Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

%SystemDrive% Folder on Desktop [RESOLVED]


  • This topic is locked This topic is locked

#1
tranquil

tranquil

    Member

  • Member
  • PipPip
  • 11 posts
A while ago, a folder named %SystemDrive% mysteriously arrived on my desktop. At about that time, I started having trouble with my system, especially my browser, which just keeps having errors and exiting by itself. I usually use IE. A friend said that this sounded like malware that he had heard of. He downloaded Firefox for me so that I could use my computer and told me about geeks to go.

I hope that you can help me. I have downloaded HijackThis! and used it to prepare a log, which I have pasted in below. Thank you for trying to help me.

Logfile of HijackThis v1.99.1
Scan saved at 8:50:56 AM, on 8/23/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WMP54Gv4.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\sabine\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ku.edu/
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SDWin32 Class - {710FF7E8-82AD-41C2-A9C7-05FFDBD29AEB} - C:\WINNT\system32\bnbko.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PnIEBrowserHelperObj Class - {D2F719F3-106A-402B-9996-3A5B12ACA564} - C:\Program Files\Failsafe\GuardIE\PnIE.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Guard-IE - {37C8204D-97C3-4127-BB28-1BFF3FA2F7DA} - C:\Program Files\Failsafe\GuardIE\PnIE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [local epson] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P11 "local epson" /O5 "LPT1:" /M "Stylus Photo 825"
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo 825] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P22 "EPSON Stylus Photo 825" /O5 "LPT1:" /M "Stylus Photo 825"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [HP Lamp] C:\SCANJET\PrecisionScanPro\HPLamp.exe
O4 - HKLM\..\Run: [\\KERMIT\EPSON Stylus Photo 825] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P31 "\\KERMIT\EPSON Stylus Photo 825" /O6 "USB001" /M "Stylus Photo 825"
O4 - HKLM\..\Run: [Ad-watch] "D:\Program Files\aaw6plus\Ad-watch.exe"
O4 - HKLM\..\Run: [LifeScape Media Detector] C:\Program Files\Picasa\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: @C:\Program Files\Failsafe\GuardIE\PnIE.dll,-100 - {BDD75188-2FC0-4099-909F-AA8D432BE037} - C:\Program Files\Failsafe\GuardIE\PnIE.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Failsafe\GuardIE\PnIE.dll,-100 - {BDD75188-2FC0-4099-909F-AA8D432BE037} - C:\Program Files\Failsafe\GuardIE\PnIE.dll
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ChatSpace Full Java Client 3.1.0.218 - http://msworld.chats...va/cfs31218.cab
O16 - DPF: ChatSpace Java Client 2.1.0.90 - http://msworld.chats...va/cs4ms090.cab
O16 - DPF: Yahoo! Literati - http://download.game...nts/y/tt3_x.cab
O16 - DPF: Yahoo! MahJong - http://download.game...nts/y/ot0_x.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.game...s/y/mjst4_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.game...ts/y/pyt1_x.cab
O16 - DPF: {0122955E-1FB0-11D2-A238-006097FAEE8B} (CscClnt Class) - http://205.159.125.1...everContent.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative....015/CTSUEng.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/i...etup1.0.0.6.exe
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec....sa/LSSupCtl.cab
O16 - DPF: {29EEFF42-F3FA-11D5-A9D5-00500413153C} (DFRun Class) - http://webpdp.gator....bpdpgeneric.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgree...eensActivia.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://sabinesthough...ad/MsnPUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.r...ip/RdxIE601.cab
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifes...ll/pinstall.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1151942947613
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/...me/ZAxRcMgr.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn...ro.cab34246.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec....sa/SymAData.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.app.../ITDetector.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.game...aploader_v6.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/...s/msnchat45.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative....15016/CTPID.cab
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINNT\system32\CTsvcCDA.EXE (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe" "WMP54Gv4.exe (file missing)
  • 0

Advertisements


#2
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,131 posts
Hello Sabine and welcome to Geeks to Go

Apologies for your wait but it has been very busy here just lately at a time when many volunteers are holidaying.

As an introduction, please note that I am not Superhuman, I do not know everything, but what I do know has taken me years to learn. I am happy to pass on this information to you, but please bear in mind that I am also fallible.

Please note that you should have Administrator rights to perform the fixes. Also note that multiple identity PC’s (family PC’s) present a different problem; please tell me if your PC has more than one individual’s setting, but continue with the fix.

Before we get underway, you may wish to print these instructions for easy reference during the fix, although please be aware that many of the required URLs are hyperlinks in the red names shown on your screen.

You have a mixture of malware. Let’s see what we can do.

To start please download the following programmes, we will run them later. Please save them to a place that you will remember, I suggest the Desktop:

CCleaner
Ewido Anti Spyware
combofix.exe

Please install, and update Ewido anti-spyware
  • Load Ewido and then click the Update tab at the top. Under Manual Update click Start update.
  • After the update finishes (the status bar at the bottom will display "Update successful")
  • Please select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
  • Select "Automatically generate report after every scan"
  • Deselect "Only if threats were found"
  • Close Ewido. Do not run it yet.
Next, please reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
For additional help in booting into Safe Mode, see the following site:

Safe Mode

  • In Safe Mode, load Ewido and click on the Scanner tab at the top and then click on Complete System Scan. This scan can take quite a while to run, so be patient.
  • Ewido will list any infections found on the left hand side. When the scan has finished, it will automatically set the recommended action. Click the Apply all actions button. Ewido will display "All actions have been applied" on the right hand side.
  • Click on "Save Report", then "Save Report As". This will create a text file. Make sure you know where to find this file again (I suggest the Desktop).
  • Please ensure you post that log in your reply.
Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

R3 - Default URLSearchHook is missing
O2 - BHO: SDWin32 Class - {710FF7E8-82AD-41C2-A9C7-05FFDBD29AEB} - C:\WINNT\system32\bnbko.dll (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/i...etup1.0.0.6.exe
O16 - DPF: {29EEFF42-F3FA-11D5-A9D5-00500413153C} (DFRun Class) - http://webpdp.gator....bpdpgeneric.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.r...ip/RdxIE601.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.game...aploader_v6.cab

Now close all windows other than HiJackThis, then click Fix Checked. Please now reboot into normal mode.

There is almost certainly bound to be some junk (leftover bits and pieces) on your system that is doing nothing but taking up space. I would recommend that you run CCleaner. Install it, check the default setting in the left-hand pane, ensure you uncheck old prefetch data found under the system tab, and under the heading of Applications uncheck Ewido Security Suite log then click Analyze> Run Cleaner. You may be fairly surprised by how much it finds. Also click Issues then Scan for issues – fix selected issues

Double click combofix.exe & follow the prompts.

When it has finished, it will produce a log. Please post that log in your next reply.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Post back a fresh HijackThis log (from normal mode) and I will take another look. (3 logs in total please).
  • 0

#3
tranquil

tranquil

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Hi! Thanks very much for getting back to me. I am sorry that it has been so busy for you. There are a lot of destructive people in the workd. I have read your instructions and downloaded the programs. Ewido installed without difficulty. I followed all the instructions. Then I rebooted into Safe Mode.

When in Safe Mode, I ran a full system scan using Ewido. I had it apply changes and then had it save a report. It found 47 objects, 134 traces, which I let the program take care of as you said to. I wonder why Adaware SE is not finding these?

I then ran HijackThis! and did as you said. During that process, it asked to quarantine an archive (I think it said archive) and I told it yes. Then I rebooted back into normal mode.

I installed and ran cccleaner.I could not find a "Default" setting or button on the left or anywhere else. Maybe they have changed the program. So I assumed that the default seting is the way it is when it first runs and didn't change anything. It did not say anything about saving a log, so I copied the contents of the right-hand program pane into notepad and saved it.

Then I ran ComboFix and save the log that it produced. I think that makes four logs in all, since there were two HijackThis! logs. I will identify and paste each of them in below.

I should note, I suppose, that the %SystemDrive%" folder is still on my desktop.

I have a doctors appointment this afternoon and I probably won't get back to this until early this evening.

Thanks for all your help so far!

Sabine

Here is the log from running Ewido:

---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 12:11:25 PM 8/29/2006

+ Scan result:



HKLM\SOFTWARE\Classes\SWLAD1.SWLAD -> Adware.AdDestroyer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\SWLAD1.SWLAD\Clsid -> Adware.AdDestroyer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\SecureWin -> Adware.Adlogix : Cleaned with backup (quarantined).
C:\WINNT\system32\bnbkof.exe -> Adware.Adstart : Cleaned with backup (quarantined).
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Local Settings\Temp\THI1EE2.tmp\adremtm3.cab/remtm3.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\windows\bundles\vl_ezstub.exe -> Adware.EZula : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Application Data\ShopperReports -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Application Data\ShopperReports\cs -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Application Data\ShopperReports\cs\Config.xml -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Application Data\ShopperReports\cs\db -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Application Data\ShopperReports\cs\db\Aliases.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Application Data\ShopperReports\cs\db\Sites.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Application Data\ShopperReports\cs\dwld -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Application Data\ShopperReports\cs\dwld\WhiteList.xip -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Application Data\ShopperReports\cs\persist.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Application Data\ShopperReports\cs\res1 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Application Data\ShopperReports\cs\res1\whitelist.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Application Data\ShopperReports\shprrprt.log -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Local Settings\Temp\ICD3.tmp\hbinstie.dll -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\ShopperReports -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\ShopperReports\Bin -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\ShopperReports\Bin\1.0.0.1 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\hotbar -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\hotbar\bin -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\hotbar\bin\4.5.3.0 -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\ShopperReports -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\ShopperReports\cs -> Adware.HotBar : Cleaned with backup (quarantined).
HKU\S-1-5-21-1960408961-152049171-854245398-1000\Software\ShopperReports -> Adware.HotBar : Cleaned with backup (quarantined).
HKU\S-1-5-21-1960408961-152049171-854245398-1000\Software\ShopperReports\cs -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
C:\WINNT\system32\70tovmto.ini -> Adware.Sahat : Cleaned with backup (quarantined).
HKU\S-1-5-21-1960408961-152049171-854245398-1000\Software\Bundles -> Adware.SecondThought : Cleaned with backup (quarantined).
C:\Program Files\Windows AdStatus\WinStatComm.dll -> Adware.WinAD : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\WinStatX.Installer -> Adware.WinTaskAd : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\WinStatX.Installer\CLSID -> Adware.WinTaskAd : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Local Settings\Temp\THI3317.tmp\wupdt.exe -> Downloader.Intexp.b : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Local Settings\Temp\THIFC6.tmp\wupdt.exe -> Downloader.Intexp.b : Cleaned with backup (quarantined).
C:\windows\bundles\shopinst.exe -> Downloader.Small.wj : Cleaned with backup (quarantined).
C:\windows\bundles\HelperInstaller.exe -> Dropper.Delf.z : Cleaned with backup (quarantined).
C:\windows\bundles\saie1101.exe -> Dropper.Small.sc : Cleaned with backup (quarantined).
C:\windows\bundles\traspec7.exe -> Dropper.Small.sc : Cleaned with backup (quarantined).
:mozilla.17:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.18:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.19:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.20:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.21:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.22:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.23:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.62:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Cookies\sabine@abetterinternet[1].txt -> TrackingCookie.Abetterinternet : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Cookies\sabine@abetterinternet[3].txt -> TrackingCookie.Abetterinternet : Cleaned with backup (quarantined).
:mozilla.427:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.429:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.402:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Admarketplace : Cleaned with backup (quarantined).
:mozilla.337:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.338:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.301:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
:mozilla.302:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
:mozilla.25:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.26:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.27:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.28:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.29:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.66:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.268:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.658:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.659:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.660:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Cookies\sabine@com[1].txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.223:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup (quarantined).
:mozilla.313:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup (quarantined).
:mozilla.16:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.266:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined).
:mozilla.267:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined).
:mozilla.269:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined).
:mozilla.270:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined).
:mozilla.271:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined).
:mozilla.159:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.259:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.260:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.261:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.262:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.346:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
:mozilla.351:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
:mozilla.276:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.277:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.278:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.303:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.304:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.194:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
:mozilla.195:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.235:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.236:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.237:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.238:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt -> TrackingCookie.Popuptraffic : Cleaned with backup (quarantined).
:mozilla.513:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Preferences : Cleaned with backup (quarantined).
:mozilla.514:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Preferences : Cleaned with backup (quarantined).
:mozilla.657:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Preferences : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt -> TrackingCookie.Preferences : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Cookies\sabine@preferences[2].txt -> TrackingCookie.Preferences : Cleaned with backup (quarantined).
:mozilla.32:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.33:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.226:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
:mozilla.227:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
:mozilla.228:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
:mozilla.229:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
:mozilla.230:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
:mozilla.86:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.87:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.88:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.224:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.225:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.234:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.252:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.385:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.255:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.256:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.257:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.258:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.184:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined).
:mozilla.482:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
:mozilla.593:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
:mozilla.594:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
:mozilla.702:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
:mozilla.398:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.399:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.134:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.135:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.136:C:\Documents and Settings\sabine\Application Data\Mozilla\Firefox\Profiles\3vkf56ts.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).


