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@entrepreneur.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@franchiseservices.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@ldproducts.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@shopping.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@usatoday1.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temp\Cookies\richard wiegand@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@aavalue[2].txt -> TrackingCookie.Aavalue : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@arn.aavalue[1].txt -> TrackingCookie.Aavalue : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@getmusicfree.aavalue[1].txt -> TrackingCookie.Aavalue : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@adbrite[1].txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.415:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Addynamix : No action taken.
:mozilla.71:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adobe : No action taken.
:mozilla.72:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adobe : No action taken.
C:\Documents and Settings\Kyle\Cookies\kyle@www.adobe[1].txt -> TrackingCookie.Adobe : No action taken.
:mozilla.391:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.392:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.393:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.394:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.785:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\LocalService\Cookies\system@adrevolver[2].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@adrevolver[2].txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.604:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adserver : No action taken.
:mozilla.605:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adserver : No action taken.
:mozilla.606:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adserver : No action taken.
:mozilla.228:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.229:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.176:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.177:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.178:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.179:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.498:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.499:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.500:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Kyle\Cookies\kyle@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\LocalService\Cookies\system@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
:mozilla.360:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.8:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\i5a4h0v8.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Kyle\Cookies\kyle@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\LocalService\Cookies\system@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temp\Cookies\richard wiegand@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.249:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Bfast : No action taken.
:mozilla.250:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Bfast : No action taken.
C:\Documents and Settings\Kyle\Cookies\kyle@bfast[2].txt -> TrackingCookie.Bfast : No action taken.
C:\Documents and Settings\LocalService\Cookies\system@bfast[1].txt -> TrackingCookie.Bfast : No action taken.
:mozilla.827:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken.
:mozilla.810:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Bridgetrack : No action taken.
:mozilla.811:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Bridgetrack : No action taken.
:mozilla.455:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Burstbeacon : No action taken.
:mozilla.290:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@burstnet[2].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@www.burstnet[1].txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.135:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.136:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.137:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\Kyle\Cookies\kyle@casalemedia[2].txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@casalemedia[1].txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.656:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Centrport : No action taken.
C:\Documents and Settings\LocalService\Cookies\system@clickbank[1].txt -> TrackingCookie.Clickbank : No action taken.
:mozilla.670:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Com : No action taken.
:mozilla.671:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@connextra[3].txt -> TrackingCookie.Connextra : No action taken.
:mozilla.522:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Coremetrics : No action taken.
:mozilla.580:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Coremetrics : No action taken.
C:\Documents and Settings\LocalService\Cookies\system@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : No action taken.
C:\Documents and Settings\Kyle\Cookies\kyle@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : No action taken.
C:\Documents and Settings\LocalService\Cookies\system@dealtime[1].txt -> TrackingCookie.Dealtime : No action taken.
C:\Documents and Settings\LocalService\Cookies\system@stat.dealtime[2].txt -> TrackingCookie.Dealtime : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@dealtime[1].txt -> TrackingCookie.Dealtime : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@stat.dealtime[1].txt -> TrackingCookie.Dealtime : No action taken.
:mozilla.6:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\i5a4h0v8.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.824:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Kyle\Cookies\kyle@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\LocalService\Cookies\system@doubleclick[2].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@doubleclick[2].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temp\Cookies\richard wiegand@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\LocalService\Cookies\system@enhance[1].txt -> TrackingCookie.Enhance : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@enhance[1].txt -> TrackingCookie.Enhance : No action taken.
:mozilla.163:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.16:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.234:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.238:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.253:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.321:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.413:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.523:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.554:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.562:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.610:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.784:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.791:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.534:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.535:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.536:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.563:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.564:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.565:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.566:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.567:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.825:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.826:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\LocalService\Cookies\system@fastclick[2].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@fastclick[2].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@media.fastclick[1].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Richard Wiegand\Local Settings\Temp\Cookies\richard wiegand@fastclick[1].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\LocalService\Cookies\system@findwhat[2].txt -> TrackingCookie.Findwhat : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@findwhat[1].txt -> TrackingCookie.Findwhat : No action taken.
C:\Documents and Settings\Kyle\Cookies\kyle@fortunecity[1].txt -> TrackingCookie.Fortunecity : No action taken.
:mozilla.734:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.735:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.736:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.737:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.738:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.739:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.740:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.741:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.742:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.743:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.744:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.745:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.746:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.747:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.748:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.96:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.149:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.150:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.180:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.181:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.182:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.183:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.230:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.231:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.232:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.307:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.310:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.311:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.31:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.323:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.324:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.325:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.364:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.511:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.512:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.553:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.577:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.578:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.633:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.76:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.77:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.788:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.789:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.790:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.800:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.9:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\LocalService\Cookies\system@ehg-babyuniverse.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\LocalService\Cookies\system@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@ehg-maniatv.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.792:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitslink : No action taken.
:mozilla.793:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitslink : No action taken.
:mozilla.794:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitslink : No action taken.
:mozilla.795:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitslink : No action taken.
:mozilla.73:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hypertracker : No action taken.
:mozilla.318:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Imrworldwide : No action taken.
:mozilla.319:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Imrworldwide : No action taken.
:mozilla.82:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Information : No action taken.
C:\Documents and Settings\LocalService\Cookies\system@searchportal.information[1].txt -> TrackingCookie.Information : No action taken.
:mozilla.101:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.102:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.103:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.104:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.105:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.106:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles�

#3 SWI Support Robot

SWI Support Robot

    Helper robot

  • SWI Bot
  • PipPipPipPipPip
  • 23,523 posts

Posted 25 April 2007 - 06:30 AM

Welcome to SWI. We apologize for the delay; our helpers have been very busy.
If you have not received help after 3 days, please CLICK HERE, and post a link to your log and the date it was originally posted.

Thank you for your patience.

[this is an automated reply]
This is an automated message. It does not count as help.

#4 teacup61

teacup61

    RIP

  • Emeritus
  • PipPipPipPipPip
  • 4,064 posts

Posted 25 April 2007 - 02:21 PM

Hello Joe_Smith,

Welcome to SWI :)

Sorry for the delay.

If you still need help, please post a new HijackThis log and I'll be happy to look at it.

Thanks,
tea
My help is free, but if you wish to help keep these forums running please consider a donation, see this topic for details.

Posted Image
Posted Image

#5 Joe_Smith

Joe_Smith

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 25 April 2007 - 07:05 PM

Thanks Tea, my latest HijackThis log is below...

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:03:59 PM, on 4/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\aol\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Ipwindows\ipwins.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\pasystem\pasystem.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Richard Wiegand\Desktop\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://localhost/:80
O2 - BHO: Web Assistant - {04DCB78C-AB45-83AD-A86A-6DFB90277939} - C:\Program Files\psquery\psquery.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {45A4902E-4479-4EAE-A186-8D0F7E4C78DE} - C:\Program Files\Starware316\bin\Starware316.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: Starware316 - {9FB3908C-6565-4CB0-95F8-E9F85258723C} - C:\Program Files\Starware316\bin\Starware316.dll (file missing)
O3 - Toolbar: (no name) - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [{A0E9FA26-095A-1033-0507-030416030001}] "C:\Program Files\Common Files\{A0E9FA26-095A-1033-0507-030416030001}\Update.exe" te-110-12-0000213
O4 - HKLM\..\Run: [{A0E9FA26-0959-1033-0507-030416030001}] "C:\Program Files\Common Files\{A0E9FA26-0959-1033-0507-030416030001}\Update.exe" te-110-12-0000213
O4 - HKLM\..\Run: [Lexmark 4200 Series] "C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark 4200 Series\Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [SFP] C:\Program Files\Common Files\Verizon Online\SFP\vzSFPWin.EXE /s
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [zqzu] C:\PROGRA~1\COMMON~1\zqzu\zqzum.exe
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PaSystem] "C:\Program Files\pasystem\pasystem.exe"
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.clarkcolo...larkActivia.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\aol\ACS\AOLacsd.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 9782 bytes

#6 teacup61

teacup61

    RIP

  • Emeritus
  • PipPipPipPipPip
  • 4,064 posts

Posted 25 April 2007 - 07:16 PM

Hello,

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Post that log in your next reply please, along with a new HijackThis log.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall.

