Please help me with my spyware problem
Okay, first off, I clicked a link in AIM, which I probaly shouldn't have. It sent me that whole little virus/worm spyware thingy. Ever since we've been recieving things like Freepod Toolbar {Which we can't delete}, Command Service {Haven't a clue what this is}, startpage.TimesSquare, DollarRevenue, UCmore.XP.SearchAccelerator, Unclassified.Spyware.149, Maxifiles and Look2Me. We've run multiple scans through Norton Antivirus, CounterSpy and I believe Spyblocs. None of the three have been able to either completely remove, fix or permanently delete all of the spyware. The ones I've listed never fail to return the very next day. We've tried to remove them through the control panel, many of them haven't shown up on the Control at all though. Please help me. I've done a log through Hijack This for you to view.
Logfile of HijackThis v1.99.1
Scan saved at 4:18:40 AM, on 6/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\wmiapsv.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\devldr32.exe
G:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
G:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\webassist.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\System32\atmlib09.exe
C:\Program Files\Windows Defender\MSASCui.exe
G:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
file:\\C:\WINDOWS\system32\Searchx.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=56626&homepage=about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=56626&homepage=about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.mrfindalot.com/search.asp?si=20065&k=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.mrfindalot.com/search.asp?si=20065&k=
R3 - URLSearchHook: (no name) - <default> - (no file)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\vqnsp.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,hmtwavy.exe
O1 - Hosts: 216.177.73.139 search.netscape.com
O1 - Hosts: 216.177.73.139 ieautosearch
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [webassist] C:\WINDOWS\webassist.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [SpyBlocs] C:\SpyBlocs.exe
O4 - HKLM\..\Run: [ptcajf] C:\WINDOWS\System32\plnqzn.exe
O4 - HKLM\..\Run: [ce8bd0cab6fa] C:\WINDOWS\System32\atmlib09.exe
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [5881ac371b9b] C:\WINDOWS\system32\ati2dvag.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [w0264f4e.dll] RUNDLL32.EXE w0264f4e.dll,I2 0013bb0600264f4e
O4 - HKLM\..\Run: [SunServer] G:\Program Files\Sunbelt
Software\CounterSpy\Consumer\sunserver.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\RunOnce: [CounterSpyCleaner] G:\Program Files\Sunbelt
Software\CounterSpy\Consumer\sunASCleaner.exe
O4 - Startup: Trillian.lnk = G:\Program Files\Trillian\trillian.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office10\OSA.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box -
C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &FastSeeker Search - res://C:\Program
Files\FastSeeker\FastSeekerToolbar011203.dll/cmsearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: eZ$hopper - {BFA03761-5565-41b3-93D9-82B354C0A8EC} - (no file)
O9 - Extra 'Tools' menuitem: eZ$hopper - {BFA03761-5565-41b3-93D9-82B354C0A8EC} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program
Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} -
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)
O15 - Trusted Zone: http://www.beqanna.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation
Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) -
https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -
http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) -
http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl
Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) -
http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {F1A51F21-59DF-4486-BA31-5B816DA481EB} -
http://www.fastseeker.com/toolbar/download/FastSeekerSetup.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A96170D4-BFAA-4F6F-871F-B562EEDA8061}:
NameServer = 63.245.131.21 63.245.131.22
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3A3602C-CE7E-4E8A-AED4-68B33B0754AB}:
NameServer = 151.164.172.201
O20 - AppInit_DLLs: C:\WINDOWS\system32\csrss.dll C:\WINDOWS\system32\mshta.dll
O20 - Winlogon Notify: Unimodem - C:\WINDOWS\system32\ir40l5hm1.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation -
C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -
C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program
Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Microsoft Performance WMI Adapter AddOn (WMIPervAddOn) - Unknown owner -
C:\WINDOWS\wmiapsv.exe
Help would greatly be appreciated.
Logfile of HijackThis v1.99.1
Scan saved at 4:18:40 AM, on 6/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\wmiapsv.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\devldr32.exe
G:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
G:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\webassist.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\System32\atmlib09.exe
C:\Program Files\Windows Defender\MSASCui.exe
G:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
file:\\C:\WINDOWS\system32\Searchx.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=56626&homepage=about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=56626&homepage=about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.mrfindalot.com/search.asp?si=20065&k=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.mrfindalot.com/search.asp?si=20065&k=
R3 - URLSearchHook: (no name) - <default> - (no file)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\vqnsp.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,hmtwavy.exe
O1 - Hosts: 216.177.73.139 search.netscape.com
O1 - Hosts: 216.177.73.139 ieautosearch
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [webassist] C:\WINDOWS\webassist.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [SpyBlocs] C:\SpyBlocs.exe
O4 - HKLM\..\Run: [ptcajf] C:\WINDOWS\System32\plnqzn.exe
O4 - HKLM\..\Run: [ce8bd0cab6fa] C:\WINDOWS\System32\atmlib09.exe
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [5881ac371b9b] C:\WINDOWS\system32\ati2dvag.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [w0264f4e.dll] RUNDLL32.EXE w0264f4e.dll,I2 0013bb0600264f4e
O4 - HKLM\..\Run: [SunServer] G:\Program Files\Sunbelt
Software\CounterSpy\Consumer\sunserver.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\RunOnce: [CounterSpyCleaner] G:\Program Files\Sunbelt
Software\CounterSpy\Consumer\sunASCleaner.exe
O4 - Startup: Trillian.lnk = G:\Program Files\Trillian\trillian.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office10\OSA.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box -
C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &FastSeeker Search - res://C:\Program
Files\FastSeeker\FastSeekerToolbar011203.dll/cmsearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: eZ$hopper - {BFA03761-5565-41b3-93D9-82B354C0A8EC} - (no file)
O9 - Extra 'Tools' menuitem: eZ$hopper - {BFA03761-5565-41b3-93D9-82B354C0A8EC} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program
Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} -
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)
O15 - Trusted Zone: http://www.beqanna.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation
Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) -
https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -
http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) -
http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl
Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) -
http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {F1A51F21-59DF-4486-BA31-5B816DA481EB} -
http://www.fastseeker.com/toolbar/download/FastSeekerSetup.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A96170D4-BFAA-4F6F-871F-B562EEDA8061}:
NameServer = 63.245.131.21 63.245.131.22
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3A3602C-CE7E-4E8A-AED4-68B33B0754AB}:
NameServer = 151.164.172.201
O20 - AppInit_DLLs: C:\WINDOWS\system32\csrss.dll C:\WINDOWS\system32\mshta.dll
O20 - Winlogon Notify: Unimodem - C:\WINDOWS\system32\ir40l5hm1.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation -
C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -
C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program
Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Microsoft Performance WMI Adapter AddOn (WMIPervAddOn) - Unknown owner -
C:\WINDOWS\wmiapsv.exe
Help would greatly be appreciated.