::Report end

Here is the log from the first HijackThis run:

Logfile of HijackThis v1.99.1
Scan saved at 12:13:39 PM, on 8/29/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Documents and Settings\sabine\Desktop\System Tools - Kermit\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ku.edu/
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SDWin32 Class - {710FF7E8-82AD-41C2-A9C7-05FFDBD29AEB} - C:\WINNT\system32\bnbko.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PnIEBrowserHelperObj Class - {D2F719F3-106A-402B-9996-3A5B12ACA564} - C:\Program Files\Failsafe\GuardIE\PnIE.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Guard-IE - {37C8204D-97C3-4127-BB28-1BFF3FA2F7DA} - C:\Program Files\Failsafe\GuardIE\PnIE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [local epson] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P11 "local epson" /O5 "LPT1:" /M "Stylus Photo 825"
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo 825] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P22 "EPSON Stylus Photo 825" /O5 "LPT1:" /M "Stylus Photo 825"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [HP Lamp] C:\SCANJET\PrecisionScanPro\HPLamp.exe
O4 - HKLM\..\Run: [\\KERMIT\EPSON Stylus Photo 825] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P31 "\\KERMIT\EPSON Stylus Photo 825" /O6 "USB001" /M "Stylus Photo 825"
O4 - HKLM\..\Run: [Ad-watch] "D:\Program Files\aaw6plus\Ad-watch.exe"
O4 - HKLM\..\Run: [LifeScape Media Detector] C:\Program Files\Picasa\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: @C:\Program Files\Failsafe\GuardIE\PnIE.dll,-100 - {BDD75188-2FC0-4099-909F-AA8D432BE037} - C:\Program Files\Failsafe\GuardIE\PnIE.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Failsafe\GuardIE\PnIE.dll,-100 - {BDD75188-2FC0-4099-909F-AA8D432BE037} - C:\Program Files\Failsafe\GuardIE\PnIE.dll
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ChatSpace Full Java Client 3.1.0.218 - http://msworld.chats...va/cfs31218.cab
O16 - DPF: ChatSpace Java Client 2.1.0.90 - http://msworld.chats...va/cs4ms090.cab
O16 - DPF: Yahoo! Literati - http://download.game...nts/y/tt3_x.cab
O16 - DPF: Yahoo! MahJong - http://download.game...nts/y/ot0_x.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.game...s/y/mjst4_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.game...ts/y/pyt1_x.cab
O16 - DPF: {0122955E-1FB0-11D2-A238-006097FAEE8B} (CscClnt Class) - http://205.159.125.1...everContent.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative....015/CTSUEng.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/i...etup1.0.0.6.exe
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec....sa/LSSupCtl.cab
O16 - DPF: {29EEFF42-F3FA-11D5-A9D5-00500413153C} (DFRun Class) - http://webpdp.gator....bpdpgeneric.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgree...eensActivia.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://sabinesthough...ad/MsnPUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.r...ip/RdxIE601.cab
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifes...ll/pinstall.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1151942947613
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/...me/ZAxRcMgr.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn...ro.cab34246.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec....sa/SymAData.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.app.../ITDetector.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.game...aploader_v6.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/...s/msnchat45.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative....15016/CTPID.cab
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINNT\system32\CTsvcCDA.EXE (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe" "WMP54Gv4.exe (file missing)

Here is the log from CCCleaner:

CLEANING COMPLETE - (16.196 secs)
------------------------------------------------------------------------------------------
264.4MB removed.
------------------------------------------------------------------------------------------