Thanks,
tea
My help is free, but if you wish to help keep these forums running please consider a donation, see this topic for details.

Posted Image
Posted Image

#7 Joe_Smith

Joe_Smith

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 26 April 2007 - 06:22 PM

Sure, the ComboFix and HijackThis logs are below. Thanks!


"Richard Wiegand" - 07-04-26 18:42:16 Service Pack 2
ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\Richard Wiegand\Desktop\"


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\63246057.exe
C:\Program Files\ipwindows\ipwins.dll
C:\Program Files\ipwindows\ipwins.exe
C:\Program Files\ipwindows\UnInstall.exe
C:\Program Files\screensavers.com\SSSInst\bin\iebyterange.xml
C:\Program Files\screensavers.com\SSSInst\bin\iebyterange.xml.backup
C:\Program Files\screensavers.com\SSSInst\bin\SSSInst.dll
C:\Program Files\screensavers.com\SSSInst\bin\SSSUninst.exe
C:\Program Files\Common Files\{30E9F~1\Bar888.dll
C:\Program Files\Common Files\{30E9F~1\UnInstall.exe
C:\Program Files\Common Files\{A0E9F~2\system.dll
C:\Program Files\Common Files\{A0E9F~2\Update.exe
C:\Program Files\Common Files\{A0E9F~1\system.dll
C:\Program Files\Common Files\{A0E9F~1\Update.exe
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\svchosts.exe
C:\WINDOWS\system32\tsuninst.exe
C:\WINDOWS\system32\unsvchosts.lzma
C:\WINDOWS\system32\wnsapitr.exe
C:\Program Files\ipwindows
C:\Program Files\screensavers.com
C:\Program Files\Common Files\{30E9F~1
C:\Program Files\Common Files\{A0E9F~2
C:\Program Files\Common Files\{A0E9F~1
C:\WINDOWS\system32\drivers\core.sys
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\C\Program Files\FNTS~1


((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\core
-------\Iprip
-------\LEGACY_CMDSERVICE
-------\LEGACY_COM+_MESSAGES
-------\LEGACY_CORE
-------\LEGACY_IPRIP
-------\LEGACY_NETWORK_MONITOR


((((((((((((((((((((((((((((((( Files Created from 2007-03-26 to 2007-04-26 ))))))))))))))))))))))))))))))))))


2007-04-23 19:54 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-04-21 16:18 <DIR> d-------- C:\Temp\tn3
2007-04-21 08:01 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\4200Series
2007-04-21 08:00 <DIR> d-------- C:\Program Files\ABBYY FineReader 5.0 Sprint
2007-04-21 07:55 <DIR> d-------- C:\Program Files\Lexmark 4200 Series
2007-04-17 20:39 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-04-17 20:39 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Real
2007-04-14 08:38 <DIR> d-------- C:\Program Files\pasystem
2007-04-10 21:47 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-04-10 21:36 <DIR> d-------- C:\WINDOWS\Prefetch
2007-04-10 21:25 221,184 --a------ C:\WINDOWS\SYSTEM32\wmpns.dll
2007-04-10 21:21 <DIR> d-------- C:\WINDOWS\peernet
2007-04-10 21:20 <DIR> d-------- C:\WINDOWS\provisioning
2007-04-10 21:13 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2007-04-10 20:56 <DIR> d-------- C:\WINDOWS\EHome
2007-04-10 10:42 <DIR> d-------- C:\Program Files\DellSupport
2007-04-04 20:03 <DIR> d-------- C:\DOCUME~1\Kyle\APPLIC~1\Google
2007-04-04 20:03 <DIR> d-------- C:\DOCUME~1\Kyle\APPLIC~1\AOL
2007-04-04 20:03 <DIR> d-------- C:\DOCUME~1\Kyle\APPLIC~1\4200Series
2007-04-01 19:55 <DIR> d-------- C:\Program Files\3DGroove
2007-03-28 20:29 <DIR> d-------- C:\Program Files\psquery


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-04-21 08:03 -------- d--h----- C:\Program Files\installshield installation information
2007-04-21 07:18 76408 --a------ C:\DOCUME~1\RICHAR~1\APPLIC~1\gdipfontcachev1.dat
2007-04-10 22:36 -------- d-------- C:\Program Files\messenger
2007-04-10 21:21 -------- d-------- C:\Program Files\movie maker
2007-04-10 14:44 -------- d--h----- C:\DOCUME~1\RICHAR~1\APPLIC~1\gtek
2007-03-25 12:38 -------- d-------- C:\Program Files\google
2007-03-25 10:11 -------- d-------- C:\DOCUME~1\RICHAR~1\APPLIC~1\google
2007-03-24 10:10 -------- d-------- C:\Program Files\virtools
2007-03-17 10:37 -------- d-------- C:\Program Files\pure networks
2007-03-17 09:43 292864 --a------ C:\WINDOWS\SYSTEM32\winsrv.dll
2007-03-09 19:42 -------- d-------- C:\Program Files\starware316
2007-03-08 11:36 577536 --a------ C:\WINDOWS\SYSTEM32\user32.dll
2007-03-08 11:36 40960 --a------ C:\WINDOWS\SYSTEM32\mf3216.dll
2007-03-08 11:36 281600 --a------ C:\WINDOWS\SYSTEM32\gdi32.dll
2007-03-08 09:47 1843584 --a------ C:\WINDOWS\SYSTEM32\win32k.sys
2007-02-05 16:17 185344 --a------ C:\WINDOWS\SYSTEM32\upnphost.dll
2007-01-28 12:27 2900 --a------ C:\WINDOWS\mozver.dat


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{04DCB78C-AB45-83AD-A86A-6DFB90277939} C:\Program Files\psquery\psquery.dll
{45A4902E-4479-4EAE-A186-8D0F7E4C78DE} C:\Program Files\Starware316\bin\Starware316.dll [x]
{53707962-6F74-2D53-2644-206D7942484F} C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
{AA58ED58-01DD-4d91-8333-CF10577473F7} c:\program files\google\googletoolbar2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"MMTray"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mm_tray.exe"
"MCAgentExe"="C:\\Program Files\\McAfee.com\\Agent\\mcagent.exe"
"MCUpdateExe"="C:\\PROGRA~1\\McAfee.com\\Agent\\McUpdate.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"AdaptecDirectCD"="\"C:\\Program Files\\Roxio\\Easy CD Creator 5\\DirectCD\\DirectCD.exe\""
"VirusScan Online"="c:\\PROGRA~1\\mcafee.com\\vso\\mcvsshld.exe"
"Motive SmartBridge"="C:\\PROGRA~1\\VERIZO~1\\SUPPOR~1\\SMARTB~1\\MotiveSB.exe"
"AOLDialer"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"
"AOL Spyware Protection"="\"C:\\PROGRA~1\\COMMON~1\\aol\\AOLSPY~1\\AOLSP Scheduler.exe\""
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_02\\bin\\jusched.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Lexmark 4200 Series"="\"C:\\Program Files\\Lexmark 4200 Series\\lxbmbmgr.exe\""
"FaxCenterServer4_in_1"="\"C:\\Program Files\\Lexmark 4200 Series\\Fax\\fm3032.exe\" /s"
@=""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"DellSupport"="\"C:\\Program Files\\DellSupport\\DSAgnt.exe\" /startup"
"SFP"="C:\\Program Files\\Common Files\\Verizon Online\\SFP\\vzSFPWin.EXE /s"
"Aim6"="\"C:\\Program Files\\AIM6\\aim6.exe\" /d locale=en-US ee://aol/imApp"
"zqzu"="C:\\PROGRA~1\\COMMON~1\\zqzu\\zqzum.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"PaSystem"="\"C:\\Program Files\\pasystem\\pasystem.exe\""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{04DCB78C-AB45-83AD-A86A-6DFB90277939}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SFP]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="vzSFPWin"
"hkey"="HKCU"
"command"="C:\\Program Files\\Common Files\\Verizon Online\\SFP\\vzSFPWin.EXE /s"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_PSQUERY


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\McAfee.com Update Check (DJT1S331-Kelsey).job
C:\WINDOWS\tasks\McAfee.com Update Check (DJT1S331-Kyle).job
C:\WINDOWS\tasks\McAfee.com Update Check (DJT1S331-Owner).job
C:\WINDOWS\tasks\McAfee.com Update Check (DJT1S331-Richard Wiegand).job