0
Comments
Follow these instructions:
http://www.short-media.com/forum/showthread.php?t=42651
http://www.short-media.com/forum/showthread.php?t=45050
After that, send a fresh HjT log and contents of C:\Look2Me-Destroyer.txt
Look2Me-Destroyer V1.0.12
Scanning for infected files.....
Scan started at 6/14/2006 6:08:07 AM
Infected! C:\WINDOWS\system32\ir40l5hm1.dll
Infected! C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP63\A0032384.dll
Infected! C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP63\A0032400.dll
Infected! C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP64\A0032434.dll
Infected! C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP65\A0032461.dll
Infected! C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP66\A0032518.dll
Infected! C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP68\A0032572.dll
Infected! C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP69\A0032587.dll
Infected! C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP70\A0032648.dll
Infected! C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP71\A0034586.dll
Infected! C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP72\A0034603.dll
Infected! C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP72\A0034642.dll
Infected! C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP75\A0034681.dll
Infected! C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP75\A0034682.dll
Infected! C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP75\A0034683.dll
Infected! C:\WINDOWS\system32\assldpc.dll
Infected! C:\WINDOWS\system32\cJtsrvps.dll
Infected! C:\WINDOWS\system32\dolay.dll
Infected! C:\WINDOWS\system32\gpr0l39m1.dll
Infected! C:\WINDOWS\system32\i042laho1d4c.dll
Infected! C:\WINDOWS\system32\i4060edseh060.dll
Infected! C:\WINDOWS\system32\i4240efqeh2e0.dll
Infected! C:\WINDOWS\system32\j6n2lg5o16.dll
Infected! C:\WINDOWS\system32\kodinben.dll
Infected! C:\WINDOWS\system32\l6j8lg1u16.dll
Attempting to delete infected files...
Attempting to delete: C:\WINDOWS\system32\ir40l5hm1.dll
C:\WINDOWS\system32\ir40l5hm1.dll could not be deleted!
Attempting to delete: C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP63\A0032384.dll
C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP63\A0032384.dll could not be deleted!
Attempting to delete: C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP63\A0032400.dll
C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP63\A0032400.dll could not be deleted!
Attempting to delete: C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP64\A0032434.dll
C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP64\A0032434.dll could not be deleted!
Attempting to delete: C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP65\A0032461.dll
C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP65\A0032461.dll could not be deleted!
Attempting to delete: C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP66\A0032518.dll
C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP66\A0032518.dll could not be deleted!
Attempting to delete: C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP68\A0032572.dll
C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP68\A0032572.dll could not be deleted!
Attempting to delete: C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP69\A0032587.dll
C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP69\A0032587.dll could not be deleted!
Attempting to delete: C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP70\A0032648.dll
C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP70\A0032648.dll could not be deleted!
Attempting to delete: C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP71\A0034586.dll
C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP71\A0034586.dll could not be deleted!
Attempting to delete: C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP72\A0034603.dll
C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP72\A0034603.dll could not be deleted!
Attempting to delete: C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP72\A0034642.dll
C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP72\A0034642.dll could not be deleted!
Attempting to delete: C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP75\A0034681.dll
C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP75\A0034681.dll could not be deleted!
Attempting to delete: C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP75\A0034682.dll
C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP75\A0034682.dll could not be deleted!
Attempting to delete: C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP75\A0034683.dll
C:\System Volume Information\_restore{7AB47C38-FC36-4FA7-8DF1-B7D2BFEBB8B7}\RP75\A0034683.dll could not be deleted!
Attempting to delete: C:\WINDOWS\system32\assldpc.dll
C:\WINDOWS\system32\assldpc.dll could not be deleted!
Attempting to delete: C:\WINDOWS\system32\cJtsrvps.dll
C:\WINDOWS\system32\cJtsrvps.dll could not be deleted!
Attempting to delete: C:\WINDOWS\system32\dolay.dll
C:\WINDOWS\system32\dolay.dll could not be deleted!
Attempting to delete: C:\WINDOWS\system32\gpr0l39m1.dll
C:\WINDOWS\system32\gpr0l39m1.dll could not be deleted!
Attempting to delete: C:\WINDOWS\system32\i042laho1d4c.dll
C:\WINDOWS\system32\i042laho1d4c.dll could not be deleted!
Attempting to delete: C:\WINDOWS\system32\i4060edseh060.dll
C:\WINDOWS\system32\i4060edseh060.dll could not be deleted!
Attempting to delete: C:\WINDOWS\system32\i4240efqeh2e0.dll
C:\WINDOWS\system32\i4240efqeh2e0.dll could not be deleted!
Attempting to delete: C:\WINDOWS\system32\j6n2lg5o16.dll
C:\WINDOWS\system32\j6n2lg5o16.dll could not be deleted!
Attempting to delete: C:\WINDOWS\system32\kodinben.dll
C:\WINDOWS\system32\kodinben.dll could not be deleted!
Attempting to delete: C:\WINDOWS\system32\l6j8lg1u16.dll
C:\WINDOWS\system32\l6j8lg1u16.dll could not be deleted!
Making registry repairs.
Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Unimodem
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{79FF1555-121C-4A60-9AE5-DBFB41A9A80B}"
HKCR\Clsid\{79FF1555-121C-4A60-9AE5-DBFB41A9A80B}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{B34B4C01-839A-4DE3-9DFC-3F628E438DBA}"
HKCR\Clsid\{B34B4C01-839A-4DE3-9DFC-3F628E438DBA}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{6C47C544-13B7-4545-A5EF-A4FC3D795DB5}"
HKCR\Clsid\{6C47C544-13B7-4545-A5EF-A4FC3D795DB5}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{1CA2E637-2E54-4202-BCCE-3DCB7A8CE721}"
HKCR\Clsid\{1CA2E637-2E54-4202-BCCE-3DCB7A8CE721}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{D037EF0F-39BD-4129-BD80-74911AD7A6DB}"
HKCR\Clsid\{D037EF0F-39BD-4129-BD80-74911AD7A6DB}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{B8EB6839-6B81-41AD-B192-873260D8535A}"
HKCR\Clsid\{B8EB6839-6B81-41AD-B192-873260D8535A}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{58BA911A-85D2-4F76-886F-734C991E1857}"
HKCR\Clsid\{58BA911A-85D2-4F76-886F-734C991E1857}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{4D8136BF-5D25-424F-97F4-E15142F35949}"
HKCR\Clsid\{4D8136BF-5D25-424F-97F4-E15142F35949}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{07539422-2A33-46F7-8E34-4EEB9D88D348}"
HKCR\Clsid\{07539422-2A33-46F7-8E34-4EEB9D88D348}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{60A36C34-8A3D-40CD-9EBE-A0B99B57E949}"
HKCR\Clsid\{60A36C34-8A3D-40CD-9EBE-A0B99B57E949}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{11C409E5-22A4-40E5-825A-76A38494988C}"
HKCR\Clsid\{11C409E5-22A4-40E5-825A-76A38494988C}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{E7488E9E-9963-4AF7-8303-20A74026AB3C}"
HKCR\Clsid\{E7488E9E-9963-4AF7-8303-20A74026AB3C}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{3622D833-0C83-473A-B967-5AAADA4A12DB}"
HKCR\Clsid\{3622D833-0C83-473A-B967-5AAADA4A12DB}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{2C38C55B-C056-47FD-BF27-2512968DB506}"
HKCR\Clsid\{2C38C55B-C056-47FD-BF27-2512968DB506}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{1DD21798-BBDB-4FF7-BBFB-3B32826A0EC9}"
HKCR\Clsid\{1DD21798-BBDB-4FF7-BBFB-3B32826A0EC9}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{4402D2EF-6646-43EA-B179-80D302980789}"
HKCR\Clsid\{4402D2EF-6646-43EA-B179-80D302980789}
Restoring Windows certificates.
Replaced hosts file with default windows hosts file
Restoring SeDebugPrivilege for Administrators - Succeeded
Hijack This Log:::
Logfile of HijackThis v1.99.1
Scan saved at 8:03:49 AM, on 6/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\wmiapsv.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\wpabaln.exe
G:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
G:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\webassist.exe
G:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\System32\atmlib09.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file:\\C:\WINDOWS\system32\Searchx.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=20065&k=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=20065&k=
R3 - URLSearchHook: (no name) - <default> - (no file)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\vqnsp.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,hmtwavy.exe
O4 - HKLM\..\Run: [SunServer] G:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [SpyBlocs] C:\SpyBlocs.exe
O4 - HKLM\..\Run: [ptcajf] C:\WINDOWS\System32\plnqzn.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [ce8bd0cab6fa] C:\WINDOWS\System32\atmlib09.exe
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [5881ac371b9b] C:\WINDOWS\system32\ati2dvag.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &FastSeeker Search - res://C:\Program Files\FastSeeker\FastSeekerToolbar011203.dll/cmsearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: eZ$hopper - {BFA03761-5565-41b3-93D9-82B354C0A8EC} - (no file)
O9 - Extra 'Tools' menuitem: eZ$hopper - {BFA03761-5565-41b3-93D9-82B354C0A8EC} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)
O15 - Trusted Zone: http://www.beqanna.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {F1A51F21-59DF-4486-BA31-5B816DA481EB} - http://www.fastseeker.com/toolbar/download/FastSeekerSetup.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A96170D4-BFAA-4F6F-871F-B562EEDA8061}: NameServer = 63.245.131.21 63.245.131.22
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3A3602C-CE7E-4E8A-AED4-68B33B0754AB}: NameServer = 151.164.172.201
O20 - AppInit_DLLs: C:\WINDOWS\system32\csrss.dll C:\WINDOWS\system32\mshta.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Microsoft Performance WMI Adapter AddOn (WMIPervAddOn) - Unknown owner - C:\WINDOWS\wmiapsv.exe
Re-run look2medestroyer and send its log (C:\Look2Me-Destroyer.txt) and a fresh HjT log.
Look2Me-Destroyer V1.0.12
Scanning for infected files.....
Scan started at 6/14/2006 8:23:02 AM
Infected! C:\WINDOWS\system32\ir40l5hm1.dll
Infected! C:\WINDOWS\system32\lv6209joe.dll
Infected! C:\WINDOWS\system32\lvro0993e.dll
Infected! C:\WINDOWS\system32\lvru0999e.dll
Infected! C:\WINDOWS\system32\mDpi32.dll
Infected! C:\WINDOWS\system32\sxrstr.dll
Infected! C:\WINDOWS\system32\vurifier.dll
Attempting to delete infected files...
Attempting to delete: C:\WINDOWS\system32\ir40l5hm1.dll
C:\WINDOWS\system32\ir40l5hm1.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\lv6209joe.dll
C:\WINDOWS\system32\lv6209joe.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\lvro0993e.dll
C:\WINDOWS\system32\lvro0993e.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\lvru0999e.dll
C:\WINDOWS\system32\lvru0999e.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\mDpi32.dll
C:\WINDOWS\system32\mDpi32.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\sxrstr.dll
C:\WINDOWS\system32\sxrstr.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\vurifier.dll
C:\WINDOWS\system32\vurifier.dll Deleted successfully!
Making registry repairs.
Restoring Windows certificates.