Details of files deleted
------------------------------------------------------------------------------------------
IE Temporary Internet Files (242 files) 3.83MB
Cookie:[email protected]/(&H100001) 1.13KB
Cookie:[email protected]/(&H100001) 1.00KB
Cookie:[email protected]/(&H100001) 213 bytes
C:\Documents and Settings\sabine\Cookies\sabine@superpages[1].txt 193 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 107 bytes
C:\Documents and Settings\sabine\Cookies\sabine@google[1].txt 109 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ljworld[1].txt 78 bytes
C:\Documents and Settings\sabine\Cookies\sabine@inetfast[1].txt 79 bytes
C:\Documents and Settings\sabine\Cookies\sabine@casino-trade[2].txt 217 bytes
C:\Documents and Settings\sabine\Cookies\sabine@veritodvc[1].txt 173 bytes
C:\Documents and Settings\sabine\Cookies\sabine@cnet[2].txt 236 bytes
C:\Documents and Settings\sabine\Cookies\sabine@webmd[1].txt 147 bytes
C:\Documents and Settings\sabine\Cookies\sabine@zdnet[2].txt 215 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 109 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 69 bytes
C:\Documents and Settings\sabine\Cookies\sabine@S0011-00-11-22-152721-37762[1].txt 655 bytes
C:\Documents and Settings\sabine\Cookies\sabine@citysearch[1].txt 107 bytes
C:\Documents and Settings\sabine\Cookies\sabine@livestat[1].txt 88 bytes
C:\Documents and Settings\sabine\Cookies\sabine@midiario20[1].txt 219 bytes
C:\Documents and Settings\sabine\Cookies\sabine@bribon911[1].txt 175 bytes
C:\Documents and Settings\sabine\Cookies\sabine@sportingnews[2].txt 181 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 301 bytes
C:\Documents and Settings\sabine\Cookies\sabine@characteristics[1].txt 313 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 132 bytes
C:\Documents and Settings\sabine\Cookies\sabine@yahoo[2].txt 167 bytes
C:\Documents and Settings\sabine\Cookies\sabine@jumacari24[1].txt 261 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 69 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 71 bytes
C:\Documents and Settings\sabine\Cookies\sabine@nordstrom[3].txt 198 bytes
C:\Documents and Settings\sabine\Cookies\sabine@jcp[1].txt 82 bytes
C:\Documents and Settings\sabine\Cookies\sabine@tvguide[1].txt 1015 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 279 bytes
C:\Documents and Settings\sabine\Cookies\sabine@jcp[2].txt 177 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 147 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 152 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 115 bytes
C:\Documents and Settings\sabine\Cookies\sabine@cnn[2].txt 485 bytes
C:\Documents and Settings\sabine\Cookies\sabine@cnnaudience[1].txt 93 bytes
C:\Documents and Settings\sabine\Cookies\sabine@_cqr[1].txt 1.15KB
C:\Documents and Settings\sabine\Cookies\sabine@altavista[1].txt 101 bytes
C:\Documents and Settings\sabine\Cookies\sabine@spiegel[1].txt 210 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 124 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ahealthyme[1].txt 102 bytes
C:\Documents and Settings\sabine\Cookies\sabine@topic[1].txt 75 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][4].txt 227 bytes
C:\Documents and Settings\sabine\Cookies\sabine@google[4].txt 127 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 107 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 66 bytes
C:\Documents and Settings\sabine\Cookies\sabine@autoweb[1].txt 245 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 108 bytes
C:\Documents and Settings\sabine\Cookies\sabine@techtv[1].txt 110 bytes
C:\Documents and Settings\sabine\Cookies\sabine@l2m[1].txt 80 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 103 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ki[1].txt 80 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ureach[1].txt 89 bytes
C:\Documents and Settings\sabine\Cookies\sabine@pathfinder[1].txt 98 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 140 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 69 bytes
C:\Documents and Settings\sabine\Cookies\sabine@sabinesthoughts[1].txt 223 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 330 bytes
C:\Documents and Settings\sabine\Cookies\sabine@barnesandnoble[1].txt 309 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 151 bytes
C:\Documents and Settings\sabine\Cookies\sabine@allrecipes[1].txt 105 bytes
C:\Documents and Settings\sabine\Cookies\sabine@spencergifts[1].txt 108 bytes
C:\Documents and Settings\sabine\Cookies\sabine@about[1].txt 213 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 106 bytes
C:\Documents and Settings\sabine\Cookies\sabine@avenuea[2].txt 93 bytes
C:\Documents and Settings\sabine\Cookies\sabine@timeinc[1].txt 94 bytes
C:\Documents and Settings\sabine\Cookies\sabine@234[1].txt 74 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 110 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 176 bytes
C:\Documents and Settings\sabine\Cookies\sabine@net-on[1].txt 58 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 69 bytes
C:\Documents and Settings\sabine\Cookies\sabine@amazon[3].txt 350 bytes
C:\Documents and Settings\sabine\Cookies\sabine@amazon[1].txt 350 bytes
C:\Documents and Settings\sabine\Cookies\sabine@review[1].txt 280 bytes
C:\Documents and Settings\sabine\Cookies\sabine@americangreetings[1].txt 272 bytes
C:\Documents and Settings\sabine\Cookies\sabine@iwin[2].txt 613 bytes
C:\Documents and Settings\sabine\Cookies\sabine@Cookie[2].txt 100 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 135 bytes
C:\Documents and Settings\sabine\Cookies\sabine@go[2].txt 149 bytes
C:\Documents and Settings\sabine\Cookies\sabine@superstats[1].txt 330 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ebay[1].txt 438 bytes
C:\Documents and Settings\sabine\Cookies\sabine@uniontrib[1].txt 81 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 197 bytes
C:\Documents and Settings\sabine\Cookies\sabine@epicurious[1].txt 109 bytes
C:\Documents and Settings\sabine\Cookies\sabine@vivis3333[1].txt 173 bytes
C:\Documents and Settings\sabine\Cookies\sabine@victoriassecret[1].txt 105 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 81 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 92 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 254 bytes
C:\Documents and Settings\sabine\Cookies\sabine@tvguide[3].txt 940 bytes
C:\Documents and Settings\sabine\Cookies\sabine@redirect[1].txt 98 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 106 bytes
C:\Documents and Settings\sabine\Cookies\sabine@expedia[2].txt 478 bytes
C:\Documents and Settings\sabine\Cookies\sabine@paulas62[1].txt 174 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 69 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 344 bytes
C:\Documents and Settings\sabine\Cookies\sabine@webshots[1].txt 949 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 99 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 250 bytes
C:\Documents and Settings\sabine\Cookies\sabine@free-banners[1].txt 74 bytes
C:\Documents and Settings\sabine\Cookies\sabine@tonyyayo20[1].txt 219 bytes
C:\Documents and Settings\sabine\Cookies\sabine@Dotkew[1].txt 172 bytes
C:\Documents and Settings\sabine\Cookies\sabine@lycos[1].txt 106 bytes
C:\Documents and Settings\sabine\Cookies\sabine@google[5].txt 131 bytes
C:\Documents and Settings\sabine\Cookies\sabine@weather[2].txt 341 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 109 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 102 bytes
C:\Documents and Settings\sabine\Cookies\sabine@victoriassecret[2].txt 108 bytes
C:\Documents and Settings\sabine\Cookies\sabine@local[1].txt 85 bytes
C:\Documents and Settings\sabine\Cookies\sabine@condenet[1].txt 80 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 106 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ronjons[1].txt 102 bytes
C:\Documents and Settings\sabine\Cookies\sabine@forzamissme[1].txt 1.01KB
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 354 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 1021 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 66 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 202 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 158 bytes
C:\Documents and Settings\sabine\Cookies\sabine@dazworld1985[1].txt 219 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 94 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 94 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 173 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 136 bytes
C:\Documents and Settings\sabine\Cookies\sabine@linkexchange[2].txt 237 bytes
C:\Documents and Settings\sabine\Cookies\sabine@webshots[2].txt 376 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 155 bytes
C:\Documents and Settings\sabine\Cookies\sabine@egreetings[1].txt 70 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 69 bytes
C:\Documents and Settings\sabine\Cookies\sabine@msn[3].txt 374 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 109 bytes
C:\Documents and Settings\sabine\Cookies\sabine@kayjay16[1].txt 483 bytes
C:\Documents and Settings\sabine\Cookies\sabine@tvguide[2].txt 676 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][5].txt 67 bytes
C:\Documents and Settings\sabine\Cookies\sabine@sraymond07unitedstates[1].txt 231 bytes
C:\Documents and Settings\sabine\Cookies\sabine@camiyo1[1].txt 170 bytes
C:\Documents and Settings\sabine\Cookies\sabine@webmd[3].txt 293 bytes
C:\Documents and Settings\sabine\Cookies\sabine@fernando180392[1].txt 221 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 74 bytes
C:\Documents and Settings\sabine\Cookies\sabine@smallappliance[1].txt 251 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 413 bytes
C:\Documents and Settings\sabine\Cookies\sabine@listingsca[1].txt 66 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 148 bytes
C:\Documents and Settings\sabine\Cookies\sabine@simplest-shop[1].txt 103 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ljworld[2].txt 77 bytes
C:\Documents and Settings\sabine\Cookies\sabine@netfastmedia[1].txt 108 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 68 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 149 bytes
C:\Documents and Settings\sabine\Cookies\sabine@google[6].txt 135 bytes
C:\Documents and Settings\sabine\Cookies\sabine@msnbc[3].txt 224 bytes
C:\Documents and Settings\sabine\Cookies\sabine@melkinsco[2].txt 409 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 116 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 165 bytes
C:\Documents and Settings\sabine\Cookies\sabine@gamehouse[1].txt 66 bytes
C:\Documents and Settings\sabine\Cookies\sabine@4imprint[1].txt 105 bytes
C:\Documents and Settings\sabine\Cookies\sabine@msn[6].txt 885 bytes
C:\Documents and Settings\sabine\Cookies\sabine@bcentral[2].txt 267 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 92 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 66 bytes
C:\Documents and Settings\sabine\Cookies\sabine@go[4].txt 338 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 70 bytes
C:\Documents and Settings\sabine\Cookies\sabine@yahoo[3].txt 1.03KB
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 226 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 90 bytes
C:\Documents and Settings\sabine\Cookies\sabine@recreation[2].txt 114 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 96 bytes
C:\Documents and Settings\sabine\Cookies\sabine@digitalcity[3].txt 193 bytes
C:\Documents and Settings\sabine\Cookies\sabine@eloisacasillasmunoz[1].txt 182 bytes
C:\Documents and Settings\sabine\Cookies\sabine@kurtaransonay[1].txt 179 bytes
C:\Documents and Settings\sabine\Cookies\sabine@about[3].txt 436 bytes
C:\Documents and Settings\sabine\Cookies\sabine@amazon[5].txt 254 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 169 bytes
C:\Documents and Settings\sabine\Cookies\sabine@google[2].txt 123 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 111 bytes
C:\Documents and Settings\sabine\Cookies\sabine@virtualtourist[1].txt 80 bytes
C:\Documents and Settings\sabine\Cookies\sabine@KzsWindow[2].txt 231 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 76 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 1.36KB
C:\Documents and Settings\sabine\Cookies\sabine@mapquest[2].txt 274 bytes
C:\Documents and Settings\sabine\Cookies\sabine@weather[4].txt 340 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 111 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][5].txt 113 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 91 bytes
C:\Documents and Settings\sabine\Cookies\sabine@msn[5].txt 727 bytes
C:\Documents and Settings\sabine\Cookies\sabine@kanoodle[1].txt 119 bytes
C:\Documents and Settings\sabine\Cookies\sabine@kzswindow[1].txt 406 bytes
C:\Documents and Settings\sabine\Cookies\sabine@sitestats[1].txt 208 bytes
C:\Documents and Settings\sabine\Cookies\sabine@americangreetings[4].txt 280 bytes
C:\Documents and Settings\sabine\Cookies\sabine@hallmark[1].txt 98 bytes
C:\Documents and Settings\sabine\Cookies\sabine@sabinesthoughts[3].txt 181 bytes
C:\Documents and Settings\sabine\Cookies\sabine@1693614[1].txt 505 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 100 bytes
C:\Documents and Settings\sabine\Cookies\sabine@cnn[4].txt 92 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 87 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 285 bytes
C:\Documents and Settings\sabine\Cookies\sabine@justadayinmyparadise[1].txt 100 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 132 bytes
C:\Documents and Settings\sabine\Cookies\sabine@sabinesthoughts[2].txt 518 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 138 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 78 bytes
C:\Documents and Settings\sabine\Cookies\sabine@amazon[6].txt 263 bytes
C:\Documents and Settings\sabine\Cookies\sabine@tacoda[1].txt 412 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 71 bytes
C:\Documents and Settings\sabine\Cookies\sabine@recreation[3].txt 118 bytes
C:\Documents and Settings\sabine\Cookies\sabine@go[1].txt 211 bytes
C:\Documents and Settings\sabine\Cookies\sabine@kumc[1].txt 99 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 155 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 72 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 158 bytes
C:\Documents and Settings\sabine\Cookies\sabine@llbean[1].txt 128 bytes
C:\Documents and Settings\sabine\Cookies\sabine@infospace[2].txt 291 bytes
C:\Documents and Settings\sabine\Cookies\sabine@cnnaudience[2].txt 105 bytes
C:\Documents and Settings\sabine\Cookies\sabine@travel[2].txt 112 bytes
C:\Documents and Settings\sabine\Cookies\sabine@atwola[2].txt 98 bytes
C:\Documents and Settings\sabine\Cookies\sabine@collegehumor[2].txt 324 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 82 bytes
C:\Documents and Settings\sabine\Cookies\sabine@nordstrom[1].txt 209 bytes
C:\Documents and Settings\sabine\Cookies\sabine@cnn[5].txt 98 bytes
C:\Documents and Settings\sabine\Cookies\sabine@nnselect[2].txt 137 bytes
C:\Documents and Settings\sabine\Cookies\sabine@citysearch[3].txt 110 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][4].txt 103 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 354 bytes
C:\Documents and Settings\sabine\Cookies\sabine@msnbc[2].txt 297 bytes
C:\Documents and Settings\sabine\Cookies\sabine@msn[1].txt 166 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 180 bytes
C:\Documents and Settings\sabine\Cookies\sabine@sabinesthoughts[5].txt 416 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 96 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 109 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 156 bytes
C:\Documents and Settings\sabine\Cookies\sabine@lillianvernon[1].txt 105 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ask[1].txt 77 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 111 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 196 bytes
C:\Documents and Settings\sabine\Cookies\sabine@mywebsearch[1].txt 106 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 272 bytes
C:\Documents and Settings\sabine\Cookies\sabine@weather[5].txt 377 bytes
C:\Documents and Settings\sabine\Co
  • 0

#4
tranquil

tranquil

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
The forum is cutting off the length of my post and not letting me add all of the logs. It will only let me add one files, too. So I guess I will just post one log per file in the next several posts so that you know what it what.