********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-04-26 18:50:02
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

? [2028]

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...


scan completed successfully
hidden processes: 1
hidden services: 0
hidden files: 0


********************************************************************

Completion time: 07-04-26 18:52:19 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 07-04-26 18:52




Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 7:10:48 PM, on 4/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\aol\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\pasystem\pasystem.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Richard Wiegand\Desktop\HiJackThis_v2.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://localhost/:80
O2 - BHO: Web Assistant - {04DCB78C-AB45-83AD-A86A-6DFB90277939} - C:\Program Files\psquery\psquery.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {45A4902E-4479-4EAE-A186-8D0F7E4C78DE} - C:\Program Files\Starware316\bin\Starware316.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: Starware316 - {9FB3908C-6565-4CB0-95F8-E9F85258723C} - C:\Program Files\Starware316\bin\Starware316.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark 4200 Series] "C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark 4200 Series\Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [SFP] C:\Program Files\Common Files\Verizon Online\SFP\vzSFPWin.EXE /s
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [zqzu] C:\PROGRA~1\COMMON~1\zqzu\zqzum.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PaSystem] "C:\Program Files\pasystem\pasystem.exe"
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.clarkcolo...larkActivia.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\aol\ACS\AOLacsd.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 8925 bytes

#8 teacup61

teacup61

    RIP

  • Emeritus
  • PipPipPipPipPip
  • 4,064 posts

Posted 26 April 2007 - 10:19 PM

Hello,

Do you know what this is? C:\Program Files\pasystem\pasystem.exe

If not, please go to VirusTotal and submit the file for a scan and post the results in your next reply.

I see you already have AVG AntiSpyware. Please make sure it's fully updated.

Please reboot your computer into Safe Mode. To boot into Safe Mode, please restart your computer. Tap F8 before Windows loads. Select Safe Mode on the screen that appears.

Please run HijackThis! and click "Scan." Place checks next to the following entries, if present:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Web Assistant - {04DCB78C-AB45-83AD-A86A-6DFB90277939} - C:\Program Files\psquery\psquery.dll
O2 - BHO: (no name) - {45A4902E-4479-4EAE-A186-8D0F7E4C78DE} - C:\Program Files\Starware316\bin\Starware316.dll (file missing)
O3 - Toolbar: Starware316 - {9FB3908C-6565-4CB0-95F8-E9F85258723C} - C:\Program Files\Starware316\bin\Starware316.dll (file missing)
O4 - HKCU\..\Run: [zqzu] C:\PROGRA~1\COMMON~1\zqzu\zqzum.exe


Close all browsers and other windows except for HijackThis!, and click "Fix checked".

Delete the following folders, if present:

C:\PROGRA~1\COMMON~1\zqzu
C:\Program Files\psquery
  • In Safe Mode, load AVG Anti-Spyware and click on the Scanner tab at the top and then click on Complete System Scan. This scan can take quite a while to run, so be prepared.
  • AVG Anti-Spyware will list any infections found on the left hand side. When the scan has finished, it will automatically set the recommended action. Click the Apply all actions button. AVG Anti-Spyware will display "All actions have been applied" on the right hand side.
  • Click on "Save Report", then "Save Report As". This will create a text file. Make sure you know where to find this file again (like on the Desktop).
  • Restart back into Normal Mode.
In your reply, please post the report from AVG, the report from VirusTotal, and a new HijackThis log. Please also let me know how your computer is running. :)

Thanks,
tea
My help is free, but if you wish to help keep these forums running please consider a donation, see this topic for details.

Posted Image
Posted Image

#9 Joe_Smith

Joe_Smith

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 27 April 2007 - 10:04 PM

Thanks for the information Tea. I was not famailiar with the pasystem.exe so I pasted the VirusTotal scan below.

One thing I was not able to do was delete the psquery file. When I attempted to do so, it tells me that "Access is denied." It appeared the file was set as read-only, so I attempted to change the value but was not successful (fyi - it allowed me to remove the read-only flag, but it always seemed to revert back. I did delete a few of the files within the folder, but I couldnt delete all of them.

When I ran AVG, it listed all of the infections, but the recommendation for each one was "Ignore Once." I did not change the value, so nothing was ever removed (let me know if I should change the Ignore Once value.

I have included the AVG and HijackThis log below as well. Thus far, it looks like I'm no longer receiving the popups!



Complete scanning result of "pasystem.exe", received in VirusTotal at 04.28.2007, 04:34:06 (CET).

Antivirus Version Update Result
AhnLab-V3 2007.4.28.0 04.27.2007 no virus found
AntiVir 7.4.0.15 04.27.2007 no virus found
Authentium 4.93.8 04.27.2007 no virus found
Avast 4.7.981.0 04.26.2007 no virus found
AVG 7.5.0.464 04.26.2007 no virus found
BitDefender 7.2 04.28.2007 no virus found
CAT-QuickHeal 9.00 04.27.2007 no virus found
ClamAV devel-20070416 04.27.2007 no virus found
DrWeb 4.33 04.27.2007 no virus found
eSafe 7.0.15.0 04.27.2007 no virus found
eTrust-Vet 30.7.3601 04.27.2007 no virus found
Ewido 4.0 04.27.2007 no virus found
FileAdvisor 1 04.28.2007 no virus found
Fortinet 2.85.0.0 04.28.2007 no virus found
F-Prot 4.3.2.48 04.27.2007 no virus found
F-Secure 6.70.13030.0 04.28.2007 no virus found
Ikarus T3.1.1.5 04.27.2007 no virus found
Kaspersky 4.0.2.24 04.28.2007 no virus found
McAfee 5019 04.27.2007 no virus found
Microsoft 1.2405 04.28.2007 no virus found
NOD32v2 2225 04.27.2007 no virus found
Norman 5.80.02 04.27.2007 no virus found
Panda 9.0.0.4 04.28.2007 Suspicious file
Prevx1 V2 04.28.2007 no virus found
Sophos 4.16.0 04.23.2007 no virus found
Sunbelt 2.2.907.0 04.19.2007 no virus found
Symantec 10 04.28.2007 no virus found
TheHacker 6.1.6.095 04.15.2007 no virus found
VBA32 3.11.4 04.28.2007 no virus found
VirusBuster 4.3.7:9 04.27.2007 no virus found
Webwasher-Gateway 6.0.1 04.28.2007 no virus found


Aditional Information
File size: 184320 bytes
MD5: 5f01f268942f47809d33bdb82e6ddce3
SHA1: b3e8b791b0edbbba5a84e8a3834d2d18f1e75ba9




---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 10:27:35 PM 4/27/2007

+ Scan result:



C:\RECYCLER\S-1-5-21-3293177330-830341180-1122393778-500\Dc1.sys -> Adware.Agent : Ignored.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0001653.sys -> Adware.Agent : Ignored.
C:\Program Files\psquery\psquery.exe -> Adware.CASClient : Ignored.
[1036] C:\Program Files\psquery\psquery.exe -> Adware.CASClient : Ignored.
C:\QooBox\Quarantine\C\Program Files\Screensavers.com\SSSInst\bin\SSSInst.dll.vir -> Adware.Comet : Ignored.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001029.dll -> Adware.Comet : Ignored.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001182.dll -> Adware.Comet : Ignored.
C:\WINDOWS\UmljaGFyZCBXaWVnYW5k\asappsrv.dll -> Adware.CommAd : Ignored.
C:\WINDOWS\UmljaGFyZCBXaWVnYW5k\command.exe -> Adware.CommAd : Ignored.
HKLM\SOFTWARE\Classes\Softomate.IEToolbar -> Adware.CoolWebSearch : Ignored.
HKLM\SOFTWARE\Classes\Softomate.IEToolbar.1 -> Adware.CoolWebSearch : Ignored.
HKLM\SOFTWARE\Classes\Softomate.IEToolbar\CLSID -> Adware.CoolWebSearch : Ignored.
HKLM\SOFTWARE\Classes\Softomate.IEToolbar\CurVer -> Adware.CoolWebSearch : Ignored.
C:\QooBox\Quarantine\C\Program Files\Common Files\{30E9F~1\UnInstall.exe.vir -> Adware.IWantSearch : Ignored.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001185.exe -> Adware.IWantSearch : Ignored.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001291.dll -> Adware.Maxifiles : Ignored.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001292.exe -> Adware.Maxifiles : Ignored.
C:\QooBox\Quarantine\C\Program Files\Common Files\{30E9F~1\Bar888.dll.vir -> Adware.MaxSearch : Ignored.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001184.dll -> Adware.MaxSearch : Ignored.
C:\QooBox\Quarantine\C\Program Files\Common Files\{A0E9F~1\Update.exe.vir -> Adware.Softomate : Ignored.
C:\QooBox\Quarantine\C\Program Files\Common Files\{A0E9F~1\system.dll.vir -> Adware.Softomate : Ignored.
C:\QooBox\Quarantine\C\Program Files\Common Files\{A0E9F~2\Update.exe.vir -> Adware.Softomate : Ignored.
C:\QooBox\Quarantine\C\Program Files\Common Files\{A0E9F~2\system.dll.vir -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001186.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001187.exe -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001188.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001189.exe -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001028.dll -> Adware.TargetServer : Ignored.
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\svchosts.exe.vir -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001191.exe -> Downloader.Agent.bca : Ignored.
C:\QooBox\Quarantine\C\Program Files\Common Files\Yazzle1122OinAdmin.exe.vir -> Downloader.PurityScan.eh : Ignored.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001175.exe -> Downloader.PurityScan.eh : Ignored.
C:\QooBox\Quarantine\C\63246057.exe.vir -> Downloader.Tiny.fy : Ignored.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001178.exe -> Downloader.Tiny.fy : Ignored.
C:\Program Files\Common Files\zqzu\zqzup.exe -> Downloader.TSUpdate.f : Ignored.
C:\Program Files\Common Files\zqzu\zqzud\vocabulary -> Downloader.TSUpdate.j : Ignored.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001027.exe -> Downloader.TSUpdate.l : Ignored.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001026.exe -> Downloader.TSUpdate.n : Ignored.
C:\Program Files\Common Files\zqzu\zqzul.exe -> Downloader.TSUpdate.r : Ignored.
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\DRIVERS\core.sys.vir -> Rootkit.Agent.eq : Ignored.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001197.sys -> Rootkit.Agent.eq : Ignored.
:mozilla.359:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.247realmedia : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@247realmedia[1].txt -> TrackingCookie.247realmedia : Ignored.
:mozilla.14:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\i5a4h0v8.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.17:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\i5a4h0v8.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.17:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.302:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.303:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.304:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.320:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.385:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.62:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.66:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.691:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.692:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.693:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.694:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.695:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.696:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.697:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.698:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.699:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.6:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.700:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.701:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.702:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.703:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.704:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.705:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.706:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.707:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.708:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.709:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.710:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.720:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.78:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.7:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.8:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Kelsey\Cookies\kelsey@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Kyle\Cookies\kyle@2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Kyle\Cookies\kyle@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@2o7[2].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@babyuniverse.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@2o7[2].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@entrepreneur.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@franchiseservices.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@ldproducts.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@shopping.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@usatoday1.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@aavalue[1].txt -> TrackingCookie.Aavalue : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@arn.aavalue[2].txt -> TrackingCookie.Aavalue : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@getmusicfree.aavalue[1].txt -> TrackingCookie.Aavalue : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@www.abcsearch[1].txt -> TrackingCookie.Abcsearch : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@adbrite[1].txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.415:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Addynamix : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Ignored.
:mozilla.71:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adobe : Ignored.
:mozilla.72:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adobe : Ignored.
C:\Documents and Settings\Kyle\Cookies\kyle@www.adobe[1].txt -> TrackingCookie.Adobe : Ignored.
:mozilla.391:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.392:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.393:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.394:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.785:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@adrevolver[2].txt -> TrackingCookie.Adrevolver : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@adrevolver[2].txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.604:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adserver : Ignored.
:mozilla.605:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adserver : Ignored.
:mozilla.606:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adserver : Ignored.
:mozilla.228:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adtech : Ignored.
:mozilla.229:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adtech : Ignored.
:mozilla.176:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.177:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.178:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.179:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.498:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.499:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.500:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
C:\Documents and Settings\Kyle\Cookies\kyle@advertising[1].txt -> TrackingCookie.Advertising : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@advertising[1].txt -> TrackingCookie.Advertising : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@advertising[2].txt -> TrackingCookie.Advertising : Ignored.
:mozilla.360:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Atdmt : Ignored.
:mozilla.8:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\i5a4h0v8.default\cookies.txt -> TrackingCookie.Atdmt : Ignored.
C:\Documents and Settings\Kyle\Cookies\kyle@atdmt[2].txt -> TrackingCookie.Atdmt : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@atdmt[2].txt -> TrackingCookie.Atdmt : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@atdmt[2].txt -> TrackingCookie.Atdmt : Ignored.
:mozilla.249:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Bfast : Ignored.
:mozilla.250:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Bfast : Ignored.
C:\Documents and Settings\Kyle\Cookies\kyle@bfast[2].txt -> TrackingCookie.Bfast : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@bfast[1].txt -> TrackingCookie.Bfast : Ignored.
:mozilla.827:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Bluestreak : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@bluestreak[1].txt -> TrackingCookie.Bluestreak : Ignored.
:mozilla.810:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Bridgetrack : Ignored.
:mozilla.811:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Bridgetrack : Ignored.
:mozilla.455:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Burstbeacon : Ignored.
:mozilla.290:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Burstnet : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@burstnet[2].txt -> TrackingCookie.Burstnet : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@www.burstnet[1].txt -> TrackingCookie.Burstnet : Ignored.
:mozilla.135:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored.
:mozilla.136:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored.
:mozilla.137:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored.
C:\Documents and Settings\Kyle\Cookies\kyle@casalemedia[2].txt -> TrackingCookie.Casalemedia : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@casalemedia[1].txt -> TrackingCookie.Casalemedia : Ignored.
:mozilla.656:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Centrport : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@clickbank[1].txt -> TrackingCookie.Clickbank : Ignored.
:mozilla.670:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Com : Ignored.
:mozilla.671:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Com : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@connextra[2].txt -> TrackingCookie.Connextra : Ignored.
:mozilla.522:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Coremetrics : Ignored.
:mozilla.580:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Coremetrics : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@test.coremetrics[1].txt -> TrackingCookie.Coremetrics : Ignored.
C:\Documents and Settings\Kyle\Cookies\kyle@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@dealtime[1].txt -> TrackingCookie.Dealtime : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@stat.dealtime[2].txt -> TrackingCookie.Dealtime : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@dealtime[1].txt -> TrackingCookie.Dealtime : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@stat.dealtime[1].txt -> TrackingCookie.Dealtime : Ignored.
:mozilla.6:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\i5a4h0v8.default\cookies.txt -> TrackingCookie.Doubleclick : Ignored.
:mozilla.824:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Doubleclick : Ignored.
C:\Documents and Settings\Kyle\Cookies\kyle@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@doubleclick[2].txt -> TrackingCookie.Doubleclick : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@doubleclick[2].txt -> TrackingCookie.Doubleclick : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@enhance[1].txt -> TrackingCookie.Enhance : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@enhance[2].txt -> TrackingCookie.Enhance : Ignored.
:mozilla.163:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Ignored.
:mozilla.16:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Ignored.
:mozilla.234:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Ignored.
:mozilla.238:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Ignored.
:mozilla.253:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Ignored.
:mozilla.321:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Ignored.
:mozilla.413:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Ignored.
:mozilla.523:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Ignored.
:mozilla.554:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Ignored.
:mozilla.562:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Ignored.
:mozilla.610:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Ignored.
:mozilla.784:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Ignored.
:mozilla.791:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Ignored.
:mozilla.534:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.535:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.536:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.563:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.564:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.565:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.566:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.567:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.825:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Fastclick : Ignored.
:mozilla.826:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Fastclick : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@fastclick[2].txt -> TrackingCookie.Fastclick : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@fastclick[2].txt -> TrackingCookie.Fastclick : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@findwhat[2].txt -> TrackingCookie.Findwhat : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@findwhat[1].txt -> TrackingCookie.Findwhat : Ignored.
C:\Documents and Settings\Kyle\Cookies\kyle@fortunecity[1].txt -> TrackingCookie.Fortunecity : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@fortunecity[1].txt -> TrackingCookie.Fortunecity : Ignored.
:mozilla.734:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.735:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.736:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.737:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.738:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.739:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.740:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.741:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.742:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.743:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.744:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.745:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.746:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.747:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.748:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.96:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.149:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.150:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.180:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.181:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.182:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.183:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.230:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.231:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.232:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.307:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.310:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.311:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.31:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.323:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.324:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.325:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.364:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.511:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.512:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.553:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.577:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.578:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.633:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.76:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.77:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.788:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.789:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.790:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.800:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.9:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@ehg-babyuniverse.hitbox[1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@ehg-adaptivemarketing.hitbox[1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@ehg-hollywood.hitbox[1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@ehg-maniatv.hitbox[1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.792:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitslink : Ignored.
:mozilla.793:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitslink : Ignored.
:mozilla.794:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitslink : Ignored.
:mozilla.795:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitslink : Ignored.
:mozilla.73:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hypertracker : Ignored.
:mozilla.318:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Imrworldwide : Ignored.
:mozilla.319:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Imrworldwide : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@infinite-ads[1].txt -> TrackingCookie.Infinite-ads : Ignored.
:mozilla.82:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Information : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@searchportal.information[1].txt -> TrackingCookie.Information : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@linksynergy[2].txt -> TrackingCookie.Linksynergy : Ignored.
:mozilla.101:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.102:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.103:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.104:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.105:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.106:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.222:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.223:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.224:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.225:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.226:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.83:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.84:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.85:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.86:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.87:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.88:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.89:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@sales.liveperson[3].txt -> TrackingCookie.Liveperson : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@server.iad.liveperson[3].txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.406:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
:mozilla.407:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
:mozilla.9:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\i5a4h0v8.default\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
C:\Documents and Settings\Kyle\Cookies\kyle@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignored.
:mozilla.544:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Msn : Ignored.
:mozilla.545:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Msn : Ignored.
:mozilla.546:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Msn : Ignored.
:mozilla.547:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Msn : Ignored.
:mozilla.548:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Msn : Ignored.
:mozilla.842:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Ignored.
:mozilla.314:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.48:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.730:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.731:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.838:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Overture : Ignored.
C:\Documents and Settings\Kyle\Cookies\kyle@overture[2].txt -> TrackingCookie.Overture : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@perf.overture[1].txt -> TrackingCookie.Overture : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@overture[1].txt -> TrackingCookie.Overture : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@perf.overture[1].txt -> TrackingCookie.Overture : Ignored.
:mozilla.13:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.14:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.15:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.16:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.172:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.173:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.174:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.175:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
C:\Documents and Settings\Kyle\Cookies\kyle@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@pro-market[2].txt -> TrackingCookie.Pro-market : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@pro-market[1].txt -> TrackingCookie.Pro-market : Ignored.
:mozilla.74:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Qksrv : Ignored.
:mozilla.75:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Qksrv : Ignored.
:mozilla.49:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
:mozilla.50:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
:mozilla.51:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
:mozilla.797:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
:mozilla.798:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
:mozilla.799:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
C:\Documents and Settings\Kyle\Cookies\kyle@questionmarket[1].txt -> TrackingCookie.Questionmarket : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@questionmarket[2].txt -> TrackingCookie.Questionmarket : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@questionmarket[1].txt -> TrackingCookie.Questionmarket : Ignored.
:mozilla.504:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Realmedia : Ignored.
:mozilla.505:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Realmedia : Ignored.
:mozilla.506:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Realmedia : Ignored.
C:\Documents and Settings\Kyle\Cookies\kyle@realmedia[1].txt -> TrackingCookie.Realmedia : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@realmedia[1].txt -> TrackingCookie.Realmedia : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@network.realmedia[2].txt -> TrackingCookie.Realmedia : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@realmedia[1].txt -> TrackingCookie.Realmedia : Ignored.
:mozilla.711:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Realtracker : Ignored.
:mozilla.712:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Realtracker : Ignored.
:mozilla.52:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Revenue : Ignored.
:mozilla.803:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Revenue : Ignored.
:mozilla.288:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Revsci : Ignored.
:mozilla.289:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Revsci : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@revsci[1].txt -> TrackingCookie.Revsci : Ignored.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_