Replaced hosts file with default windows hosts file
Restoring SeDebugPrivilege for Administrators - Succeeded
Hijack This Log::
Logfile of HijackThis v1.99.1
Scan saved at 8:42:25 AM, on 6/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\wmiapsv.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\devldr32.exe
G:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
C:\WINDOWS\system32\wpabaln.exe
G:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe
G:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\System32\atmlib09.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file:\\C:\WINDOWS\system32\Searchx.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=20065&k=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=20065&k=
R3 - URLSearchHook: (no name) - <default> - (no file)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\vqnsp.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,hmtwavy.exe
O4 - HKLM\..\Run: [SunServer] G:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [SpyBlocs] C:\SpyBlocs.exe
O4 - HKLM\..\Run: [ptcajf] C:\WINDOWS\System32\plnqzn.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [ce8bd0cab6fa] C:\WINDOWS\System32\atmlib09.exe
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [5881ac371b9b] C:\WINDOWS\system32\ati2dvag.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &FastSeeker Search - res://C:\Program Files\FastSeeker\FastSeekerToolbar011203.dll/cmsearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: eZ$hopper - {BFA03761-5565-41b3-93D9-82B354C0A8EC} - (no file)
O9 - Extra 'Tools' menuitem: eZ$hopper - {BFA03761-5565-41b3-93D9-82B354C0A8EC} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)
O15 - Trusted Zone: http://www.beqanna.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {F1A51F21-59DF-4486-BA31-5B816DA481EB} - http://www.fastseeker.com/toolbar/download/FastSeekerSetup.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A96170D4-BFAA-4F6F-871F-B562EEDA8061}: NameServer = 63.245.131.21 63.245.131.22
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3A3602C-CE7E-4E8A-AED4-68B33B0754AB}: NameServer = 151.164.172.201
O20 - AppInit_DLLs: C:\WINDOWS\system32\csrss.dll C:\WINDOWS\system32\mshta.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Microsoft Performance WMI Adapter AddOn (WMIPervAddOn) - Unknown owner - C:\WINDOWS\wmiapsv.exe
This Time Look2Me was removed completely
Next one is qoologic:
Download FindQool by LonnyRJones
Check for missing files
.....
C:\WINDOWS\system32\AUTOEXEC.NT not there
.....
End check for missing files
.....
Please post this in the forum
Please download this and follow instructions (select correct operating system and install file) -> http://www.tech-forums.net/computer/topic/29806.html
After that, re-run qlocate.bat and send its log here.
Still seems to be failing.
Check for missing files
.....
C:\WINDOWS\system32\AUTOEXEC.NT not there
.....
End check for missing files
.....
Please post this in the forum
Check for missing files
.....
C:\WINDOWS\system32\AUTOEXEC.NT not there
.....
End check for missing files
.....
Please post this in the forum
Check for missing files
.....
C:\WINDOWS\system32\AUTOEXEC.NT not there
.....
End check for missing files
.....
Please post this in the forum
Save it on desktop, doubleclick it and click Unzip.
After that, re-run qlocate.bat and send its log here.
Okay, this time it went through
Wed 06/14/2006
Running from: C:\FindQool\FindQool
PLEASE NOTE: LEGIT FILES MIGHT BE LISTED. IF YOU ARE UNSURE OF WHAT IS LISTED LEAVE THEM ALONE.
Known file names
MD5 Check....
Files found with locate com.
Re-check using dir /a:-d
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
...
HKEY_LOCAL_MACHINE\software\classes\folder\shellex\columnhandlers\{ce3a44d8-bc88-4d62-a890-42d96245f8d6}
...
Runs, Listed here as a Doublecheck for the locate com results
HKLM
HKCU
...
Files In Winlogon shell and userinit
Listed here as a Doublecheck for the locate com results
shell REG_SZ Explorer.exe, C:\WINDOWS\system32\vqnsp.exe
userinit REG_SZ C:\WINDOWS\system32\userinit.exe,hmtwavy.exe
...
SWReg utility
Written by Bobbi Flekman © 2005
Findqool edited 17/05/2006
Uninstall via add/remove programs (control panel), if present:
Ebates_MoeMoneyMaker
FastSeeker
Open HijackThis, click do a system scan only, checkmark these and press fix checked:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file:\\C:\WINDOWS\system32\Searchx.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?Link...ge=about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=20065&k=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=20065&k=
R3 - URLSearchHook: (no name) - <default> - (no file)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\vqnsp.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,hmtwavy. exe
O4 - HKLM\..\Run: [SpyBlocs] C:\SpyBlocs.exe
O4 - HKLM\..\Run: [ptcajf] C:\WINDOWS\System32\plnqzn.exe
O4 - HKLM\..\Run: [ce8bd0cab6fa] C:\WINDOWS\System32\atmlib09.exe
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [5881ac371b9b] C:\WINDOWS\system32\ati2dvag.exe
O8 - Extra context menu item: &FastSeeker Search - res://C:\Program Files\FastSeeker\FastSeekerToolbar011203.dll/cmsearch.html
O9 - Extra button: eZ$hopper - {BFA03761-5565-41b3-93D9-82B354C0A8EC} - (no file)
O9 - Extra 'Tools' menuitem: eZ$hopper - {BFA03761-5565-41b3-93D9-82B354C0A8EC} - (no file)
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.ht m (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} - http://wdownload.weatherbug.com/mini...ansporter.cab?
O16 - DPF: {F1A51F21-59DF-4486-BA31-5B816DA481EB} - http://www.fastseeker.com/toolbar/do...eekerSetup.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\csrss.dll C:\WINDOWS\system32\mshta.dll
O23 - Service: Microsoft Performance WMI Adapter AddOn (WMIPervAddOn) - Unknown owner - C:\WINDOWS\wmiapsv.exe
Please click Start > Run and type in: services.msc
Click OK
In the Services window find: Microsoft Performance WMI Adapter AddOn (WMIPervAddOn)
Select/highlight and right click the entry, and choose: Properties
On the General tab, under Service Status click the Stop button
Beside: Startup Type, in the drop menu, select: Disabled
Click Apply, then OK
Now, go to Start > Run, and copy/paste the following into the Open box:
sc delete WMIPervAddOn
Click: OK
Please download the Killbox.
Unzip it to the desktop
Please run Killbox.