Sabine

Attached Files


  • 0

#5
tranquil

tranquil

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
The first Hijackthis log is posted in below:

Logfile of HijackThis v1.99.1
Scan saved at 12:13:39 PM, on 8/29/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Documents and Settings\sabine\Desktop\System Tools - Kermit\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ku.edu/
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SDWin32 Class - {710FF7E8-82AD-41C2-A9C7-05FFDBD29AEB} - C:\WINNT\system32\bnbko.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PnIEBrowserHelperObj Class - {D2F719F3-106A-402B-9996-3A5B12ACA564} - C:\Program Files\Failsafe\GuardIE\PnIE.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Guard-IE - {37C8204D-97C3-4127-BB28-1BFF3FA2F7DA} - C:\Program Files\Failsafe\GuardIE\PnIE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [local epson] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P11 "local epson" /O5 "LPT1:" /M "Stylus Photo 825"
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo 825] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P22 "EPSON Stylus Photo 825" /O5 "LPT1:" /M "Stylus Photo 825"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [HP Lamp] C:\SCANJET\PrecisionScanPro\HPLamp.exe
O4 - HKLM\..\Run: [\\KERMIT\EPSON Stylus Photo 825] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P31 "\\KERMIT\EPSON Stylus Photo 825" /O6 "USB001" /M "Stylus Photo 825"
O4 - HKLM\..\Run: [Ad-watch] "D:\Program Files\aaw6plus\Ad-watch.exe"
O4 - HKLM\..\Run: [LifeScape Media Detector] C:\Program Files\Picasa\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: @C:\Program Files\Failsafe\GuardIE\PnIE.dll,-100 - {BDD75188-2FC0-4099-909F-AA8D432BE037} - C:\Program Files\Failsafe\GuardIE\PnIE.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Failsafe\GuardIE\PnIE.dll,-100 - {BDD75188-2FC0-4099-909F-AA8D432BE037} - C:\Program Files\Failsafe\GuardIE\PnIE.dll
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ChatSpace Full Java Client 3.1.0.218 - http://msworld.chats...va/cfs31218.cab
O16 - DPF: ChatSpace Java Client 2.1.0.90 - http://msworld.chats...va/cs4ms090.cab
O16 - DPF: Yahoo! Literati - http://download.game...nts/y/tt3_x.cab
O16 - DPF: Yahoo! MahJong - http://download.game...nts/y/ot0_x.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.game...s/y/mjst4_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.game...ts/y/pyt1_x.cab
O16 - DPF: {0122955E-1FB0-11D2-A238-006097FAEE8B} (CscClnt Class) - http://205.159.125.1...everContent.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative....015/CTSUEng.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/i...etup1.0.0.6.exe
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec....sa/LSSupCtl.cab
O16 - DPF: {29EEFF42-F3FA-11D5-A9D5-00500413153C} (DFRun Class) - http://webpdp.gator....bpdpgeneric.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgree...eensActivia.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://sabinesthough...ad/MsnPUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.r...ip/RdxIE601.cab
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifes...ll/pinstall.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1151942947613
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/...me/ZAxRcMgr.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn...ro.cab34246.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec....sa/SymAData.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.app.../ITDetector.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.game...aploader_v6.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/...s/msnchat45.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative....15016/CTPID.cab
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINNT\system32\CTsvcCDA.EXE (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe" "WMP54Gv4.exe (file missing)
  • 0

#6
tranquil

tranquil

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
The forum is also making me log of and back on between posts. One would thing that they would provide for very long posts! Anyway, that's not your problem, Phil.

Here is the CCCleaner log:

CLEANING COMPLETE - (16.196 secs)
------------------------------------------------------------------------------------------
264.4MB removed.
------------------------------------------------------------------------------------------