#10 Joe_Smith

Joe_Smith

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 27 April 2007 - 10:08 PM

Sorry, forgot to include the HijackThis post...

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 10:57:08 PM, on 4/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\pasystem\pasystem.exe
C:\PROGRA~1\COMMON~1\aol\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Richard Wiegand\Desktop\HiJackThis_v2.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://localhost/:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark 4200 Series] "C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark 4200 Series\Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [SFP] C:\Program Files\Common Files\Verizon Online\SFP\vzSFPWin.EXE /s
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [zqzu] C:\PROGRA~1\COMMON~1\zqzu\zqzum.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PaSystem] "C:\Program Files\pasystem\pasystem.exe"
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.clarkcolo...larkActivia.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\aol\ACS\AOLacsd.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 8481 bytes

#11 teacup61

teacup61

    RIP

  • Emeritus
  • PipPipPipPipPip
  • 4,064 posts

Posted 28 April 2007 - 01:24 AM

Hello,

Open AVG and change the setting to clean (quarantine) and run it again in the same fashion as before. Only this time it will clean all it finds. :) Post the report and a new HijackThis log, please.

Thanks,
tea
My help is free, but if you wish to help keep these forums running please consider a donation, see this topic for details.

Posted Image
Posted Image

#12 Joe_Smith

Joe_Smith

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 28 April 2007 - 10:08 AM

I updated/quarantined the AVG items and posted the log below. The HijackThis log is also below.

Thanks!


---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 11:04:34 AM 4/28/2007

+ Scan result:



C:\RECYCLER\S-1-5-21-3293177330-830341180-1122393778-500\Dc1.sys -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0001653.sys -> Adware.Agent : Cleaned with backup (quarantined).
C:\Program Files\psquery\psquery.exe -> Adware.CASClient : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Screensavers.com\SSSInst\bin\SSSInst.dll.vir -> Adware.Comet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001029.dll -> Adware.Comet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001182.dll -> Adware.Comet : Cleaned with backup (quarantined).
C:\WINDOWS\UmljaGFyZCBXaWVnYW5k\asappsrv.dll -> Adware.CommAd : Cleaned with backup (quarantined).
C:\WINDOWS\UmljaGFyZCBXaWVnYW5k\command.exe -> Adware.CommAd : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Softomate.IEToolbar -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Softomate.IEToolbar.1 -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Softomate.IEToolbar\CLSID -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Softomate.IEToolbar\CurVer -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Common Files\{30E9F~1\UnInstall.exe.vir -> Adware.IWantSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001185.exe -> Adware.IWantSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001291.dll -> Adware.Maxifiles : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001292.exe -> Adware.Maxifiles : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Common Files\{30E9F~1\Bar888.dll.vir -> Adware.MaxSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001184.dll -> Adware.MaxSearch : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Common Files\{A0E9F~1\Update.exe.vir -> Adware.Softomate : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Common Files\{A0E9F~1\system.dll.vir -> Adware.Softomate : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Common Files\{A0E9F~2\Update.exe.vir -> Adware.Softomate : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Common Files\{A0E9F~2\system.dll.vir -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001186.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001187.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001188.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001189.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001028.dll -> Adware.TargetServer : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\svchosts.exe.vir -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001191.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Common Files\Yazzle1122OinAdmin.exe.vir -> Downloader.PurityScan.eh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001175.exe -> Downloader.PurityScan.eh : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\63246057.exe.vir -> Downloader.Tiny.fy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001178.exe -> Downloader.Tiny.fy : Cleaned with backup (quarantined).
C:\Program Files\Common Files\zqzu\zqzup.exe -> Downloader.TSUpdate.f : Cleaned with backup (quarantined).
C:\Program Files\Common Files\zqzu\zqzud\vocabulary -> Downloader.TSUpdate.j : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001027.exe -> Downloader.TSUpdate.l : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001026.exe -> Downloader.TSUpdate.n : Cleaned with backup (quarantined).
C:\Program Files\Common Files\zqzu\zqzul.exe -> Downloader.TSUpdate.r : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\DRIVERS\core.sys.vir -> Rootkit.Agent.eq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0001197.sys -> Rootkit.Agent.eq : Cleaned with backup (quarantined).
:mozilla.359:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.14:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\i5a4h0v8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.17:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\i5a4h0v8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.17:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.302:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.303:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.304:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.320:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.385:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.62:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.66:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.691:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.692:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.693:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.694:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.695:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.696:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.697:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.698:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.699:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.6:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.700:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.701:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.702:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.703:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.704:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.705:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.706:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.707:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.708:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.709:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.710:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.720:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.78:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.7:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.8:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kelsey\Cookies\kelsey@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kyle\Cookies\kyle@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kyle\Cookies\kyle@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@babyuniverse.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@entrepreneur.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@franchiseservices.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@ldproducts.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@shopping.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@usatoday1.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@arn.aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@getmusicfree.aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@www.abcsearch[1].txt -> TrackingCookie.Abcsearch : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.415:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.71:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adobe : Cleaned.
:mozilla.72:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adobe : Cleaned.
C:\Documents and Settings\Kyle\Cookies\kyle@www.adobe[1].txt -> TrackingCookie.Adobe : Cleaned.
:mozilla.391:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.392:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.393:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.394:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.785:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.604:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.605:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.606:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.228:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.229:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.176:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.177:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.178:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.179:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.498:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.499:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.500:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Kyle\Cookies\kyle@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.360:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.8:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\i5a4h0v8.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Kyle\Cookies\kyle@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.249:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.250:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Bfast : Cleaned.
C:\Documents and Settings\Kyle\Cookies\kyle@bfast[2].txt -> TrackingCookie.Bfast : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@bfast[1].txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.827:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.810:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.811:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.455:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.290:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@www.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.135:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.136:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.137:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Kyle\Cookies\kyle@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.656:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Centrport : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@clickbank[1].txt -> TrackingCookie.Clickbank : Cleaned.
:mozilla.670:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.671:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@connextra[2].txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.522:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.580:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@test.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Documents and Settings\Kyle\Cookies\kyle@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@dealtime[1].txt -> TrackingCookie.Dealtime : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@stat.dealtime[2].txt -> TrackingCookie.Dealtime : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@dealtime[1].txt -> TrackingCookie.Dealtime : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@stat.dealtime[1].txt -> TrackingCookie.Dealtime : Cleaned.
:mozilla.6:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\i5a4h0v8.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.824:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Kyle\Cookies\kyle@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@enhance[1].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@enhance[2].txt -> TrackingCookie.Enhance : Cleaned.
:mozilla.163:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.16:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.234:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.238:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.253:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.321:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.413:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.523:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.554:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.562:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.610:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.784:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.791:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.534:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.535:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.536:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.563:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.564:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.565:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.566:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.567:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.825:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.826:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@findwhat[2].txt -> TrackingCookie.Findwhat : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned.
C:\Documents and Settings\Kyle\Cookies\kyle@fortunecity[1].txt -> TrackingCookie.Fortunecity : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@fortunecity[1].txt -> TrackingCookie.Fortunecity : Cleaned.
:mozilla.734:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.735:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.736:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.737:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.738:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.739:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.740:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.741:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.742:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.743:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.744:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.745:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.746:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.747:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.748:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.96:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.149:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.150:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.180:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.181:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.182:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.183:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.230:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.231:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.232:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.307:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.310:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.311:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.31:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.323:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.324:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.325:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.364:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.511:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.512:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.553:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.577:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.578:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.633:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.76:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.77:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.788:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.789:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.790:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.800:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.9:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@ehg-babyuniverse.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@ehg-adaptivemarketing.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@ehg-hollywood.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@ehg-maniatv.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.792:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.793:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.794:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.795:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.73:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Hypertracker : Cleaned.
:mozilla.318:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.319:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@infinite-ads[1].txt -> TrackingCookie.Infinite-ads : Cleaned.
:mozilla.82:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Information : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@searchportal.information[1].txt -> TrackingCookie.Information : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@linksynergy[2].txt -> TrackingCookie.Linksynergy : Cleaned.
:mozilla.101:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.102:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.103:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.104:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.105:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.106:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.222:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.223:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.224:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.225:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.226:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.83:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.84:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.85:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.86:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.87:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.88:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.89:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@sales.liveperson[3].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@server.iad.liveperson[3].txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.406:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.407:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.9:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\i5a4h0v8.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Kyle\Cookies\kyle@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.544:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.545:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.546:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.547:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.548:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.842:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.314:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.48:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.730:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.731:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.838:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Kyle\Cookies\kyle@overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
:mozilla.13:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.14:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.15:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.16:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.172:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.173:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.174:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.175:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Kyle\Cookies\kyle@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@pro-market[2].txt -> TrackingCookie.Pro-market : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@pro-market[1].txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.74:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.75:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.49:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.50:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.51:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.797:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.798:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.799:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Kyle\Cookies\kyle@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.504:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.505:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.506:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\Kyle\Cookies\kyle@realmedia[1].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@realmedia[1].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@network.realmedia[2].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@realmedia[1].txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.711:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned.
:mozilla.712:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned.
:mozilla.52:C:\Documents and Settings\Richard Wiegand\Application Data\Mozilla\Firefox\Profiles\44iubdlg.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.803:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.288:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.289:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@revsci[1].txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\Richard Wiegand\Cookies\richard_wiegand@revsci[1].txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.581:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.582:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.583:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.584:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.585:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.586:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.587:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.588:C:\Documents and Settings\Richard Wiegand\Application Data\Netscape\NSB\Profiles\1auiagbk.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.589:C:\Documents and Settings\Richard Wiegand\Applicat

#13 teacup61

teacup61

    RIP

  • Emeritus
  • PipPipPipPipPip
  • 4,064 posts

Posted 28 April 2007 - 12:11 PM

Hi,

Looks like it got cut off. Could you just post the HijackThis log please? How is it running now?

Thanks
My help is free, but if you wish to help keep these forums running please consider a donation, see this topic for details.

Posted Image
Posted Image

#14 Joe_Smith

Joe_Smith

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 28 April 2007 - 04:13 PM

Sure, it's below. Thanks.

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 5:12:50 PM, on 4/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\aol\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\pasystem\pasystem.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Richard Wiegand\Desktop\HiJackThis_v2.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://localhost/:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark 4200 Series] "C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark 4200 Series\Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [SFP] C:\Program Files\Common Files\Verizon Online\SFP\vzSFPWin.EXE /s
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [zqzu] C:\PROGRA~1\COMMON~1\zqzu\zqzum.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PaSystem] "C:\Program Files\pasystem\pasystem.exe"
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.clarkcolo...larkActivia.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\aol\ACS\AOLacsd.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 8631 bytes

#15 teacup61

teacup61

    RIP

  • Emeritus
  • PipPipPipPipPip
  • 4,064 posts

Posted 28 April 2007 - 04:34 PM

Could you please go to that folder in Program Files PaSystem and right click on it and tell me what the properties are for it?

Also, how is it running now?

Thanks
My help is free, but if you wish to help keep these forums running please consider a donation, see this topic for details.

Posted Image
Posted Image

#16 Joe_Smith

Joe_Smith

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 29 April 2007 - 12:30 PM

Everything appeared to be running well (no more popups), but I did get another one today. It was the only one I've received in a few days, but it was definitely like the others I used to receive (meaning it wasn't a popup from a sites I visited - I believe it was 1800Buyer, which is a frequent one I used to get. I'm afraid they are going to start coming more frequently now.

I checked the properties of the pasystem file and here are some of the attributes...

Flagged as read-only (doesn't appear I can change it though)
Created on 4/14/2007
It's not flagged to be shared

There also appears to be an uninstall.exe file in the folder. Not sure if that would create other problems though.

Thanks.

#17 teacup61

teacup61

    RIP

  • Emeritus
  • PipPipPipPipPip
  • 4,064 posts

Posted 29 April 2007 - 04:59 PM

Hello,

If there's an uninstaller, then look in Add/Remove Programs and see if it can be uninstalled before we start deleting stuff. It's the only thing that was created on that day according to the ComboFix log. If you don't remember adding anything on the 14th, then uninstall it.