Copy the lines below at the same time:
C:\WINDOWS\system32\Searchx.htm
C:\SpyBlocs.exe
C:\WINDOWS\System32\plnqzn.exe
C:\WINDOWS\System32\atmlib09.exe
C:\WINDOWS\system32\ati2dvag.exe
C:\WINDOWS\system32\csrss.dll
C:\WINDOWS\system32\mshta.dll
C:\WINDOWS\wmiapsv.exe
Select "Delete on Reboot" and "all files"
Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.
If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try TheKillbox again..
If your computer does not restart automatically, please restart it manually.
Please download ewido anti-malware it is a free version of the program -> http://www.ewido.net/en/download/
1. Install ewido anti-malware
2. When installing, under "Additional Options" uncheck..
* Install background guard
* Install scan via context menu
3. Launch ewido, there should be an icon on your desktop, double-click it.
4. The program will now open to the main screen.
5. When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
6. You will need to update ewido to the latest definition files.
* On the left hand side of the main screen click update.
* Then click on Start Update.
7. The update will start and a progress bar will show the updates being installed.
(the status bar at the bottom will display ("Update successful")
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates -> http://download.ewido.net/ewido-signatures-full-current.exe Make sure to close Ewido before installing the update.
Once the updates are installed do the following:
Reboot your computer in SafeMode by doing the following:
1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the first option, to run Windows in Safe Mode.
Delete if found:
C:\Program Files\FastSeeker
C:\Program Files\Ebates_MoeMoneyMaker
Then launch ewido:
* Click on scanner
* Click on Complete System Scan and the scan will begin.
* You will be prompted to clean the first infection.
* Select "Perform action on all infections", then proceed.
* Once the scan has completed, there will be a button located on the bottom of the screen named Save report
* Click Save report.
* Save the report .txt file to your desktop or a location where you can find it easily.
Close ewido anti-malware.
Reboot back to normal mode
Send:
- ewido report
- a fresh HjT log
Hijack This Log
Logfile of HijackThis v1.99.1
Scan saved at 1:50:07 PM, on 6/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\devldr32.exe
G:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
C:\WINDOWS\system32\wpabaln.exe
G:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe
G:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file:\\C:\WINDOWS\system32\Searchx.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=20065&k=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=20065&k=
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,hmtwavy.exe
O4 - HKLM\..\Run: [SunServer] G:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://www.beqanna.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A96170D4-BFAA-4F6F-871F-B562EEDA8061}: NameServer = 63.245.131.21 63.245.131.22
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3A3602C-CE7E-4E8A-AED4-68B33B0754AB}: NameServer = 151.164.172.201
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
The ewido log will be in the second post, too long for this one. in fact may take too more lol, worry ^_^
ewido anti-malware - Scan report
+ Created on: 1:35:16 PM, 6/14/2006
+ Report-Checksum: EA52C52B
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{1ADBCCE8-CF84-441E-9B38-AFC7A19C06A4} -> Adware.ActivShopper : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3D782BB3-F2A5-11D3-BF4C-000000000000} -> Adware.ActivShopper : Cleaned with backup
HKLM\SOFTWARE\Classes\MP.MediaPops -> Adware.NetworkEssentials : Cleaned with backup
HKLM\SOFTWARE\Classes\MP.MediaPops\CLSID -> Adware.NetworkEssentials : Cleaned with backup
HKLM\SOFTWARE\Classes\MP.MediaPops\CurVer -> Adware.NetworkEssentials : Cleaned with backup
HKLM\SOFTWARE\Classes\MP.MediaPops.1 -> Adware.NetworkEssentials : Cleaned with backup
HKLM\SOFTWARE\Classes\pwrswmda.PWRSWMDA -> Adware.KeenValue : Cleaned with backup
HKLM\SOFTWARE\Classes\pwrswmda.PWRSWMDA\Clsid -> Adware.KeenValue : Cleaned with backup
HKU\.DEFAULT\Software\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKU\.DEFAULT\Software\DNS -> Adware.Shorty : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1ADBCCE8-CF84-441E-9B38-AFC7A19C06A4} -> Adware.ActivShopper : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{85A77577-A8CA-41B7-AA1E-DDAD4C0B12B1} -> Adware.LinkMaker : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{944864A5-3916-46E2-96A9-A2E84F3F1208} -> Adware.Accoona : Cleaned with backup
HKU\.DEFAULT\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-1935655697-113007714-854245398-1009\Software\Comet Systems -> Adware.CometCursor : Cleaned with backup
HKU\S-1-5-21-1935655697-113007714-854245398-1009\Software\Comet Systems\Features -> Adware.CometCursor : Cleaned with backup
HKU\S-1-5-21-1935655697-113007714-854245398-1009\Software\Comet Systems\Features\Adzap -> Adware.CometCursor : Cleaned with backup
HKU\S-1-5-21-1935655697-113007714-854245398-1009\Software\Comet Systems\Features\HistZap -> Adware.CometCursor : Cleaned with backup
HKU\S-1-5-21-1935655697-113007714-854245398-1009\Software\Microsoft\Internet Explorer\URLSearchHooks\{944864A5-3916-46E2-96A9-A2E84F3F1208} -> Adware.Accoona : Cleaned with backup
HKU\S-1-5-21-1935655697-113007714-854245398-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1ADBCCE8-CF84-441E-9B38-AFC7A19C06A4} -> Adware.ActivShopper : Cleaned with backup
HKU\S-1-5-21-1935655697-113007714-854245398-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{85A77577-A8CA-41B7-AA1E-DDAD4C0B12B1} -> Adware.LinkMaker : Cleaned with backup
HKU\S-1-5-21-1935655697-113007714-854245398-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{944864A5-3916-46E2-96A9-A2E84F3F1208} -> Adware.Accoona : Cleaned with backup
HKU\S-1-5-21-1935655697-113007714-854245398-1009\Software\Support Software -> Adware.NetworkEssentials : Cleaned with backup
HKU\S-1-5-21-1935655697-113007714-854245398-1009\Software\Support Software\Params -> Adware.NetworkEssentials : Cleaned with backup
HKU\S-1-5-18\Software\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-18\Software\DNS -> Adware.Shorty : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1ADBCCE8-CF84-441E-9B38-AFC7A19C06A4} -> Adware.ActivShopper : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{85A77577-A8CA-41B7-AA1E-DDAD4C0B12B1} -> Adware.LinkMaker : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{944864A5-3916-46E2-96A9-A2E84F3F1208} -> Adware.Accoona : Cleaned with backup
HKU\S-1-5-18\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
C:\!KillBox\ati2dvag.exe -> Adware.UrlSpy : Cleaned with backup
C:\!KillBox\atmlib09.exe -> Adware.IEDriver : Cleaned with backup
C:\!KillBox\csrss.dll -> Adware.PurityScan : Cleaned with backup
C:\!KillBox\mshta.dll -> Adware.PurityScan : Cleaned with backup
C:\!KillBox\wmiapsv.exe -> Backdoor.SdBot.aad : Cleaned with backup
C:\Crazy-Frog.Html -> Worm.Sumom.a : Cleaned with backup
:mozilla.6:C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\iaiue9qp.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.7:C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\iaiue9qp.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.9:C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\iaiue9qp.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.11:C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\iaiue9qp.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.12:C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\iaiue9qp.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
-> : Error during cleaning
:mozilla.19:C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\iaiue9qp.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.20:C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\iaiue9qp.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
C:\Documents and Settings\James\Cookies\james@kmpads[2].txt -> TrackingCookie.Kmpads : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Application Data\Sunbelt Software\CounterSpy\Quarantine\B2D3745A-5507-4BB4-A132-E714FC\8143817A-94A7-474D-8F75-3B7707 -> Downloader.Adload.bx : Cleaned with backup
C:\Documents and Settings\Linda\Cookies\linda@targetnet[1].txt -> TrackingCookie.Targetnet : Cleaned with backup
C:\Documents and Settings\Linda\Cookies\linda@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\LocalService\Application Data\Fоnts\netdde.exe -> Downloader.PurityScan.bx : Cleaned with backup
:mozilla.6:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\3c8r5e1w.default\cookies.txt -> TrackingCookie.Findwhat : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\system@ad.doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\system@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\system@banners.searchingbooth[1].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\system@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\system@install.bestoffersnetworks[2].txt -> TrackingCookie.Bestoffersnetworks : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\system@media.top-banners[1].txt -> TrackingCookie.Top-banners : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\system@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.128:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.129:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.136:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.137:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.138:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.139:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.142:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.143:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.145:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.166:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.167:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.168:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.172:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.173:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.174:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.175:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.176:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.179:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.180:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.181:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.182:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup
:mozilla.183:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup
:mozilla.191:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.192:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.193:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.194:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.195:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.196:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup
:mozilla.197:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup
:mozilla.198:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup
:mozilla.206:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.207:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.208:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.214:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.215:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.216:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.217:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.218:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.219:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.220:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.221:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.222:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.223:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.225:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.226:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.227:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.228:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.230:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.237:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.238:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.240:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.241:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.242:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.243:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.244:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.245:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.246:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.249:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.250:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.251:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.252:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.253:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Realtracker : Cleaned with backup
:mozilla.264:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.265:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.266:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.267:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.317:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
:mozilla.318:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.322:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.337:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.344:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.379:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.380:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.381:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.382:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.383:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.394:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Clickbank : Cleaned with backup
:mozilla.405:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.406:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.407:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.408:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.409:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.410:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.411:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.412:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.413:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.417:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.418:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.442:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.443:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.447:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.448:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.449:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.450:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.451:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.452:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.461:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.462:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.466:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup
:mozilla.467:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.516:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.517:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.518:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.519:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.537:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.538:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.544:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.569:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.574:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.576:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.577:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.578:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.580:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.581:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.582:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.583:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.584:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.585:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.586:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.604:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.605:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.617:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.639:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Starware : Cleaned with backup
:mozilla.640:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Starware : Cleaned with backup
:mozilla.641:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Starware : Cleaned with backup
:mozilla.645:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.646:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.649:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup
:mozilla.650:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.651:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.652:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.653:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.654:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.655:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.656:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.672:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.675:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.696:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.704:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.710:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.712:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.713:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.716:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.717:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\dgl2kr44.Kcat\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup
:mozilla.153:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.163:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.164:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.166:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.167:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.169:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.187:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.188:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.209:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.210:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.211:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.212:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.213:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.214:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.215:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.221:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.222:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.223:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.224:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.225:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.227:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.228:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.229:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.231:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.232:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.233:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.234:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.235:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.236:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.237:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.238:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.239:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.240:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.241:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