Details of files deleted
------------------------------------------------------------------------------------------
IE Temporary Internet Files (242 files) 3.83MB
Cookie:[email protected]/(&H100001) 1.13KB
Cookie:[email protected]/(&H100001) 1.00KB
Cookie:[email protected]/(&H100001) 213 bytes
C:\Documents and Settings\sabine\Cookies\sabine@superpages[1].txt 193 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 107 bytes
C:\Documents and Settings\sabine\Cookies\sabine@google[1].txt 109 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ljworld[1].txt 78 bytes
C:\Documents and Settings\sabine\Cookies\sabine@inetfast[1].txt 79 bytes
C:\Documents and Settings\sabine\Cookies\sabine@casino-trade[2].txt 217 bytes
C:\Documents and Settings\sabine\Cookies\sabine@veritodvc[1].txt 173 bytes
C:\Documents and Settings\sabine\Cookies\sabine@cnet[2].txt 236 bytes
C:\Documents and Settings\sabine\Cookies\sabine@webmd[1].txt 147 bytes
C:\Documents and Settings\sabine\Cookies\sabine@zdnet[2].txt 215 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 109 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 69 bytes
C:\Documents and Settings\sabine\Cookies\sabine@S0011-00-11-22-152721-37762[1].txt 655 bytes
C:\Documents and Settings\sabine\Cookies\sabine@citysearch[1].txt 107 bytes
C:\Documents and Settings\sabine\Cookies\sabine@livestat[1].txt 88 bytes
C:\Documents and Settings\sabine\Cookies\sabine@midiario20[1].txt 219 bytes
C:\Documents and Settings\sabine\Cookies\sabine@bribon911[1].txt 175 bytes
C:\Documents and Settings\sabine\Cookies\sabine@sportingnews[2].txt 181 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 301 bytes
C:\Documents and Settings\sabine\Cookies\sabine@characteristics[1].txt 313 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 132 bytes
C:\Documents and Settings\sabine\Cookies\sabine@yahoo[2].txt 167 bytes
C:\Documents and Settings\sabine\Cookies\sabine@jumacari24[1].txt 261 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 69 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 71 bytes
C:\Documents and Settings\sabine\Cookies\sabine@nordstrom[3].txt 198 bytes
C:\Documents and Settings\sabine\Cookies\sabine@jcp[1].txt 82 bytes
C:\Documents and Settings\sabine\Cookies\sabine@tvguide[1].txt 1015 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 279 bytes
C:\Documents and Settings\sabine\Cookies\sabine@jcp[2].txt 177 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 147 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 152 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 115 bytes
C:\Documents and Settings\sabine\Cookies\sabine@cnn[2].txt 485 bytes
C:\Documents and Settings\sabine\Cookies\sabine@cnnaudience[1].txt 93 bytes
C:\Documents and Settings\sabine\Cookies\sabine@_cqr[1].txt 1.15KB
C:\Documents and Settings\sabine\Cookies\sabine@altavista[1].txt 101 bytes
C:\Documents and Settings\sabine\Cookies\sabine@spiegel[1].txt 210 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 124 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ahealthyme[1].txt 102 bytes
C:\Documents and Settings\sabine\Cookies\sabine@topic[1].txt 75 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][4].txt 227 bytes
C:\Documents and Settings\sabine\Cookies\sabine@google[4].txt 127 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 107 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 66 bytes
C:\Documents and Settings\sabine\Cookies\sabine@autoweb[1].txt 245 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 108 bytes
C:\Documents and Settings\sabine\Cookies\sabine@techtv[1].txt 110 bytes
C:\Documents and Settings\sabine\Cookies\sabine@l2m[1].txt 80 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 103 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ki[1].txt 80 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ureach[1].txt 89 bytes
C:\Documents and Settings\sabine\Cookies\sabine@pathfinder[1].txt 98 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 140 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 69 bytes
C:\Documents and Settings\sabine\Cookies\sabine@sabinesthoughts[1].txt 223 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 330 bytes
C:\Documents and Settings\sabine\Cookies\sabine@barnesandnoble[1].txt 309 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 151 bytes
C:\Documents and Settings\sabine\Cookies\sabine@allrecipes[1].txt 105 bytes
C:\Documents and Settings\sabine\Cookies\sabine@spencergifts[1].txt 108 bytes
C:\Documents and Settings\sabine\Cookies\sabine@about[1].txt 213 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 106 bytes
C:\Documents and Settings\sabine\Cookies\sabine@avenuea[2].txt 93 bytes
C:\Documents and Settings\sabine\Cookies\sabine@timeinc[1].txt 94 bytes
C:\Documents and Settings\sabine\Cookies\sabine@234[1].txt 74 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 110 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 176 bytes
C:\Documents and Settings\sabine\Cookies\sabine@net-on[1].txt 58 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 69 bytes
C:\Documents and Settings\sabine\Cookies\sabine@amazon[3].txt 350 bytes
C:\Documents and Settings\sabine\Cookies\sabine@amazon[1].txt 350 bytes
C:\Documents and Settings\sabine\Cookies\sabine@review[1].txt 280 bytes
C:\Documents and Settings\sabine\Cookies\sabine@americangreetings[1].txt 272 bytes
C:\Documents and Settings\sabine\Cookies\sabine@iwin[2].txt 613 bytes
C:\Documents and Settings\sabine\Cookies\sabine@Cookie[2].txt 100 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 135 bytes
C:\Documents and Settings\sabine\Cookies\sabine@go[2].txt 149 bytes
C:\Documents and Settings\sabine\Cookies\sabine@superstats[1].txt 330 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ebay[1].txt 438 bytes
C:\Documents and Settings\sabine\Cookies\sabine@uniontrib[1].txt 81 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 197 bytes
C:\Documents and Settings\sabine\Cookies\sabine@epicurious[1].txt 109 bytes
C:\Documents and Settings\sabine\Cookies\sabine@vivis3333[1].txt 173 bytes
C:\Documents and Settings\sabine\Cookies\sabine@victoriassecret[1].txt 105 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 81 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 92 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 254 bytes
C:\Documents and Settings\sabine\Cookies\sabine@tvguide[3].txt 940 bytes
C:\Documents and Settings\sabine\Cookies\sabine@redirect[1].txt 98 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 106 bytes
C:\Documents and Settings\sabine\Cookies\sabine@expedia[2].txt 478 bytes
C:\Documents and Settings\sabine\Cookies\sabine@paulas62[1].txt 174 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 69 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 344 bytes
C:\Documents and Settings\sabine\Cookies\sabine@webshots[1].txt 949 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 99 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 250 bytes
C:\Documents and Settings\sabine\Cookies\sabine@free-banners[1].txt 74 bytes
C:\Documents and Settings\sabine\Cookies\sabine@tonyyayo20[1].txt 219 bytes
C:\Documents and Settings\sabine\Cookies\sabine@Dotkew[1].txt 172 bytes
C:\Documents and Settings\sabine\Cookies\sabine@lycos[1].txt 106 bytes
C:\Documents and Settings\sabine\Cookies\sabine@google[5].txt 131 bytes
C:\Documents and Settings\sabine\Cookies\sabine@weather[2].txt 341 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 109 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 102 bytes
C:\Documents and Settings\sabine\Cookies\sabine@victoriassecret[2].txt 108 bytes
C:\Documents and Settings\sabine\Cookies\sabine@local[1].txt 85 bytes
C:\Documents and Settings\sabine\Cookies\sabine@condenet[1].txt 80 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 106 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ronjons[1].txt 102 bytes
C:\Documents and Settings\sabine\Cookies\sabine@forzamissme[1].txt 1.01KB
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 354 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 1021 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 66 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 202 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 158 bytes
C:\Documents and Settings\sabine\Cookies\sabine@dazworld1985[1].txt 219 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 94 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 94 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 173 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 136 bytes
C:\Documents and Settings\sabine\Cookies\sabine@linkexchange[2].txt 237 bytes
C:\Documents and Settings\sabine\Cookies\sabine@webshots[2].txt 376 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 155 bytes
C:\Documents and Settings\sabine\Cookies\sabine@egreetings[1].txt 70 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 69 bytes
C:\Documents and Settings\sabine\Cookies\sabine@msn[3].txt 374 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 109 bytes
C:\Documents and Settings\sabine\Cookies\sabine@kayjay16[1].txt 483 bytes
C:\Documents and Settings\sabine\Cookies\sabine@tvguide[2].txt 676 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][5].txt 67 bytes
C:\Documents and Settings\sabine\Cookies\sabine@sraymond07unitedstates[1].txt 231 bytes
C:\Documents and Settings\sabine\Cookies\sabine@camiyo1[1].txt 170 bytes
C:\Documents and Settings\sabine\Cookies\sabine@webmd[3].txt 293 bytes
C:\Documents and Settings\sabine\Cookies\sabine@fernando180392[1].txt 221 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 74 bytes
C:\Documents and Settings\sabine\Cookies\sabine@smallappliance[1].txt 251 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 413 bytes
C:\Documents and Settings\sabine\Cookies\sabine@listingsca[1].txt 66 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 148 bytes
C:\Documents and Settings\sabine\Cookies\sabine@simplest-shop[1].txt 103 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ljworld[2].txt 77 bytes
C:\Documents and Settings\sabine\Cookies\sabine@netfastmedia[1].txt 108 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 68 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 149 bytes
C:\Documents and Settings\sabine\Cookies\sabine@google[6].txt 135 bytes
C:\Documents and Settings\sabine\Cookies\sabine@msnbc[3].txt 224 bytes
C:\Documents and Settings\sabine\Cookies\sabine@melkinsco[2].txt 409 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 116 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 165 bytes
C:\Documents and Settings\sabine\Cookies\sabine@gamehouse[1].txt 66 bytes
C:\Documents and Settings\sabine\Cookies\sabine@4imprint[1].txt 105 bytes
C:\Documents and Settings\sabine\Cookies\sabine@msn[6].txt 885 bytes
C:\Documents and Settings\sabine\Cookies\sabine@bcentral[2].txt 267 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 92 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 66 bytes
C:\Documents and Settings\sabine\Cookies\sabine@go[4].txt 338 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 70 bytes
C:\Documents and Settings\sabine\Cookies\sabine@yahoo[3].txt 1.03KB
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 226 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 90 bytes
C:\Documents and Settings\sabine\Cookies\sabine@recreation[2].txt 114 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 96 bytes
C:\Documents and Settings\sabine\Cookies\sabine@digitalcity[3].txt 193 bytes
C:\Documents and Settings\sabine\Cookies\sabine@eloisacasillasmunoz[1].txt 182 bytes
C:\Documents and Settings\sabine\Cookies\sabine@kurtaransonay[1].txt 179 bytes
C:\Documents and Settings\sabine\Cookies\sabine@about[3].txt 436 bytes
C:\Documents and Settings\sabine\Cookies\sabine@amazon[5].txt 254 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 169 bytes
C:\Documents and Settings\sabine\Cookies\sabine@google[2].txt 123 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 111 bytes
C:\Documents and Settings\sabine\Cookies\sabine@virtualtourist[1].txt 80 bytes
C:\Documents and Settings\sabine\Cookies\sabine@KzsWindow[2].txt 231 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 76 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 1.36KB
C:\Documents and Settings\sabine\Cookies\sabine@mapquest[2].txt 274 bytes
C:\Documents and Settings\sabine\Cookies\sabine@weather[4].txt 340 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 111 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][5].txt 113 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 91 bytes
C:\Documents and Settings\sabine\Cookies\sabine@msn[5].txt 727 bytes
C:\Documents and Settings\sabine\Cookies\sabine@kanoodle[1].txt 119 bytes
C:\Documents and Settings\sabine\Cookies\sabine@kzswindow[1].txt 406 bytes
C:\Documents and Settings\sabine\Cookies\sabine@sitestats[1].txt 208 bytes
C:\Documents and Settings\sabine\Cookies\sabine@americangreetings[4].txt 280 bytes
C:\Documents and Settings\sabine\Cookies\sabine@hallmark[1].txt 98 bytes
C:\Documents and Settings\sabine\Cookies\sabine@sabinesthoughts[3].txt 181 bytes
C:\Documents and Settings\sabine\Cookies\sabine@1693614[1].txt 505 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 100 bytes
C:\Documents and Settings\sabine\Cookies\sabine@cnn[4].txt 92 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 87 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 285 bytes
C:\Documents and Settings\sabine\Cookies\sabine@justadayinmyparadise[1].txt 100 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 132 bytes
C:\Documents and Settings\sabine\Cookies\sabine@sabinesthoughts[2].txt 518 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 138 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 78 bytes
C:\Documents and Settings\sabine\Cookies\sabine@amazon[6].txt 263 bytes
C:\Documents and Settings\sabine\Cookies\sabine@tacoda[1].txt 412 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 71 bytes
C:\Documents and Settings\sabine\Cookies\sabine@recreation[3].txt 118 bytes
C:\Documents and Settings\sabine\Cookies\sabine@go[1].txt 211 bytes
C:\Documents and Settings\sabine\Cookies\sabine@kumc[1].txt 99 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 155 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 72 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 158 bytes
C:\Documents and Settings\sabine\Cookies\sabine@llbean[1].txt 128 bytes
C:\Documents and Settings\sabine\Cookies\sabine@infospace[2].txt 291 bytes