Please download ATF Cleaner by Atribune.Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Download the trial version of Spy Sweeper from
Here


Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)

You will be prompted to check for updated definitions, please do so.
(This may take several minutes)

Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.

Click on Sweep and allow it to fully scan your system.

When the sweep has finished, click Remove. Click Select All and then Next

From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.

Exit Spy Sweeper.

Restart your computer, and then please copy and paste the SpySweeper log into this thread, along with a new HijackThis log.

Thanks,
tea
My help is free, but if you wish to help keep these forums running please consider a donation, see this topic for details.

Posted Image
Posted Image

#18 Joe_Smith

Joe_Smith

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 29 April 2007 - 08:51 PM

I don't see a pasystem related item in the Add/Remove Programs. Should I attempt to use the uninstall option within the pasystem folder?

I also ran the ATF cleaner.

The SpySweeper and HijackThis logs are below.

Thanks!

9:39 PM: Removal process completed. Elapsed time 00:01:51
9:39 PM: Preparing to restart your computer. Please wait...
9:38 PM: Quarantining All Traces: atwola cookie
9:38 PM: Quarantining All Traces: command
9:38 PM: Quarantining All Traces: targetsaver
9:38 PM: Quarantining All Traces: maxifiles
9:38 PM: Quarantining All Traces: comet cursor
9:38 PM: Quarantining All Traces: starware toolbar
9:38 PM: Quarantining All Traces: fullcontext
9:37 PM: Removal process initiated
9:25 PM: Traces Found: 41
9:25 PM: Full Sweep has completed. Elapsed time 00:26:25
9:25 PM: File Sweep Complete, Elapsed Time: 00:20:27
9:23 PM: Warning: TCompressedFile.GetStreams(1): Stream read error
9:22 PM: C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\tsuninst.exe.vir (ID = 329490)
9:22 PM: C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\atmtd.dll._.vir (ID = 166754)
9:14 PM: C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\atmtd.dll.vir (ID = 166754)
9:14 PM: Found Adware: command
9:14 PM: HKU\S-1-5-21-3293177330-830341180-1122393778-1006\Software\Microsoft\Windows\CurrentVersion\Run || PaSystem (ID = 0)
9:14 PM: C:\Program Files\pasystem\pasystem.exe (ID = 525743)
9:14 PM: C:\Program Files\Common Files\zqzu\zqzud\class-barrel (ID = 78229)
9:14 PM: Found Adware: targetsaver
9:14 PM: C:\QooBox\Quarantine\C\Program Files\Ipwindows\ipwins.exe.vir (ID = 519351)
9:14 PM: C:\QooBox\Quarantine\C\Program Files\Ipwindows\ipwins.dll.vir (ID = 516399)
9:14 PM: Found Adware: maxifiles
9:08 PM: C:\Documents and Settings\Richard Wiegand\Desktop\backups\backup-20070427-204347-344.dll (ID = 522862)
9:05 PM: C:\Program Files\pasystem (3 subtraces) (ID = 2147551617)
9:05 PM: Starting File Sweep
9:05 PM: Warning: SweepDirectories: Cannot find directory "a:". This directory was not added to the list of paths to be scanned.
9:05 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
9:05 PM: c:\documents and settings\richard wiegand\cookies\richard_wiegand@atwola[1].txt (ID = 2255)
9:05 PM: Found Spy Cookie: atwola cookie
9:05 PM: Starting Cookie Sweep
9:05 PM: Registry Sweep Complete, Elapsed Time:00:00:30
9:05 PM: HKU\S-1-5-18\software\adsponsorcl\ (ID = 2170948)
9:05 PM: HKU\S-1-5-21-3293177330-830341180-1122393778-1006\software\pasystem\ (ID = 2174903)
9:05 PM: HKU\S-1-5-21-3293177330-830341180-1122393778-1006\software\microsoft\windows\currentversion\run\ || pasystem (ID = 2174902)
9:05 PM: HKU\S-1-5-21-3293177330-830341180-1122393778-1006\software\psupport\ (ID = 2170962)
9:05 PM: HKU\S-1-5-21-3293177330-830341180-1122393778-1006\software\psquery\ (ID = 2170951)
9:05 PM: HKU\WRSS_Profile_S-1-5-21-3293177330-830341180-1122393778-1010\software\psupport\ (ID = 2170962)
9:05 PM: HKU\WRSS_Profile_S-1-5-21-3293177330-830341180-1122393778-1010\software\psquery\ (ID = 2170951)
9:05 PM: HKU\WRSS_Profile_S-1-5-21-3293177330-830341180-1122393778-1011\software\psupport\ (ID = 2170962)
9:05 PM: HKU\WRSS_Profile_S-1-5-21-3293177330-830341180-1122393778-1011\software\psquery\ (ID = 2170951)
9:05 PM: HKU\WRSS_Profile_S-1-5-21-3293177330-830341180-1122393778-1011\software\adsponsorcl\ (ID = 2170948)
9:05 PM: HKU\WRSS_Profile_S-1-5-21-3293177330-830341180-1122393778-500\software\psupport\ (ID = 2170962)
9:05 PM: HKU\WRSS_Profile_S-1-5-21-3293177330-830341180-1122393778-500\software\psquery\ (ID = 2170951)
9:05 PM: HKLM\system\controlset001\services\psquery\ (ID = 2170932)
9:05 PM: HKLM\system\controlset001\enum\root\legacy_psquery\ (ID = 2170930)
9:05 PM: HKLM\software\microsoft\internet explorer\explorer bars\{2bc9c452-bb57-4896-a9a2-64611e06c9aa}\ (ID = 2170925)
9:05 PM: HKLM\software\classes\clsid\{4c1caacf-1788-4613-a840-6bd943d4ee95}\ (ID = 1635328)
9:05 PM: HKCR\clsid\{9a7d6ad2-0881-451f-bb27-f5e2ee2c5b14}\ (ID = 1635327)
9:05 PM: HKCR\clsid\{4c1caacf-1788-4613-a840-6bd943d4ee95}\ (ID = 1632675)
9:05 PM: HKLM\software\classes\clsid\{9fb3908c-6565-4cb0-95f8-e9f85258723c}\ (ID = 1576245)
9:05 PM: HKLM\software\classes\clsid\{9a7d6ad2-0881-451f-bb27-f5e2ee2c5b14}\ (ID = 1576244)
9:05 PM: HKCR\clsid\{9fb3908c-6565-4cb0-95f8-e9f85258723c}\ (ID = 1576239)
9:05 PM: HKLM\software\screensavers.com\ (ID = 140569)
9:05 PM: Found Adware: comet cursor
9:04 PM: Starting Registry Sweep
9:04 PM: Memory Sweep Complete, Elapsed Time: 00:05:16
9:02 PM: HKU\S-1-5-21-3293177330-830341180-1122393778-1006\Software\Microsoft\Windows\CurrentVersion\Run || PaSystem (ID = 0)
9:02 PM: Detected running threat: C:\Program Files\pasystem\pasystem.exe (ID = 525743)
9:02 PM: Found Adware: fullcontext
8:59 PM: Starting Memory Sweep
8:59 PM: HKCR\clsid\{9fb3908c-6565-4cb0-95f8-e9f85258723c}\inprocserver32\ (ID = 1942864)
8:59 PM: HKCR\clsid\{9a7d6ad2-0881-451f-bb27-f5e2ee2c5b14}\inprocserver32\ (ID = 1942863)
8:59 PM: HKCR\clsid\{4c1caacf-1788-4613-a840-6bd943d4ee95}\inprocserver32\ (ID = 1942861)
8:59 PM: Found Adware: starware toolbar
8:59 PM: Start Full Sweep
8:59 PM: Sweep initiated using definitions version 904
8:59 PM: Access to Hosts file blocked for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
Keylogger: Off
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites: Off
Hosts File Shield: On
Internet Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: Off
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
8:54 PM: Shield States
8:54 PM: Spyware Definitions: 904
8:53 PM: Spy Sweeper 5.3.2.2361 started
8:53 PM: Spy Sweeper 5.3.2.2361 started
8:53 PM: | Start of Session, Sunday, April 29, 2007 |
***************


Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 9:46:23 PM, on 4/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\aol\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\system32\wscntfy.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Richard Wiegand\Desktop\HiJackThis_v2.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://localhost/:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [MCAgentExe] "C:\Program Files\McAfee.com\Agent\mcagent.exe"
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [AOLDialer] "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark 4200 Series] "C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark 4200 Series\Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [SFP] "C:\Program Files\Common Files\Verizon Online\SFP\vzSFPWin.EXE" /s
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [zqzu] C:\PROGRA~1\COMMON~1\zqzu\zqzum.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.clarkcolo...larkActivia.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\aol\ACS\AOLacsd.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 8724 bytes

#19 teacup61

teacup61

    RIP

  • Emeritus
  • PipPipPipPipPip
  • 4,064 posts

Posted 29 April 2007 - 10:14 PM

Hello,

Should I attempt to use the uninstall option within the pasystem folder?

No, because it's not in the log anymore. SpySweeper got it. ;) If the folder is still there, then delete it and reboot.

1) Please download the Killbox.
Save it to the desktop and run it.

2) Select "Delete on Reboot", and then select "All files".

3) Copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\PROGRA~1\COMMON~1\zqzu

4) Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

5) Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

Run another scan with AVG, and post the report with a new HijackThis log please. Let me know if the popups are gone and how it's running. :)

Thanks,
tea
My help is free, but if you wish to help keep these forums running please consider a donation, see this topic for details.

Posted Image
Posted Image

#20 Joe_Smith

Joe_Smith

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 30 April 2007 - 07:36 PM

The popups do appear to be gone! Thanks! However, I was not able to access the Killbox link you provided. I received a "The requested document was not found on this server." message.

#21 teacup61

teacup61

    RIP

  • Emeritus
  • PipPipPipPipPip
  • 4,064 posts

Posted 30 April 2007 - 08:05 PM

Sorry about that link. :unsure: Let's do it this way, if it's still there.

Open HijackThis. It should open to a "New users quickstart" menu
Click "Open the Misc Tools section"
Click "Delete a file on reboot..."
In the "Enter file to delete on reboot..." window, navigate to:

C:\Program Files\Common Files

And select the file/folder

zqzu

Then click Open. After you click Open, HiJackThis will ask you if you want to restart your computer now. You do, so click Yes.

Post a new HiajckThis log so I can be sure it's gone. :)

Thanks,
tea
My help is free, but if you wish to help keep these forums running please consider a donation, see this topic for details.

Posted Image
Posted Image

#22 Joe_Smith

Joe_Smith

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 01 May 2007 - 07:12 PM

Unfortunately HijackThis will only let me select a file (not a folder). Any other suggestions on how to delete it? Should I attempt to delete this folder manually myself or is there another way to do so via HijackThis?

Thanks.

#23 teacup61

teacup61

    RIP

  • Emeritus
  • PipPipPipPipPip
  • 4,064 posts

Posted 01 May 2007 - 08:39 PM

Hello,

Actually it should be gone. That's why I wanted to see a new HijackThis log. :) If it's still there, you can try to delete it. If it won't go in normal mode, then try safe mode. If not, we'll go from there.

Thanks,
tea
My help is free, but if you wish to help keep these forums running please consider a donation, see this topic for details.

Posted Image
Posted Image

#24 Joe_Smith

Joe_Smith

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 02 May 2007 - 05:54 PM

I was able to manually delete the zqzu folder manually. The pasystem folder is also gone. Here's the latest HijackThis log.

Thanks!

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 6:50:28 PM, on 5/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmon.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\COMMON~1\aol\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\wscntfy.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Richard Wiegand\Desktop\HiJackThis_v2.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://localhost/:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [MCAgentExe] "C:\Program Files\McAfee.com\Agent\mcagent.exe"
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [AOLDialer] "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark 4200 Series] "C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark 4200 Series\Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [SFP] "C:\Program Files\Common Files\Verizon Online\SFP\vzSFPWin.EXE" /s
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [zqzu] C:\PROGRA~1\COMMON~1\zqzu\zqzum.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.clarkcolo...larkActivia.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\aol\ACS\AOLacsd.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 8907 bytes

#25 teacup61

teacup61

    RIP

  • Emeritus
  • PipPipPipPipPip
  • 4,064 posts

Posted 03 May 2007 - 12:04 PM

Hello,

Please run HijackThis! and click "Scan." Place checks next to the following entries, if present:

O4 - HKCU\..\Run: [zqzu] C:\PROGRA~1\COMMON~1\zqzu\zqzum.exe

Close all browsers and other windows except for HijackThis!, and click "Fix checked".

Make sure this folder is gone from CommonFiles :

C:\PROGRA~1\COMMON~1\zqzu

Reboot your computer.

Do a windows search and see if it comes up anywhere. :)

Your Java is way out of date, which leaves your computer vulnerable.

Updating Java
  • Download the latest version of Java Runtime Environment (JRE) 6u1.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windows-i586.exe to install the newest version.
How is it running?
My help is free, but if you wish to help keep these forums running please consider a donation, see this topic for details.

Posted Image
Posted Image

#26 Joe_Smith

Joe_Smith

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 03 May 2007 - 09:02 PM

I removed the zqzu folder and added the updated java. I've attached a new HijackThis log if needed.

Thanks.

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 9:59:41 PM, on 5/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\aol\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Richard Wiegand\Desktop\HiJackThis_v2.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://localhost/:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [MCAgentExe] "C:\Program Files\McAfee.com\Agent\mcagent.exe"
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [AOLDialer] "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark 4200 Series] "C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark 4200 Series\Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [SFP] "C:\Program Files\Common Files\Verizon Online\SFP\vzSFPWin.EXE" /s
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.clarkcolo...larkActivia.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\aol\ACS\AOLacsd.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 8855 bytes

#27 teacup61

teacup61

    RIP

  • Emeritus
  • PipPipPipPipPip
  • 4,064 posts

Posted 03 May 2007 - 10:58 PM

Yay! Great job! Posted Image
Your log looks clean again. :) You can delete the little tools we used along the way like Killbox, ComboFix and its accompanying folder C:\qoobox

If there are no further problems:

Below I have included a number of recommendations on how to protect your computer in order to prevent future malware infections. Please take these recommendations seriously! These few simple steps can stave off the vast majority of spyware problems.

Regularly go to http://windowsupdate.microsoft.com and download all the "critical updates" for Windows, including the latest version of Internet Explorer. This can patch many of the security holes through which attackers can gain access to your computer. You should also turn on the Windows automatic update feature.

You should definitely maintain a firewall. Some good free firewalls are Kerio, ZoneAlarm, or Outpost
A tutorial on understanding and using firewalls may be found here.

In order to protect yourself against spyware, you should consider installing and running the following free programs:

SpywareBlaster
A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found here.

SpywareGuard
A tutorial on using SpywareGuard for realtime protection against spyware and hijackers may be found here.

A tutorial on using Spybot to remove spyware from your computer may be found here. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features.

IE/Spyad:
It places over 5000 malicious websites and domains in your IE's restricted zone.
IE/Spyad

Make sure to keep these programs up-to-date and to run them regularly, as this can prevent a great deal of spyware hassle.

* Avoid illegal sites, because that's where most malware is present.
* Don't click on links inside popups.
* Don't click on links in spam messages claiming to offer anti-spyware software; because most of these so called removers ARE spyware.
* Download free software only from sites you know and trust. A lot of free software can bundle other software, including spyware.

Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in popup blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from here:
http://www.mozilla.o...oducts/firefox/

Please make sure to run your antivirus software regularly, and to keep it up-to-date.

Please also read Tony Klein's excellent article: How I got Infected in the First Place

Take care!
tea

Edited by teacup61, 03 May 2007 - 10:58 PM.

My help is free, but if you wish to help keep these forums running please consider a donation, see this topic for details.

Posted Image
Posted Image

#28 teacup61

teacup61

    RIP

  • Emeritus
  • PipPipPipPipPip
  • 4,064 posts

Posted 05 May 2007 - 05:54 PM

Since this issue appears resolved ... this Topic is closed.

If you need this topic reopened, please tell the moderating team by replying here with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
My help is free, but if you wish to help keep these forums running please consider a donation, see this topic for details.

Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button