.242:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.243:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.244:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.245:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.246:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.247:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.248:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.249:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.250:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.251:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.262:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.263:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.264:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.265:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.266:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.267:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.300:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.301:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.302:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.303:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.304:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.306:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.308:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.309:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.310:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.317:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.318:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.319:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.323:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.324:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.325:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.326:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.327:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Enhance : Cleaned with backup
:mozilla.333:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.334:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.335:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.339:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.340:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.341:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.342:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.343:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.344:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.345:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.346:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.360:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.361:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.362:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.363:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.364:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.365:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.377:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.378:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.389:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
:mozilla.394:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.395:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.396:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.397:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.438:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.441:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.442:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.443:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.449:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.463:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.464:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.465:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.466:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.467:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.468:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.476:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.479:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.481:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.482:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.483:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.501:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.509:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.513:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.514:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.531:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup
:mozilla.561:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Spylog : Cleaned with backup
:mozilla.563:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.567:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.587:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.590:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Tracking101 : Cleaned with backup
:mozilla.592:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.593:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.594:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.595:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.596:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.597:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.598:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.619:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.620:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.621:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.634:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.660:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.661:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.662:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.668:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.675:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.684:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned with backup
:mozilla.690:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.691:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.707:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup
:mozilla.708:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup
:mozilla.720:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.721:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.724:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.725:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.755:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup
:mozilla.756:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup
:mozilla.760:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.761:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.766:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.767:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.768:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.793:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.794:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.814:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.829:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Adviva : Cleaned with backup
:mozilla.830:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Adviva : Cleaned with backup
:mozilla.854:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.886:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned with backup
:mozilla.890:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned with backup
:mozilla.900:C:\Documents and Settings\Nichole.KIDSMACHINE\Application Data\Mozilla\Firefox\Profiles\kmj9p149.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Nichole.KIDSMACHINE\Cookies\nichole@adorigin[1].txt -> TrackingCookie.Adorigin : Cleaned with backup
C:\Documents and Settings\Nichole.KIDSMACHINE\Cookies\nichole@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Nichole.KIDSMACHINE\Cookies\nichole@ads.trafficvenue[1].txt -> TrackingCookie.Trafficvenue : Cleaned with backup
C:\Documents and Settings\Nichole.KIDSMACHINE\Cookies\nichole@ads18.bpath[2].txt -> TrackingCookie.Bpath : Cleaned with backup
C:\Documents and Settings\Nichole.KIDSMACHINE\Cookies\nichole@kmpads[2].txt -> TrackingCookie.Kmpads : Cleaned with backup
C:\Documents and Settings\Nichole.KIDSMACHINE\Cookies\nichole@pro-market[1].txt -> TrackingCookie.Pro-market : Cleaned with backup
C:\Documents and Settings\Nichole.KIDSMACHINE\Cookies\nichole@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Nichole.KIDSMACHINE\Cookies\nichole@www.adultbooks.com.22792.fb.dbbsrv[2].txt -> TrackingCookie.Dbbsrv : Cleaned with backup
C:\Documents and Settings\Nichole.KIDSMACHINE\Cookies\nichole@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Nichole.KIDSMACHINE\Cookies\nichole@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\Nichole.KIDSMACHINE\Cookies\nichole@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Nichole.KIDSMACHINE\Local Settings\Application Data\Sunbelt Software\CounterSpy\Quarantine\20BB0F35-96D5-45D0-BD53-4874E0\BF6AA14B-7A7A-4AC0-9270-FD82CC -> Adware.Suggestor : Cleaned with backup
C:\Documents and Settings\Nichole.KIDSMACHINE\Local Settings\Application Data\Sunbelt Software\CounterSpy\Quarantine\72470E78-3D97-40A6-AE3A-EE03ED\C4CD4C1B-7715-41F6-9096-A02FA3 -> Downloader.Qoologic.bj : Cleaned with backup
C:\Documents and Settings\Nichole.KIDSMACHINE\Local Settings\Application Data\Sunbelt Software\CounterSpy\Quarantine\72470E78-3D97-40A6-AE3A-EE03ED\F0098BAB-14AF-4269-998C-81F069 -> Downloader.Qoologic.bj : Cleaned with backup
C:\Documents and Settings\Nichole.KIDSMACHINE\Local Settings\Application Data\Sunbelt Software\CounterSpy\Quarantine\72470E78-3D97-40A6-AE3A-EE03ED\F99907BB-970E-4ADB-A61E-2FB138 -> Downloader.Qoologic.bj : Cleaned with backup
C:\Documents and Settings\Nichole.KIDSMACHINE\Local Settings\Application Data\Sunbelt Software\CounterSpy\Quarantine\CBFD6FAB-A639-40BF-BF3E-D312EE\B526E37F-FBBC-4EE5-A8A8-1841AF -> Adware.Suggestor : Cleaned with backup