C:\Documents and Settings\sabine\Cookies\sabine@cnnaudience[2].txt 105 bytes
C:\Documents and Settings\sabine\Cookies\sabine@travel[2].txt 112 bytes
C:\Documents and Settings\sabine\Cookies\sabine@atwola[2].txt 98 bytes
C:\Documents and Settings\sabine\Cookies\sabine@collegehumor[2].txt 324 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 82 bytes
C:\Documents and Settings\sabine\Cookies\sabine@nordstrom[1].txt 209 bytes
C:\Documents and Settings\sabine\Cookies\sabine@cnn[5].txt 98 bytes
C:\Documents and Settings\sabine\Cookies\sabine@nnselect[2].txt 137 bytes
C:\Documents and Settings\sabine\Cookies\sabine@citysearch[3].txt 110 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][4].txt 103 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 354 bytes
C:\Documents and Settings\sabine\Cookies\sabine@msnbc[2].txt 297 bytes
C:\Documents and Settings\sabine\Cookies\sabine@msn[1].txt 166 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 180 bytes
C:\Documents and Settings\sabine\Cookies\sabine@sabinesthoughts[5].txt 416 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 96 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 109 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 156 bytes
C:\Documents and Settings\sabine\Cookies\sabine@lillianvernon[1].txt 105 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ask[1].txt 77 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 111 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 196 bytes
C:\Documents and Settings\sabine\Cookies\sabine@mywebsearch[1].txt 106 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 272 bytes
C:\Documents and Settings\sabine\Cookies\sabine@weather[5].txt 377 bytes
C:\Documents and Settings\sabine\Cookies\sabine@freeslots[1].txt 329 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 107 bytes
C:\Documents and Settings\sabine\Cookies\sabine@cgi-bin[2].txt 211 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 153 bytes
C:\Documents and Settings\sabine\Cookies\sabine@usatoday[2].txt 760 bytes
C:\Documents and Settings\sabine\Cookies\sabine@about[2].txt 999 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 168 bytes
C:\Documents and Settings\sabine\Cookies\sabine@tessisabeachbum[3].txt 429 bytes
C:\Documents and Settings\sabine\Cookies\sabine@nytimes[1].txt 868 bytes
C:\Documents and Settings\sabine\Cookies\sabine@zeynepankara-live[2].txt 96 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 0.52MB
C:\Documents and Settings\sabine\Cookies\sabine@live[1].txt 726 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 147 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 124 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 105 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 231 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 327 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 93 bytes
C:\Documents and Settings\sabine\Cookies\sabine@americangreetings[2].txt 436 bytes
C:\Documents and Settings\sabine\Cookies\sabine@gamehouse[2].txt 66 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 206 bytes
C:\Documents and Settings\sabine\Cookies\sabine@iwin[1].txt 779 bytes
C:\Documents and Settings\sabine\Cookies\sabine@expedia[1].txt 583 bytes
C:\Documents and Settings\sabine\Cookies\sabine@cnn[1].txt 453 bytes
C:\Documents and Settings\sabine\Cookies\sabine@cnet[3].txt 237 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 451 bytes
C:\Documents and Settings\sabine\Cookies\sabine@oprah[2].txt 270 bytes
C:\Documents and Settings\sabine\Cookies\sabine@weather[1].txt 306 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 86 bytes
C:\Documents and Settings\sabine\Cookies\sabine@Cookie[1].txt 128 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 82 bytes
C:\Documents and Settings\sabine\Cookies\sabine@gap[2].txt 99 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 173 bytes
C:\Documents and Settings\sabine\Cookies\sabine@webshots[3].txt 1.10KB
C:\Documents and Settings\sabine\Cookies\sabine@healthology[1].txt 109 bytes
C:\Documents and Settings\sabine\Cookies\sabine@rankyou[1].txt 263 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 546 bytes
C:\Documents and Settings\sabine\Cookies\sabine@amazingmedia[2].txt 254 bytes
C:\Documents and Settings\sabine\Cookies\sabine@jcp[5].txt 411 bytes
C:\Documents and Settings\sabine\Cookies\sabine@drugstore[2].txt 251 bytes
C:\Documents and Settings\sabine\Cookies\sabine@eb[2].txt 80 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 302 bytes
C:\Documents and Settings\sabine\Cookies\sabine@citysearch[2].txt 106 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 309 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 561 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 123 bytes
C:\Documents and Settings\sabine\Cookies\sabine@amazon[2].txt 437 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 94 bytes
C:\Documents and Settings\sabine\Cookies\sabine@WomansDay[2].txt 185 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 338 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 109 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 203 bytes
C:\Documents and Settings\sabine\Cookies\sabine@realtor[1].txt 103 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 101 bytes
C:\Documents and Settings\sabine\Cookies\sabine@public[1].txt 104 bytes
C:\Documents and Settings\sabine\Cookies\sabine@rooms[1].txt 87 bytes
C:\Documents and Settings\sabine\Cookies\sabine@smarterkids[1].txt 107 bytes
C:\Documents and Settings\sabine\Cookies\sabine@zoovy[1].txt 98 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 353 bytes
C:\Documents and Settings\sabine\Cookies\sabine@affiliate[1].txt 90 bytes
C:\Documents and Settings\sabine\Cookies\sabine@casino[1].txt 103 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 82 bytes
C:\Documents and Settings\sabine\Cookies\sabine@oprah[3].txt 271 bytes
C:\Documents and Settings\sabine\Cookies\sabine@redeemmygifts[1].txt 109 bytes
C:\Documents and Settings\sabine\Cookies\sabine@johnsonlane[1].txt 107 bytes
C:\Documents and Settings\sabine\Cookies\sabine@gap[1].txt 99 bytes
C:\Documents and Settings\sabine\Cookies\sabine@mediabrains[1].txt 107 bytes
C:\Documents and Settings\sabine\Cookies\sabine@crystalad[1].txt 86 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 167 bytes
C:\Documents and Settings\sabine\Cookies\sabine@magazineoutlet[1].txt 110 bytes
C:\Documents and Settings\sabine\Cookies\sabine@Cookie[3].txt 102 bytes
C:\Documents and Settings\sabine\Cookies\sabine@jcp[4].txt 264 bytes
C:\Documents and Settings\sabine\Cookies\sabine@digitalcity[2].txt 359 bytes
C:\Documents and Settings\sabine\Cookies\sabine@inphonic[1].txt 104 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 331 bytes
C:\Documents and Settings\sabine\Cookies\sabine@geoaccess[1].txt 124 bytes
C:\Documents and Settings\sabine\Cookies\sabine@46163393[1].txt 118 bytes
C:\Documents and Settings\sabine\Cookies\sabine@webshots[4].txt 1.18KB
C:\Documents and Settings\sabine\Cookies\sabine@askjeeves[2].txt 388 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 71 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 123 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 309 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 175 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][4].txt 251 bytes
C:\Documents and Settings\sabine\Cookies\sabine@twistedhumor[2].txt 292 bytes
C:\Documents and Settings\sabine\Cookies\sabine@insure[1].txt 78 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 160 bytes
C:\Documents and Settings\sabine\Cookies\sabine@adscpm[2].txt 144 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 78 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 135 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 73 bytes
C:\Documents and Settings\sabine\Cookies\sabine@dealtime[1].txt 84 bytes
C:\Documents and Settings\sabine\Cookies\sabine@232[1].txt 73 bytes
C:\Documents and Settings\sabine\Cookies\sabine@iwin[3].txt 853 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 362 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 92 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 368 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 72 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 88 bytes
C:\Documents and Settings\sabine\Cookies\sabine@S122504[1].txt 151 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 125 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 76 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 303 bytes
C:\Documents and Settings\sabine\Cookies\sabine@msnbc[1].txt 224 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 205 bytes
C:\Documents and Settings\sabine\Cookies\sabine@askcm[1].txt 153 bytes
C:\Documents and Settings\sabine\Cookies\sabine@nih[1].txt 97 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 132 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 107 bytes
C:\Documents and Settings\sabine\Cookies\sabine@rankyou[3].txt 266 bytes
C:\Documents and Settings\sabine\Cookies\sabine@S110197[1].txt 795 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 76 bytes
C:\Documents and Settings\sabine\Cookies\sabine@mswatch[2].txt 183 bytes
C:\Documents and Settings\sabine\Cookies\sabine@oldnavy[1].txt 103 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 113 bytes
C:\Documents and Settings\sabine\Cookies\sabine@realtor[2].txt 275 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 73 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 138 bytes
C:\Documents and Settings\sabine\Cookies\sabine@seaworld[1].txt 104 bytes
C:\Documents and Settings\sabine\Cookies\sabine@switchboard[1].txt 91 bytes
C:\Documents and Settings\sabine\Cookies\sabine@S114450[1].txt 388 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 196 bytes
C:\Documents and Settings\sabine\Cookies\sabine@pogo[1].txt 84 bytes
C:\Documents and Settings\sabine\Cookies\sabine@microsoft[1].txt 124 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 316 bytes
C:\Documents and Settings\sabine\Cookies\sabine@recreation[1].txt 133 bytes
C:\Documents and Settings\sabine\Cookies\sabine@drugstore[3].txt 251 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 87 bytes
C:\Documents and Settings\sabine\Cookies\sabine@cnet[4].txt 237 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 72 bytes
C:\Documents and Settings\sabine\Cookies\sabine@flowers[1].txt 155 bytes
C:\Documents and Settings\sabine\Cookies\sabine@homestore[2].txt 210 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 93 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 171 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 172 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 112 bytes
C:\Documents and Settings\sabine\Cookies\sabine@50255095[1].txt 112 bytes
C:\Documents and Settings\sabine\Cookies\sabine@match[2].txt 100 bytes
C:\Documents and Settings\sabine\Cookies\sabine@pbskids[1].txt 77 bytes
C:\Documents and Settings\sabine\Cookies\sabine@pbs[2].txt 166 bytes
C:\Documents and Settings\sabine\Cookies\sabine@verizon[1].txt 90 bytes
C:\Documents and Settings\sabine\Cookies\sabine@consumercentric[1].txt 85 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 80 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 131 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 224 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 111 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 187 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 464 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 100 bytes
C:\Documents and Settings\sabine\Cookies\sabine@asp[2].txt 233 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 149 bytes
C:\Documents and Settings\sabine\Cookies\sabine@coldwatercreek[1].txt 110 bytes
C:\Documents and Settings\sabine\Cookies\sabine@frognet[1].txt 96 bytes
C:\Documents and Settings\sabine\Cookies\sabine@bluebunny[1].txt 106 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 94 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 150 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 110 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 94 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 95 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 140 bytes
C:\Documents and Settings\sabine\Cookies\sabine@highschoolalumni[2].txt 381 bytes
C:\Documents and Settings\sabine\Cookies\sabine@amazingmedia[1].txt 272 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 137 bytes
C:\Documents and Settings\sabine\Cookies\sabine@cnn[3].txt 494 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 80 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 92 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 93 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 71 bytes
C:\Documents and Settings\sabine\Cookies\sabine@google[3].txt 127 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 153 bytes
C:\Documents and Settings\sabine\Cookies\sabine@mayoclinic[1].txt 82 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 101 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 158 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 84 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 105 bytes
C:\Documents and Settings\sabine\Cookies\sabine@expedia[3].txt 586 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 73 bytes
C:\Documents and Settings\sabine\Cookies\sabine@login[3].txt 228 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 107 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][4].txt 153 bytes
C:\Documents and Settings\sabine\Cookies\sabine@citysearch[4].txt 186 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 108 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 172 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 112 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 79 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 155 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 336 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 108 bytes
C:\Documents and Settings\sabine\Cookies\sabine@lookandfeel[1].txt 82 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ea[1].txt 98 bytes
C:\Documents and Settings\sabine\Cookies\sabine@54838159[1].txt 112 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 83 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 110 bytes
C:\Documents and Settings\sabine\Cookies\sabine@datingcash[1].txt 106 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 219 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 221 bytes