C:\Documents and Settings\Nichole.KIDSMACHINE\Local Settings\Application Data\Sunbelt Software\CounterSpy\Quarantine\E3D6DFB9-1FCD-44A3-BF9E-48E8F0\CA2E33F1-100C-4CC9-B9CE-83ECDA -> Adware.Look2Me : Cleaned with backup
C:\Documents and Settings\Nichole.KIDSMACHINE\Local Settings\Temporary Internet Files\Content.IE5\OD2VS9E7\AppWrap[1].exe -> Adware.Zestyfind : Cleaned with backup
C:\Program Files\Common Files\ѕуstem32\ntvdm.exe -> Downloader.PurityScan.cl : Cleaned with backup
C:\Program Files\Lycos\Sidesearch\ClrSchUninstall_78_86.exe -> Adware.ClearSearch : Cleaned with backup
C:\Program Files\Lycos\Sidesearch\sidesearch1410.dll -> Adware.Sidesearch : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\1F2D1B14-8F85-4640-8020-1B2B7C\397DC0D7-16BF-404F-9474-B080E2 -> Downloader.Braidupdate.d : Cleaned with backup
C:\Program Files\Οracle\dllhost.exe -> Adware.PurityScan : Cleaned with backup
C:\RECYCLER\S-1-5-21-1935655697-113007714-854245398-1004\Dc7\_SUPERBAR.dll -> Adware.GigatechSuperBar : Cleaned with backup
C:\winbooter.exe -> Downloader.Adload.bo : Cleaned with backup
C:\winbootini.exe -> Downloader.Adload.bo : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\WUInst.dll -> Adware.SaveNow : Cleaned with backup
C:\WINDOWS\errorfix.exe -> Downloader.Adload.bo : Cleaned with backup
C:\WINDOWS\iczkat.exe -> Hijacker.VB.ca : Cleaned with backup
C:\WINDOWS\loads.exe -> Hijacker.VB.ek : Cleaned with backup
C:\WINDOWS\mazbcjtqw.exe -> Downloader.VB.ec : Cleaned with backup
C:\WINDOWS\mm19.ocx -> Downloader.VB.db : Cleaned with backup
C:\WINDOWS\msnupdate.exe -> Downloader.Adload.bq : Cleaned with backup
C:\WINDOWS\Mvussycrh.phx\sah.exe -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\roing18.ocx -> Downloader.VB.bo : Cleaned with backup
C:\WINDOWS\system\N0.exe -> Downloader.Small.rg : Cleaned with backup
C:\WINDOWS\system\Sleep.exe -> Trojan.VB.el : Cleaned with backup
C:\WINDOWS\system\Update_Hosts.DLL -> Adware.IGetNet : Cleaned with backup
C:\WINDOWS\system32\adsnw795.exe -> Downloader.Agent.adz : Cleaned with backup
C:\WINDOWS\system32\kwinmqez.exe -> Adware.ZenoSearch : Cleaned with backup
C:\WINDOWS\system32\msguard.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mwinsqez.exe -> Adware.ZenoSearch : Cleaned with backup
C:\WINDOWS\system32\nouse.txt -> Adware.ZenoSearch : Cleaned with backup
C:\WINDOWS\system32\qwinlqez.exe -> Adware.ZenoSearch : Cleaned with backup
C:\WINDOWS\system32\shell.exe -> Worm.Kelvir.bq : Cleaned with backup
C:\WINDOWS\system32\WkvZ063.exe -> Downloader.VB.em : Cleaned with backup
C:\WINDOWS\Temp\TMP0000001691BBB3A59BFF3DF8 -> Adware.CommAd : Cleaned with backup
C:\WINDOWS\Temp\TMP00000033A89C7118F0B0185B -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\ymdawcj.exe -> Downloader.VB.do : Cleaned with backup
C:\WINDOWS\Тasks\taskmgr.exe -> Adware.ClickSpring : Cleaned with backup
C:\winexplore.exe -> Downloader.Adload.bo : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@a.as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@ad-flow[2].txt -> TrackingCookie.Ad-flow : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@ad-logics[1].txt -> TrackingCookie.Ad-logics : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@adnetintads.valuead[1].txt -> TrackingCookie.Valuead : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@adorigin[1].txt -> TrackingCookie.Adorigin : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@ads.specificpop[2].txt -> TrackingCookie.Specificpop : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@ads.trafficvenue[1].txt -> TrackingCookie.Trafficvenue : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@ads.x10[2].txt -> TrackingCookie.X10 : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@ads18.bpath[2].txt -> TrackingCookie.Bpath : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@adserv.internetfuel[1].txt -> TrackingCookie.Internetfuel : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@bfast[1].txt -> TrackingCookie.Bfast : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@bis.180solutions[1].txt -> TrackingCookie.180solutions : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@centrport[1].txt -> TrackingCookie.Centrport : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@citi.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@clickagents[2].txt -> TrackingCookie.Clickagents : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@commission-junction[1].txt -> TrackingCookie.Commission-junction : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@com[2].txt -> TrackingCookie.Com : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@counter.hitslink[2].txt -> TrackingCookie.Hitslink : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@data.coremetrics[2].txt -> TrackingCookie.Coremetrics : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@dbbsrv[1].txt -> TrackingCookie.Dbbsrv : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@ehg-careerbuilder.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@ehg-legonewyorkinc.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@ehg-tekzoned.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@euniverseads[1].txt -> TrackingCookie.Euniverseads : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@gator[2].txt -> TrackingCookie.Gator : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@hg1.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@hotlog[1].txt -> TrackingCookie.Hotlog : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@hypertracker[1].txt -> TrackingCookie.Hypertracker : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@linksynergy[1].txt -> TrackingCookie.Linksynergy : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@mediatrack.popupsponsor[1].txt -> TrackingCookie.Popupsponsor : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@mediatrack.revenue[1].txt -> TrackingCookie.Revenue : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@overture[2].txt -> TrackingCookie.Overture : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@paycounter[1].txt -> TrackingCookie.Paycounter : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@phg.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@popupsponsor[2].txt -> TrackingCookie.Popupsponsor : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@pro-market[2].txt -> TrackingCookie.Pro-market : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@qksrv[1].txt -> TrackingCookie.Qksrv : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@rccl.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@revenue[1].txt -> TrackingCookie.Revenue : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@servedfor.valuead[1].txt -> TrackingCookie.Valuead : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@specificpop[2].txt -> TrackingCookie.Specificpop : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@stat.onestat[2].txt -> TrackingCookie.Onestat : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@targetnet[2].txt -> TrackingCookie.Targetnet : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@tpl1.realtracker[1].txt -> TrackingCookie.Realtracker : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@track-star[1].txt -> TrackingCookie.Track-star : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@w131.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@w132.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@web1.realtracker[1].txt -> TrackingCookie.Realtracker : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@webpdp.gator[2].txt -> TrackingCookie.Gator : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@www.adultbooks.com.22792.fb.dbbsrv[2].txt -> TrackingCookie.Dbbsrv : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@www.paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@www1.paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@www3.paypopup[2].txt -> TrackingCookie.Paypopup : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@xxxcounter[2].txt -> TrackingCookie.Xxxcounter : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@z1.adserver[2].txt -> TrackingCookie.Adserver : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Cookies\nichole@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Local Settings\Temp\Cookies\nichole@adnetintads.valuead[1].txt -> TrackingCookie.Valuead : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Local Settings\Temp\Cookies\nichole@ads.specificpop[2].txt -> TrackingCookie.Specificpop : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Local Settings\Temp\Cookies\nichole@advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Local Settings\Temp\Cookies\nichole@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Local Settings\Temp\Cookies\nichole@clickagents[1].txt -> TrackingCookie.Clickagents : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Local Settings\Temp\Cookies\nichole@overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Local Settings\Temp\Cookies\nichole@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Local Settings\Temp\Cookies\nichole@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Local Settings\Temp\Cookies\nichole@www.qksrv[1].txt -> TrackingCookie.Qksrv : Cleaned with backup
G:\Nichole\Nichole.KIDSMACHINE\Local Settings\Temp\Cookies\nichole@x10[1].txt -> TrackingCookie.X10 : Cleaned with backup
::Report End
Disable CounterSpy according to these instructions temporarily ->
http://wiki.castlecops.com/Malware_Removal:_Temporarily_Disable_Real_Time_Monitoring_Programs#CounterSpy
After that:
Open HijackThis, click do a system scan only, checkmark these and press fix checked:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file:\\C:\WINDOWS\system32\Searchx.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=20065&k=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=20065&k=
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,hmtwavy. exe
Reboot
Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
o Scan using the following Anti-Virus database:
+ Extended (If available otherwise Standard)
o Scan Options:
+ Scan Archives
+ Scan Mail Bases
Send:
- a fresh HjT log
- kaspersky report