C:\Documents and Settings\sabine\Cookies\sabine@S110606[1].txt 136 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 87 bytes
C:\Documents and Settings\sabine\Cookies\sabine@generalmills[1].txt 108 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 141 bytes
C:\Documents and Settings\sabine\Cookies\sabine@al[2].txt 156 bytes
C:\Documents and Settings\sabine\Cookies\sabine@howstuffworks[2].txt 163 bytes
C:\Documents and Settings\sabine\Cookies\sabine@S[1].txt 461 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 74 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 163 bytes
C:\Documents and Settings\sabine\Cookies\sabine@geocities[2].txt 159 bytes
C:\Documents and Settings\sabine\Cookies\sabine@aaa[1].txt 98 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 373 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 109 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 479 bytes
C:\Documents and Settings\sabine\Cookies\sabine@aol[2].txt 387 bytes
C:\Documents and Settings\sabine\Cookies\sabine@webmd[4].txt 294 bytes
C:\Documents and Settings\sabine\Cookies\sabine@6425137[1].txt 118 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 264 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 209 bytes
C:\Documents and Settings\sabine\Cookies\sabine@classmates[2].txt 403 bytes
C:\Documents and Settings\sabine\Cookies\sabine@weather[3].txt 397 bytes
C:\Documents and Settings\sabine\Cookies\sabine@egreetings[3].txt 232 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 211 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 112 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 92 bytes
C:\Documents and Settings\sabine\Cookies\sabine@amazon[4].txt 439 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 168 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 171 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 74 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 152 bytes
C:\Documents and Settings\sabine\Cookies\sabine@S005-01-8-19-270873-97879[1].txt 135 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 223 bytes
C:\Documents and Settings\sabine\Cookies\sabine@msn[2].txt 326 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 121 bytes
C:\Documents and Settings\sabine\Cookies\sabine@fullsail[1].txt 62 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 69 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 73 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 145 bytes
C:\Documents and Settings\sabine\Cookies\sabine@americangreetings[3].txt 538 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 106 bytes
C:\Documents and Settings\sabine\Cookies\sabine@_cqr[3].txt 981 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 112 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 354 bytes
C:\Documents and Settings\sabine\Cookies\sabine@S138734[2].txt 119 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][3].txt 287 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 477 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 108 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 242 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 111 bytes
C:\Documents and Settings\sabine\Cookies\sabine@washingtonpost[1].txt 95 bytes
C:\Documents and Settings\sabine\Cookies\sabine@crc[1].txt 123 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 97 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 134 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ku[1].txt 97 bytes
C:\Documents and Settings\sabine\Cookies\sabine@ukans[1].txt 101 bytes
C:\Documents and Settings\sabine\Cookies\sabine@_cqr[4].txt 993 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 83 bytes
C:\Documents and Settings\sabine\Cookies\sabine@galleryatthecreek[1].txt 112 bytes
C:\Documents and Settings\sabine\Cookies\sabine@go[3].txt 211 bytes
C:\Documents and Settings\sabine\Cookies\sabine@askthewizard[2].txt 203 bytes
C:\Documents and Settings\sabine\Cookies\sabine@checksunlimited[2].txt 113 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 126 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 472 bytes
C:\Documents and Settings\sabine\Cookies\sabine@williams-sonoma[1].txt 113 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 367 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 86 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][1].txt 85 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 172 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 115 bytes
C:\Documents and Settings\sabine\Cookies\sabine@alumni[2].txt 65 bytes
C:\Documents and Settings\sabine\Cookies\[email protected][2].txt 105 bytes
C:\WINNT\Cookies\sabine@msn[2].txt 160 bytes
C:\WINNT\Cookies\sabine@pogo[1].txt 85 bytes
C:\WINNT\Cookies\sabine@login[1].txt 78 bytes
C:\WINNT\Cookies\[email protected][2].txt 88 bytes
C:\WINNT\Cookies\[email protected][1].txt 135 bytes
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\desktop.ini 113 bytes
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012004120720041208\index.dat 32.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012004122920041230\index.dat 48.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012005020720050208\index.dat 32.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012005033020050331\index.dat 32.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012005051420050515\index.dat 32.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012005070120050702\index.dat 32.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012005091920050920\index.dat 32.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012005092120050922\index.dat 32.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012005100120051002\index.dat 48.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012006032320060324\index.dat 32.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012006050720060508\index.dat 32.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012006050920060510\index.dat 48.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012006051420060515\index.dat 32.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012006053020060531\index.dat 32.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012006070320060704\index.dat 64.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012006070820060709 16.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012006072120060722\index.dat 48.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012006080420060805\index.dat 32.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012006080520060806\index.dat 32.00KB
C:\Documents and Settings\sabine\Local Settings\History\History.IE5\MSHist012006080920060810\index.dat 32.00KB
Marked for deletion: C:\Documents and Settings\sabine\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Marked for deletion: C:\Documents and Settings\sabine\Cookies\index.dat
Marked for deletion: C:\Documents and Settings\sabine\Local Settings\History\History.IE5\index.dat
Marked for deletion: C:\Documents and Settings\sabine\Local Settings\History\History.IE5\mshist012006082920060830\index.dat
Marked for deletion: C:\WINNT\Temporary Internet Files\Content.IE5\index.dat
Marked for deletion: C:\WINNT\Cookies\index.dat
Emptied Recycle Bin (5 files) 7.01MB
C:\WINNT\TEMP\ioconfig.log 389 bytes
C:\WINNT\TEMP\ENGSETUP.LOG 23.80KB
C:\WINNT\TEMP\_ISTMP3.DIR\msvcp60.dll 0.38MB
C:\WINNT\TEMP\_ISTMP3.DIR\mfc42.dll 0.95MB
C:\WINNT\TEMP\_ISTMP0.DIR\HPSETUP.LOG 464 bytes
C:\WINNT\TEMP\OLDE.tmp 5.21MB
C:\WINNT\TEMP\sotmp1.dir\ALUpdate.exe 0.18MB
C:\WINNT\TEMP\sotmp1.dir\CidSync.dll 0.21MB
C:\WINNT\TEMP\sotmp1.dir\Config.dll 100.00KB
C:\WINNT\TEMP\sotmp1.dir\InstlMgr.dll 84.00KB
C:\WINNT\TEMP\sotmp1.dir\libeay32.dll 0.76MB
C:\WINNT\TEMP\sotmp1.dir\ps_rootca.crt 1.28KB
C:\WINNT\TEMP\sotmp1.dir\ps.crl 1.35KB
C:\WINNT\TEMP\sotmp1.dir\Logger.dll 0.25MB
C:\WINNT\TEMP\sotmp1.dir\MSVCR71.DLL 0.33MB
C:\WINNT\TEMP\sotmp1.dir\MSVCP71.DLL 0.48MB
C:\WINNT\TEMP\sotmp1.dir\SharedRes.dll 13.00KB
C:\WINNT\TEMP\OLDF.tmp 590 bytes
C:\WINNT\TEMP\OLD1.tmp 7.42MB
C:\WINNT\TEMP\OLD2.tmp 1.07KB
C:\WINNT\TEMP\OLD31.tmp 5.26MB
C:\WINNT\TEMP\OLD32.tmp 2.92KB
C:\WINNT\TEMP\Sophos Remote Update Setup.log 125 bytes
C:\WINNT\TEMP\Sophos Anti-Virus install log.txt 3.94KB
C:\WINNT\TEMP\Sophos Anti-Virus CustomActions Log.txt 8.61MB
C:\WINNT\TEMP\Sophos Anti-Virus Configuration.txt 0 bytes
C:\WINNT\TEMP\Sophos AutoUpdate install log.txt 0.62MB
C:\WINNT\TEMP\_ISTMP2.DIR\004636F2._MP 0.53MB
C:\WINNT\TEMP\sophos_autoupdate1.dir\ALUpdate.exe 0.18MB
C:\WINNT\TEMP\sophos_autoupdate1.dir\CidSync.dll 0.21MB
C:\WINNT\TEMP\sophos_autoupdate1.dir\Config.dll 100.00KB
C:\WINNT\TEMP\sophos_autoupdate1.dir\InstlMgr.dll 84.00KB
C:\WINNT\TEMP\sophos_autoupdate1.dir\libeay32.dll 0.76MB
C:\WINNT\TEMP\sophos_autoupdate1.dir\ps_rootca.crt 1.28KB
C:\WINNT\TEMP\sophos_autoupdate1.dir\ps.crl 1.35KB
C:\WINNT\TEMP\sophos_autoupdate1.dir\Logger.dll 0.25MB
C:\WINNT\TEMP\sophos_autoupdate1.dir\MSVCR71.DLL 0.33MB
C:\WINNT\TEMP\sophos_autoupdate1.dir\MSVCP71.DLL 0.48MB
C:\WINNT\TEMP\sophos_autoupdate1.dir\SharedRes.dll 13.00KB
C:\WINNT\TEMP\A5355s._0a 72.00KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\SBSetup.log 112 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\D2F2F703.TMP 198 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\A5355s._0a 72.00KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\6B907.dmp 0 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\ff_temp\xpcom.ns\bin\xpcom_core.dll 0.38MB
C:\DOCUME~1\sabine\LOCALS~1\Temp\ff_temp\xpcom.ns\bin\components\jar50.dll 59.11KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\ff_temp\xpcom.ns\bin\components\xpinstal.dll 0.16MB
C:\DOCUME~1\sabine\LOCALS~1\Temp\ff_temp\xpcom.ns\bin\xpcom_compat.dll 66.61KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\ff_temp\xpcom.ns\bin\js3250.dll 0.40MB
C:\DOCUME~1\sabine\LOCALS~1\Temp\ff_temp\xpcom.ns\bin\plc4.dll 28.11KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\ff_temp\xpcom.ns\bin\plds4.dll 24.11KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\ff_temp\xpcom.ns\bin\nspr4.dll 0.15MB
C:\DOCUME~1\sabine\LOCALS~1\Temp\TWAIN.LOG 219 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\Twain001.Mtx 3 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\Twunk002.MTX 0 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\Twunk001.MTX 156 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\~461f168e58ab1c6425340971600.jpd 21 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\JVV6QLTY.htm 85.53KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\Outlook Startup.Log 874 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\tmp.xpi 89.17KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\jusched.log 165 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\Invitation.doc 24.00KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\WebshotsTemp\wssetup.exe 0.94MB
C:\DOCUME~1\sabine\LOCALS~1\Temp\xpinstall.exe 0.23MB
C:\DOCUME~1\sabine\LOCALS~1\Temp\fsglicense.txt 29.78KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\~461f168e58ab1c6425340971600.jpg 4.10KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\~deed87832acf781c5bba949166a00.jpd 21 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\~deed87832acf781c5bba949166a00.jpg 3.48KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\~2eed87822a5a7d1c5bba9ad392e00.jpd 21 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\~2eed87822a5a7d1c5bba9ad392e00.jpg 3.85KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\~4d3e66cb212c8b1c5d2791066800.jpd 21 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\~4d3e66cb212c8b1c5d2791066800.jpg 2.31KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\~e73e66ca226db51c5d27982d7600.jpd 21 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\~e73e66ca226db51c5d27982d7600.jpg 2.22KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\r2h6.tmp 3.02KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\h2r7.tmp 0 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\~002D3 32.00KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\~fa25af532332661c5d27bac182100.jpd 21 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\~fa25af532332661c5d27bac182100.jpg 2.84KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\~672be7eb232d001c5d2799bff4200.jpd 21 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\~672be7eb232d001c5d2799bff4200.jpg 1.77KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\~cd2be7ea1f36a71c5d27ac0dc800.jpd 21 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\~cd2be7ea1f36a71c5d27ac0dc800.jpg 1.82KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\java_install_reg.log 5.25KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\~002U4 39 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\java_install.log 23.04KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\~002D5 32.00KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\tmp-1.xpi 1.26MB
C:\DOCUME~1\sabine\LOCALS~1\Temp\f5388.msi 5.76MB
C:\DOCUME~1\sabine\LOCALS~1\Temp\8u731.tmp 0 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\r2h3.tmp 3.02KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\h2r4.tmp 0 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\~002D6 32.00KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\wgm2D.tmp 0 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\~002D7 48.00KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\~b3fae9f2466591c5d281973e8c00.jpd 21 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\~b3fae9f2466591c5d281973e8c00.jpg 2.59KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\~a13fae9e2128021c5d281a6bdd500.jpd 21 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\hue2F.tmp 0 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\0nc34.tmp 0 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\ICD1.tmp\wtinst.exe 0.19MB
C:\DOCUME~1\sabine\LOCALS~1\Temp\german 1.jpg 0.16MB
C:\DOCUME~1\sabine\LOCALS~1\Temp\uea16.tmp 0 bytes
C:\DOCUME~1\sabine\LOCALS~1\Temp\German 2.jpg 0.15MB
C:\DOCUME~1\sabine\LOCALS~1\Temp\_ISTMP1.DIR\_ISTMP0.DIR\FileGrp\nppdf32.dll 100.92KB
C:\DOCUME~1\sabine\LOCALS~1\Temp\germ 3.jpg 0.16MB
C:\DOCUME~1\sabine\LOCALS~1\Temp\germ 4.jpg 0.14MB
C:\DOCUME~1\sabine\LOCALS~1\Temp\germ 5.jpg 0.14MB
C:\DOCUME~1\sabine\LOCALS~1\Temp\germ 6.jpg 0.16MB
C:\DOCUME~1\sabine\LOCALS~1\Temp\germ 7.jpg 0.15MB
C:\DOCUME~1\sabine\LOCALS~1\Temp\germ 8.jpg 0.15MB
C:\DOCUME~1\sabine\LOCALS~1\Temp\~a13fae9e2128021c5d281a6bdd500.jpg 2.35KB
C:\DOCUME~1\sabine\LOCALS
  • 0

#7
tranquil

tranquil

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Here is the combofix log.

Sabine - Tue 08/29/2006 12:37:55.81
ComboFix 06.08.27BT - Running from: D:\Zipper\Combofix

((((((((((((((((((((((((((((((( Files Created from 2006-07-29 to 2006-08-29 ))))))))))))))))))))))))))))))))))


2006-08-16 19:14 356,352 --a------ C:\WINNT\system32\eSellerateEngine.dll
2006-08-16 19:14 118,784 --a------ C:\WINNT\system32\eWebControl.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-08-29 12:27 -------- d-------- C:\Program Files\CCleaner
2006-08-29 11:26 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-08-22 21:08 -------- d-------- C:\Documents and Settings\sabine\Application Data\Sun
2006-07-25 00:08 840976 --------- C:\WINNT\system32\mmcndmgr.dll
2006-07-21 10:08 72704 --------- C:\WINNT\system32\hlink.dll
2006-07-06 11:52 613648 --------- C:\WINNT\system32\mmc.exe
2006-07-06 06:45 96528 --a------ C:\WINNT\system32\dnsrslvr.dll
2006-06-21 01:52 54544 --a------ C:\WINNT\system32\mpr.dll
2006-06-16 02:05 1713536 --------- C:\WINNT\system32\NTKRNLPA.EXE
2006-06-16 02:04 1690880 --------- C:\WINNT\system32\NTOSKRNL.EXE


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"local epson"="C:\\WINNT\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S10IC2.EXE /P11 \"local epson\" /O5 \"LPT1:\" /M \"Stylus Photo 825\""
"IntelliType"="\"C:\\Program Files\\Microsoft Hardware\\Keyboard\\type32.exe\""
"EPSON Stylus Photo 825"="C:\\WINNT\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S10IC2.EXE /P22 \"EPSON Stylus Photo 825\" /O5 \"LPT1:\" /M \"Stylus Photo 825\""
"Synchronization Manager"="mobsync.exe /logon"
"HP Lamp"="C:\\SCANJET\\PrecisionScanPro\\HPLamp.exe"
"\\\\KERMIT\\EPSON Stylus Photo 825"="C:\\WINNT\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S10IC2.EXE /P31 \"\\\\KERMIT\\EPSON Stylus Photo 825\" /O6 \"USB001\" /M \"Stylus Photo 825\""
"Ad-watch"="\"D:\\Program Files\\aaw6plus\\Ad-watch.exe\""
"LifeScape Media Detector"="C:\\Program Files\\Picasa\\PicasaMediaDetector.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000095
"CDRAutoRun"=dword:00000000

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000003
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="http://ivillage.com/i/t.gif"
"SubscribedURL"="http://ivillage.com/i/t.gif"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,cb,00,00,00,24,01,00,00,61,02,00,00,98,00,00,00,e8,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=dword:00000001
"OriginalStateInfo"=hex:18,00,00,00,10,03,00,00,15,01,00,00,1c,00,00,00,1e,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:b4,f0,4f,7c,38,c4,4f,7c,ff,ff,ff,ff,2c,5d,c5,05,ea,1c,\
34,70,e0,da,e4,03

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e4,02,00,00,ea,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=dword:40000004
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,10,03,00,00,1f,00,00,00,e0,00,00,00,d6,00,\
00,00,01,00,00,00

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000095

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\SAVService

Contents of the 'Scheduled Tasks' folder
C:\WINNT\tasks\Monday Scan 7pm.job

Completion time: Tue 2006-08-29 12:38:10.75
ComboFix.txt
  • 0

#8
tranquil

tranquil

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
I'm sorry about all the posts. This is about the only way I can think of to get all of these logs to you with all of the restrictions they have on posts in this forum.

This is the final HijackThis log. Thanks again, Phil!

Logfile of HijackThis v1.99.1
Scan saved at 12:41:46 PM, on 8/29/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WMP54Gv4.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Documents and Settings\sabine\Desktop\System Tools - Kermit\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ku.edu/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PnIEBrowserHelperObj Class - {D2F719F3-106A-402B-9996-3A5B12ACA564} - C:\Program Files\Failsafe\GuardIE\PnIE.dll
O4 - HKLM\..\Run: [local epson] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P11 "local epson" /O5 "LPT1:" /M "Stylus Photo 825"
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo 825] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P22 "EPSON Stylus Photo 825" /O5 "LPT1:" /M "Stylus Photo 825"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [HP Lamp] C:\SCANJET\PrecisionScanPro\HPLamp.exe
O4 - HKLM\..\Run: [\\KERMIT\EPSON Stylus Photo 825] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P31 "\\KERMIT\EPSON Stylus Photo 825" /O6 "USB001" /M "Stylus Photo 825"
O4 - HKLM\..\Run: [Ad-watch] "D:\Program Files\aaw6plus\Ad-watch.exe"
O4 - HKLM\..\Run: [LifeScape Media Detector] C:\Program Files\Picasa\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: @C:\Program Files\Failsafe\GuardIE\PnIE.dll,-100 - {BDD75188-2FC0-4099-909F-AA8D432BE037} - C:\Program Files\Failsafe\GuardIE\PnIE.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Failsafe\GuardIE\PnIE.dll,-100 - {BDD75188-2FC0-4099-909F-AA8D432BE037} - C:\Program Files\Failsafe\GuardIE\PnIE.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ChatSpace Full Java Client 3.1.0.218 - http://msworld.chats...va/cfs31218.cab
O16 - DPF: ChatSpace Java Client 2.1.0.90 - http://msworld.chats...va/cs4ms090.cab
O16 - DPF: Yahoo! Literati - http://download.game...nts/y/tt3_x.cab
O16 - DPF: Yahoo! MahJong - http://download.game...nts/y/ot0_x.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.game...s/y/mjst4_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.game...ts/y/pyt1_x.cab
O16 - DPF: {0122955E-1FB0-11D2-A238-006097FAEE8B} (CscClnt Class) - http://205.159.125.1...everContent.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative....015/CTSUEng.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec....sa/LSSupCtl.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgree...eensActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://sabinesthough...ad/MsnPUpld.cab
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifes...ll/pinstall.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1151942947613
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/...me/ZAxRcMgr.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn...ro.cab34246.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec....sa/SymAData.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.app.../ITDetector.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/...s/msnchat45.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative....15016/CTPID.cab
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINNT\system32\CTsvcCDA.EXE (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe" "WMP54Gv4.exe (file missing)
  • 0

#9
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,131 posts
Hello again Sabine

Thanks for your perseverance with all the logs; they all look fine.

I should note, I suppose, that the %SystemDrive%" folder is still on my desktop.

Could you post a screen shot please, after a further clean up?

Please delete your temporary files.

Click on START > RUN > type in cleanmgr and hit ENTER

You will see a window asking you to choose your harddrive (most likely C: Drive)

Click it and Windows will now scan the drive and show you the results

Make sure the following are checked:Downloaded Program Files
Temporary Internet Files and
Recycle Bin
Compress Old Files (if you want more disk space)

Click OK and Disk Cleanup will delete those files for you.

Next, go to Start>Run>type in %temp% hit Enter and delete the content of all the temp folders shown (only the content, not the folder). A couple of files may be in memory and will not therefore delete, this is normal.

***********************

How to provide a screen capture of the error

Select the window that you want to show us

Press the ALT key and the Print Screen (sometimes this key is labelled Prt Sc, or Prt Scr) simultaneously

Open Microsoft Paint (usually Start > All Programs > Accessories > Paint)

On the menu bar at the top, choose EDIT > PASTE

Save the file on the desktop by choosing FILE > SAVE AS

Click on the DESKTOP button on the left side of the dialog box, then in the FILE NAME box type: screen1, and under SAVE AS TYPE, choose JPEG

Click the SAVE button

Close Paint

To attach the file, click the ADD_REPLY button at the bottom of this thread. When the window opens, scroll below the message box to FILE ATTACHMENTS, click BROWSE, click the DESKTOP button, then choose SCREEN1, and then click the OPEN button.

Now click the ATTACH button, then click ADD_REPLY button

How's the PC running now?
  • 0

#10
tranquil

tranquil

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Phil -

Thanks for getting back to me. I have attached a copy of the desktop with the %SystemDrive% folder in the middle. It is in GIF format. It didn't give me JPG as an option, oddly enough.

20060829desktop.gif

The contants of the folder looked sort of suspicious to my husband. There doesn't appear to be anything in them, but the path to the bottom directory is:

C:\Documents and Settings\sabine\Desktop\%SystemDrive%\Documents and Settings\sabine\Application Data\Microsoft\SystemCertificates\My

There aqree three folders underneath that last one, all of which are also empty.

Thanks again for for your help so far! Let me know if I need to do anything else..

Sabine
  • 0

Advertisements


#11
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,131 posts
Hello again Sabine

The words %system drive% simply refers to your main drive which is most likely C:\

The SystemCertificates do normally reside in folder/s within documents & settings but not the desktop. The path you have provided seems a little quirky with there being almost a continuous circular reference. When looking at the final folder My on my own PC, I find the 3 sub-folders empty and on that basis I am going to recommend that you send the desktop folder to the recycle bin for a few days. If everything works OK in that time, then delete it, if the PC starts acting odd or you get error messages, restore it.

How's the PC running now?
  • 0

#12
tranquil

tranquil

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Phil -

Thanks for getting back to me. I understand that I should be able to delete this pesky folder, so I will do that. It concerned my husband and I because the name was similar to one that was reported on here that was capturing screenshots of the user's activities! I will delete it and leave it in the recycle bin for a while. That's a great idea.

I have not had a chance to use the computer much in the last 24 hours. I will do that today, after yet another doctor appointment. I wonder if you could leave this topic open for another day so that I can really use things and make sure that it is better?

Thanks for all of your help. Maybe you are super-human after all! ;o)

Sabine
  • 0

#13
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,131 posts
Hello again Sabine

Take your time, but no longer than 10 days when my "thread closing system" kicks in.
  • 0

#14
tranquil

tranquil

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Thanks for leaving the topic open a bit longer, Phil. I have now been able to use my system for several hours and it seems to be back to normal.

I realy thank you for helping me with this problem. I hope that I never need this kind of help again, but if I do I hope that it is you that provides it. You have been wonderful!

Thanks! ;o)

Sabine
  • 0

#15
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,131 posts
Congratulations! your system is clean. :whistling: Just a little bit more to do to prevent further infection.

I recommend going to the following link and update as recommended by Microsoft. This adds more security and extra features including a pop-up blocker for Internet Explorer. Microsoft Update

MVPS Hosts file This replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is the IP of your local computer.

SiteAdvisor download this plug-in for your browser and it will alert you of a known bad site for FREE.

Now that everything is fixed, I suggest that you consider getting these programmes to help keep the computer clean:

SPYWARE BLASTER - Blocks bad ActiveX items from installing on your computer.
WINDOWS DEFENDER - With daily updates and scans, this programme offers good security against malware.
AD-AWARE PERSONAL – A fine free malware detector and removal programme
SPYBOT S&D – Excellent free spyware detector and removal programme
GOOGLE TOOLBAR - Blocks many unwanted pop-ups in Internet Explorer.
FIREFOX - Safer alternative to the Internet Explorer web browser.
AVG ANTIVIRUS FREE EDITION - Free antivirus programme if you currently are not using one.
ZONEALARM - Free firewall programme if you currently are not using one (Windows XP has a built-in firewall).

Remember to update these frequently.

Please note that whilst there is nothing wrong in having more than one antispyware programme for “on demand” scanning, having two or more antivirus systems is not recommended as they may well cause conflicts and slowness.

You may also want to read "How did I get infected in the first place" to learn how to better secure your computer.

Be sure to keep your Windows, antispyware and antivirus updated. :blink:

It just remains for me to wish you happy safe surfing; I hope you found my advice helpful.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP