Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

I-Worm/Delf.Cl Inet20004\alg.exe keeps reinstalling itself


  • Please log in to reply

#1
bretamazzeing

bretamazzeing

    New Member

  • Member
  • Pip
  • 2 posts
hey,
ive got this worm that keeps reinstalling itself.. i did some research.. it says it knocks out your security and i cant seem to get rid of it.. i did all the scans..
- macafee
- house call
- panda
-avg free keeps poping up telling me there is a virus, when i put it in the vault i delete it, and it comes back a few times a day....

and it didnt get rid of it...

a friend of mine said to sign up here, and they will be able to help you....


C:\WINNT\Inet20004\alg.exe


Logfile of HijackThis v1.99.1
Scan saved at 5:53:43 PM, on 4/10/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\system32\crypserv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINNT\system32\sesinetd.exe
C:\WINNT\system32\hserver.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\inet20004\services.exe
C:\WINNT\system32\atiptaxx.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\WINNT\system32\ezSP_Px.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\inet20004\socks.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\inet20004\socks.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgwb.dat
C:\PROGRA~1\Grisoft\AVGFRE~1\avgvv.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optonline.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://login.passpor...rf?lc=1033&id=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optonline.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://login.passpor...ilogin.srf?id=2
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe,msswip95.exe
F3 - REG:win.ini: run=C:\WINNT\inet20004\services.exe
F2 - REG:system.ini: UserInit=
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {D714A94F-123A-45CC-8F03-040BCAF82AD6} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Zend Studio - {95188727-288F-4581-A48D-EAB3BD027314} - C:\Program Files\Zend\bin\ZendIEToolbar.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINNT\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [WXcmeinst] C:\winnt\system32\muwemafyh.exe
O4 - HKLM\..\Run: [asejet] uyohuvax.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [FastTVSync] "C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [Microsoft standard protector] C:\WINNT\inet20004\socks.exe
O4 - HKLM\..\Run: [adajsaaa] C:\WINNT\system32\adajsaaa.exe
O4 - HKLM\..\Run: [CreateCD50] C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE -r
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [xp_system] C:\WINNT\inet20004\services.exe
O4 - HKLM\..\RunServices: [asejet] uyohuvax.exe
O4 - HKCU\..\Run: [asejet] uyohuvax.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [Disspy] C:\Program Files\Disspy\Disspy.exe - silent
O4 - HKCU\..\Run: [adajsaaa] C:\WINNT\system32\adajsaaa.exe
O4 - HKCU\..\Run: [xp_system] C:\WINNT\inet20004\services.exe
O4 - Global Startup: AdsGone 2004.lnk = C:\Program Files\AdsGone\adsgone.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://km.bar.need2f...earch.html?p=KM
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Zend Studio - Debug current page - res://C:\Program Files\Zend\bin\ZendIEToolbar.dll/DebugCurrent.html
O8 - Extra context menu item: Zend Studio - Debug next page - res://C:\Program Files\Zend\bin\ZendIEToolbar.dll/DebugNext.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Voiced Keyboard Homepage - {1ff190e7-38ab-423e-b59c-4d166c2ea5f1} - http://www.yayahoohoo.com (file missing)
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms &] - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms &[ - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RF Toolbar &2 - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Zend Studio Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\Zend\bin\ZendIEToolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: Zend Studio - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\Zend\bin\ZendIEToolbar.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: SWFDecompiler - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\SourceTec\Sothink SWF Decompiler\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Decompiler - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\SourceTec\Sothink SWF Decompiler\InternetExplorer.htm
O9 - Extra button: Flash - {43CF38F3-5AEC-45a3-AD31-04EB06E9C6CA} - C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll (HKCU)
O15 - Trusted Zone: http://linktrader.cyberspacehq.com
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {0837121A-6472-43BD-8A40-D9221FF1C4CE} - http://download.side...22675/sb028.cab
O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - https://www.plaxo.co...laxoInstall.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {1CC506A7-1B8D-11D4-BDD5-0060977007E0} (CrazyTalk Player) - http://plug-in.reall...m/CrazyTalk.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...llInstaller.exe
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg...l_v1-0-3-24.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150...ip/RdxIE601.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots....SDownloader.ocx
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://download.side...42033/sb028.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1135822392226
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://solo.webstert...:3333/msrdp.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installen...gine/isetup.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai....02/cpbrkpie.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} (WebCam Control) - http://www.webcamnow...tiveXWebCam.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart...ploadClient.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/z...s/heartbeat.cab
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {D44C75D8-C827-473E-8F68-A77E42500782} (Uploader Class) - http://photo.walmart...ploadClient.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.app.../ITDetector.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/z...s/heartbeat.cab
O16 - DPF: {EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} (Microsoft Search Settings Control) - http://lg.home.micro...rchsettings.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...734/mcfscan.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www5.incredim...er/imloader.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O21 - SSODL: Client Meeting - {676C539B-8C1A-4D0F-968A-C6EBA9936E9A} - C:\WINNT\system32\sqlsuixx.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINNT\SYSTEM32\crypserv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Houdini License Server (HoudiniLicenseServer) - Side Effects Software Inc. - C:\WINNT\system32\sesinetd.exe
O23 - Service: Houdini License Client (HoudiniServer) - Side Effects Software Inc. - C:\WINNT\system32\hserver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINNT\system32\ZoneLabs\vsmon.exe



thats what i have there


where do i go from here???
  • 0

Advertisements


#2
williesbest2

williesbest2

    Visiting Staff

  • Member
  • PipPipPip
  • 892 posts
Hi I will be helping you with your computer today. I am working with the Geekstogo staff to help get your computer completely free of malware. Please be patient as I analyze your logfile. Thank you.
  • 0

#3
bretamazzeing

bretamazzeing

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts
bretamazzeing Today, 09:28 AM Post #4


New Member


Group: Members
Posts: 4
Joined: Yesterday, 04:42 PM
Member No.: 63538



---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 10:17:56 AM, 4/11/2006
+ Report-Checksum: 93B8CC6F

+ Scan result:

HKU\S-1-5-21-1454471165-2111687655-1708537768-1000\Software\Microsoft\Internet Explorer\Keywords -> Adware.CoolWebSearch : Cleaned with backup
:mozilla.8:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.14:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.16:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.17:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.18:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.35:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.37:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.38:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.39:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.41:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.42:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.43:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.71:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.72:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.73:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.74:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.75:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.76:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.77:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.78:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.79:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.81:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.82:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.83:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.105:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.106:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.107:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.108:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.109:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.110:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.140:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.154:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.155:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.156:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.157:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.158:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.159:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.164:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.165:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.166:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.191:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.206:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.207:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.223:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.232:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.233:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.234:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.235:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.236:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.257:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.267:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup
:mozilla.297:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.316:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.317:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.318:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.319:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.320:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.321:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.322:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.323:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.324:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.331:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.332:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.337:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.338:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.367:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.368:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.369:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.370:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.371:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.372:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.373:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.374:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.387:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.392:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup
:mozilla.425:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup
:mozilla.453:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.462:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.465:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.501:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.502:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.506:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.507:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.509:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.520:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.531:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.532:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.533:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.547:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.548:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.554:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.563:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.564:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.570:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.572:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.596:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.597:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.604:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.605:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.607:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.608:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.609:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.615:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.616:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.617:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.620:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.622:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Ivwbox : Cleaned with backup
:mozilla.627:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.656:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.660:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.661:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.664:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.685:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.719:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.739:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.756:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Findwhat : Cleaned with backup
:mozilla.791:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.792:C:\Documents and Settings\High Energy Entertai\Application Data\Mozilla\Firefox\Profiles\oboilhnl.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\High Energy Entertai\Cookies\high energy [email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\High Energy Entertai\Cookies\high energy [email protected][2].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\High Energy Entertai\Cookies\high energy [email protected][1].txt -> TrackingCookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\High Energy Entertai\Cookies\high energy [email protected][2].txt -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Documents and Settings\High Energy Entertai\Cookies\high energy [email protected][2].txt -> TrackingCookie.Clickzs : Cleaned with backup
C:\Documents and Settings\High Energy Entertai\Cookies\high energy [email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\High Energy Entertai\Cookies\high energy [email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\High Energy Entertai\Cookies\high energy [email protected][1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\High Energy Entertai\Cookies\high energy [email protected][1].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\High Energy Entertai\Cookies\high energy [email protected][1].txt -> TrackingCookie.Sexlist : Cleaned with backup
C:\My Downloads\trilliancrack\Trillian_Pro_v2[1].0_Public_Beta_3_by_MaRKuS.zip/Loader.exe -> Not-A-Virus.VirTool.Win32.Patcher.a : Cleaned with backup
C:\Program Files\Common Files\Uninstall Information\RemoveWebDP.exe -> Adware.DelphinMediaViewer : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000002.dat -> TrackingCookie.Advertising : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000004.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000005.dat -> TrackingCookie.Bfast : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000006.dat -> TrackingCookie.Bridgetrack : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000007.dat -> TrackingCookie.Sextracker : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000008.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000009.dat -> TrackingCookie.Coremetrics : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000012.dat -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000013.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000014.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000015.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000016.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000017.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000020.dat -> TrackingCookie.Tracking101 : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000024.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000027.dat -> TrackingCookie.Sexlist : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000030.dat -> TrackingCookie.Sextracker : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000035.dat -> TrackingCookie.Spylog : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000036.dat -> TrackingCookie.Webtrendslive : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000037.dat -> TrackingCookie.Targetnet : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000040.dat -> TrackingCookie.Directnetadvertising : Cleaned with backup
C:\Program Files\Disspy\Backup\02_19_200601_00_02.zip/0000043.dat -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
C:\Program Files\Disspy\Backup\02_24_200615_28_26.zip/0000000.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\02_24_200615_28_26.zip/0000001.dat -> TrackingCookie.Hitslink : Cleaned with backup
C:\Program Files\Disspy\Backup\03_01_200616_10_11.zip/0000002.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\03_01_200616_10_11.zip/0000003.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\03_02_200613_43_12.zip/0000000.dat -> TrackingCookie.Sextracker : Cleaned with backup
C:\Program Files\Disspy\Backup\03_02_200613_43_12.zip/0000001.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\03_02_200613_43_12.zip/0000002.dat -> TrackingCookie.Sextracker : Cleaned with backup
C:\Program Files\Disspy\Backup\03_05_200614_18_13.zip/0000001.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\03_05_200614_18_13.zip/0000002.dat -> TrackingCookie.Sextracker : Cleaned with backup
C:\Program Files\Disspy\Backup\03_05_200614_18_13.zip/0000003.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\03_05_200614_18_13.zip/0000004.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_05_200614_18_13.zip/0000005.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_05_200614_18_13.zip/0000006.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_05_200614_18_13.zip/0000007.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_05_200614_18_13.zip/0000009.dat -> TrackingCookie.Sexlist : Cleaned with backup
C:\Program Files\Disspy\Backup\03_05_200614_18_13.zip/0000010.dat -> TrackingCookie.Sextracker : Cleaned with backup
C:\Program Files\Disspy\Backup\03_05_200614_18_13.zip/0000011.dat -> TrackingCookie.Directnetadvertising : Cleaned with backup
C:\Program Files\Disspy\Backup\03_06_200612_33_14.zip/0000000.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\03_06_200612_33_14.zip/0000001.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\03_09_200611_52_37.zip/0000001.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\03_09_200611_52_37.zip/0000002.dat -> TrackingCookie.Sextracker : Cleaned with backup
C:\Program Files\Disspy\Backup\03_09_200611_52_37.zip/0000003.dat -> TrackingCookie.Sextracker : Cleaned with backup
C:\Program Files\Disspy\Backup\03_09_200611_52_37.zip/0000004.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\03_09_200611_52_37.zip/0000006.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_09_200611_52_37.zip/0000007.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_09_200611_52_37.zip/0000008.dat -> TrackingCookie.Sexlist : Cleaned with backup
C:\Program Files\Disspy\Backup\03_09_200611_52_37.zip/0000009.dat -> TrackingCookie.Sextracker : Cleaned with backup
C:\Program Files\Disspy\Backup\03_09_200611_52_37.zip/0000011.dat -> TrackingCookie.Directnetadvertising : Cleaned with backup
C:\Program Files\Disspy\Backup\03_12_200600_27_36.zip/0000000.dat -> TrackingCookie.Advertising : Cleaned with backup
C:\Program Files\Disspy\Backup\03_12_200600_27_36.zip/0000002.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\03_12_200600_27_36.zip/0000003.dat -> TrackingCookie.Bfast : Cleaned with backup
C:\Program Files\Disspy\Backup\03_12_200600_27_36.zip/0000004.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\03_12_200600_27_36.zip/0000005.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_12_200600_27_36.zip/0000006.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_12_200600_27_36.zip/0000007.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_12_200600_27_36.zip/0000010.dat -> TrackingCookie.Directnetadvertising : Cleaned with backup
C:\Program Files\Disspy\Backup\03_12_200600_27_39.zip/0000000.dat -> TrackingCookie.Coremetrics : Cleaned with backup
C:\Program Files\Disspy\Backup\03_12_200615_20_22.zip/0000000.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\03_12_200615_20_22.zip/0000001.dat -> TrackingCookie.Sexlist : Cleaned with backup
C:\Program Files\Disspy\Backup\03_14_200611_49_44.zip/0000001.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\03_14_200611_49_44.zip/0000002.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\03_14_200611_49_44.zip/0000003.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_14_200611_49_44.zip/0000004.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_14_200611_49_44.zip/0000005.dat -> TrackingCookie.Hypertracker : Cleaned with backup
C:\Program Files\Disspy\Backup\03_14_200611_49_44.zip/0000007.dat -> TrackingCookie.Sexlist : Cleaned with backup
C:\Program Files\Disspy\Backup\03_14_200611_49_44.zip/0000009.dat -> TrackingCookie.Coremetrics : Cleaned with backup
C:\Program Files\Disspy\Backup\03_15_200610_09_02.zip/0000001.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\03_15_200610_09_02.zip/0000002.dat -> TrackingCookie.Coremetrics : Cleaned with backup
C:\Program Files\Disspy\Backup\03_15_200610_09_02.zip/0000003.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_15_200610_09_02.zip/0000004.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_16_200612_14_10.zip/0000001.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\03_16_200612_14_10.zip/0000002.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\03_16_200612_14_10.zip/0000003.dat -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Program Files\Disspy\Backup\03_16_200612_14_10.zip/0000004.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_16_200612_14_10.zip/0000005.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_16_200612_14_10.zip/0000006.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_16_200612_14_10.zip/0000008.dat -> TrackingCookie.Directnetadvertising : Cleaned with backup
C:\Program Files\Disspy\Backup\03_18_200613_31_06.zip/0000000.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\03_18_200613_31_06.zip/0000001.dat -> TrackingCookie.Bfast : Cleaned with backup
C:\Program Files\Disspy\Backup\03_18_200613_31_06.zip/0000002.dat -> TrackingCookie.Coremetrics : Cleaned with backup
C:\Program Files\Disspy\Backup\03_18_200613_31_06.zip/0000003.dat -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Program Files\Disspy\Backup\03_18_200613_31_06.zip/0000004.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_18_200613_31_06.zip/0000005.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_18_200613_31_06.zip/0000006.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_18_200613_31_06.zip/0000007.dat -> TrackingCookie.Coremetrics : Cleaned with backup
C:\Program Files\Disspy\Backup\03_18_200613_31_06.zip/0000008.dat -> TrackingCookie.Directnetadvertising : Cleaned with backup
C:\Program Files\Disspy\Backup\03_20_200610_05_22.zip/0000001.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\03_22_200608_52_50.zip/0000001.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\03_22_200608_52_50.zip/0000002.dat -> TrackingCookie.Hitslink : Cleaned with backup
C:\Program Files\Disspy\Backup\03_22_200608_52_50.zip/0000003.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\03_22_200608_52_50.zip/0000004.dat -> TrackingCookie.Coremetrics : Cleaned with backup
C:\Program Files\Disspy\Backup\03_22_200608_52_50.zip/0000005.dat -> TrackingCookie.Sexlist : Cleaned with backup
C:\Program Files\Disspy\Backup\03_23_200609_14_25.zip/0000000.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\03_23_200609_14_25.zip/0000001.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\03_23_200609_14_25.zip/0000004.dat -> TrackingCookie.Webtrendslive : Cleaned with backup
C:\Program Files\Disspy\Backup\03_23_200609_14_25.zip/0000005.dat -> TrackingCookie.Directnetadvertising : Cleaned with backup
C:\Program Files\Disspy\Backup\03_23_200620_29_18.zip/0000000.dat -> TrackingCookie.Sextracker : Cleaned with backup
C:\Program Files\Disspy\Backup\03_23_200620_29_18.zip/0000001.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\03_23_200620_29_18.zip/0000002.dat -> TrackingCookie.Sextracker : Cleaned with backup
C:\Program Files\Disspy\Backup\03_25_200611_05_36.zip/0000000.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\03_25_200611_05_36.zip/0000002.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\03_25_200611_05_36.zip/0000005.dat -> TrackingCookie.Sexlist : Cleaned with backup
C:\Program Files\Disspy\Backup\03_27_200611_33_35.zip/0000001.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\03_27_200611_33_35.zip/0000002.dat -> TrackingCookie.Coremetrics : Cleaned with backup
C:\Program Files\Disspy\Backup\03_27_200611_33_35.zip/0000004.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_27_200611_33_35.zip/0000005.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_27_200611_33_35.zip/0000007.dat -> TrackingCookie.Directnetadvertising : Cleaned with backup
C:\Program Files\Disspy\Backup\03_29_200612_41_17.zip/0000000.dat -> TrackingCookie.Sextracker : Cleaned with backup
C:\Program Files\Disspy\Backup\03_29_200612_41_17.zip/0000001.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\03_29_200612_41_17.zip/0000002.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_29_200612_41_17.zip/0000003.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\03_29_200612_41_17.zip/0000005.dat -> TrackingCookie.Sextracker : Cleaned with backup
C:\Program Files\Disspy\Backup\04_01_200617_52_12.zip/0000001.dat -> TrackingCookie.Advertising : Cleaned with backup
C:\Program Files\Disspy\Backup\04_01_200617_52_12.zip/0000002.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\04_01_200617_52_12.zip/0000003.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\04_01_200617_52_12.zip/0000004.dat -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Program Files\Disspy\Backup\04_01_200617_52_12.zip/0000005.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\04_01_200617_52_12.zip/0000006.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\04_01_200617_52_12.zip/0000007.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\04_01_200617_52_12.zip/0000008.dat -> TrackingCookie.Sexlist : Cleaned with backup
C:\Program Files\Disspy\Backup\04_01_200617_52_12.zip/0000009.dat -> TrackingCookie.Directnetadvertising : Cleaned with backup
C:\Program Files\Disspy\Backup\04_02_200613_56_50.zip/0000000.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\04_02_200613_56_50.zip/0000001.dat -> TrackingCookie.Sexlist : Cleaned with backup
C:\Program Files\Disspy\Backup\04_07_200614_02_50.zip/0000000.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\04_07_200614_02_50.zip/0000001.dat -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Program Files\Disspy\Backup\04_07_200614_02_50.zip/0000002.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\04_07_200614_02_50.zip/0000003.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\04_08_200616_12_00.zip/0000001.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\04_08_200616_12_00.zip/0000002.dat -> TrackingCookie.Sexlist : Cleaned with backup
C:\Program Files\Disspy\Backup\04_09_200615_37_12.zip/0000000.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\04_09_200615_37_12.zip/0000001.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\04_09_200615_37_12.zip/0000002.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\04_09_200615_37_12.zip/0000003.dat -> TrackingCookie.Hitbox : Cleaned with backup
C:\Program Files\Disspy\Backup\04_11_200600_54_37.zip/0000002.dat -> TrackingCookie.Atdmt : Cleaned with backup
C:\Program Files\Disspy\Backup\04_11_200600_54_37.zip/0000003.dat -> TrackingCookie.Bfast : Cleaned with backup
C:\Program Files\Disspy\Backup\04_11_200600_54_37.zip/0000004.dat -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Program Files\Disspy\Backup\04_11_200600_54_37.zip/0000005.dat -> TrackingCookie.Doubleclick : Cleaned with backup
C:\SaveInstCsSm.exe/Save.exe -> Adware.SaveNow : Cleaned with backup
C:\SaveInstCsSm.exe/SaveUninst.exe -> Adware.SaveNow : Cleaned with backup
C:\SaveInstCsSm.exe/Save.exe -> Adware.SaveNow : Cleaned with backup
C:\SaveInstCsSm.exe/SaveUninst.exe -> Adware.SaveNow : Cleaned with backup
C:\SaveInstCsSm.exe/Search.exe -> Adware.SaveNow : Cleaned with backup
C:\SaveInstCsSm.exe/Search.exe -> Adware.SaveNow : Cleaned with backup
C:\SaveInstCsSm.exe/DnldStub.exe -> Downloader.Small.kl : Cleaned with backup
C:\SaveInstCsSm.exe/DnldStub.exe -> Downloader.Small.kl : Cleaned with backup
C:\WINNT\system32\biplmaaa.exe -> Downloader.CWS.s : Cleaned with backup


::Report End



Logfile of HijackThis v1.99.1
Scan saved at 10:19:06 AM, on 4/11/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\system32\crypserv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINNT\system32\sesinetd.exe
C:\WINNT\system32\hserver.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINNT\system32\SERVICES.EXE
C:\WINNT\system32\atiptaxx.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINNT\system32\ezSP_Px.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Disspy\Disspy.exe
C:\Program Files\AdsGone\adsgone.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optonline.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://login.passpor...rf?lc=1033&id=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optonline.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://login.passpor...ilogin.srf?id=2
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe,msswip95.exe
F3 - REG:win.ini: run=C:\WINNT\inet20004\services.exe
F2 - REG:system.ini: UserInit=
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {D714A94F-123A-45CC-8F03-040BCAF82AD6} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Zend Studio - {95188727-288F-4581-A48D-EAB3BD027314} - C:\Program Files\Zend\bin\ZendIEToolbar.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINNT\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [WXcmeinst] C:\winnt\system32\muwemafyh.exe
O4 - HKLM\..\Run: [asejet] uyohuvax.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [FastTVSync] "C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [Microsoft standard protector] C:\WINNT\inet20004\socks.exe
O4 - HKLM\..\Run: [adajsaaa] C:\WINNT\system32\adajsaaa.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [CreateCD50] C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE -r
O4 - HKLM\..\RunServices: [asejet] uyohuvax.exe
O4 - HKCU\..\Run: [asejet] uyohuvax.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [Disspy] C:\Program Files\Disspy\Disspy.exe - silent
O4 - HKCU\..\Run: [adajsaaa] C:\WINNT\system32\adajsaaa.exe
O4 - Global Startup: AdsGone 2004.lnk = C:\Program Files\AdsGone\adsgone.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://km.bar.need2f...earch.html?p=KM
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Zend Studio - Debug current page - res://C:\Program Files\Zend\bin\ZendIEToolbar.dll/DebugCurrent.html
O8 - Extra context menu item: Zend Studio - Debug next page - res://C:\Program Files\Zend\bin\ZendIEToolbar.dll/DebugNext.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Voiced Keyboard Homepage - {1ff190e7-38ab-423e-b59c-4d166c2ea5f1} - http://www.yayahoohoo.com (file missing)
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms &] - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms &[ - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RF Toolbar &2 - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Zend Studio Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\Zend\bin\ZendIEToolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: Zend Studio - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\Zend\bin\ZendIEToolbar.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: SWFDecompiler - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\SourceTec\Sothink SWF Decompiler\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Decompiler - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\SourceTec\Sothink SWF Decompiler\InternetExplorer.htm
O9 - Extra button: Flash - {43CF38F3-5AEC-45a3-AD31-04EB06E9C6CA} - C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll (HKCU)
O15 - Trusted Zone: http://linktrader.cyberspacehq.com
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {0837121A-6472-43BD-8A40-D9221FF1C4CE} - http://download.side...22675/sb028.cab
O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - https://www.plaxo.co...laxoInstall.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {1CC506A7-1B8D-11D4-BDD5-0060977007E0} (CrazyTalk Player) - http://plug-in.reall...m/CrazyTalk.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...llInstaller.exe
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg...l_v1-0-3-24.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150...ip/RdxIE601.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots....SDownloader.ocx
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -


Full Edit
Quick Edit Daemon Today, 03:36 PM Post #5


Security Expert


Group: HJT Team
Posts: 754
Joined: 22-June 04
From: UK
Member No.: 959



Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R3 - Default URLSearc
  • 0

#4
williesbest2

williesbest2

    Visiting Staff

  • Member
  • PipPipPip
  • 892 posts
Hi bretamazzeing I will be helping you with your computer today. Please follow my instructions completely and you will be free of malware in no time. If you have any problems or questions please let me know immediately.

1. Fix in HijackThis
Please re-open HijackThis and put checkmarks next to the following entries:

R3 - Default URLSearchHook is missing

F3 - REG:win.ini: run=C:\WINNT\inet20004\services.exe

F2 - REG:system.ini: UserInit=

O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)

O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [WXcmeinst] C:\winnt\system32\muwemafyh.exe
O4 - HKLM\..\Run: [Microsoft standard protector] C:\WINNT\inet20004\socks.exe
O4 - HKLM\..\Run: [adajsaaa] C:\WINNT\system32\adajsaaa.exe
O4 - HKLM\..\Run: [xp_system] C:\WINNT\inet20004\services.exe
O4 - HKCU\..\Run: [adajsaaa] C:\WINNT\system32\adajsaaa.exe
O4 - HKCU\..\Run: [xp_system] C:\WINNT\inet20004\services.exe

O15 - Trusted Zone: http://linktrader.cyberspacehq.com

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150...ip/RdxIE601.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai....02/cpbrkpie.cab

O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
(RXToolbar)

now please close all other windows other than HijackThis and click Fix Checked. Now close HijackThis.

2. Boot into safe mode
  • Restart your computer.
  • When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. When that is completed it will start loading Windows.
  • When you see the screen that has a black and white bar at the bottom stating "Starting Windows", tap the F8 key repeatedly until you get to the Windows 2000 Advanced Options Menu
  • At this menu use the arrow keys to select the Safe Mode option, which is usually the first in the list.
  • Press the enter key.
  • Your computer will continue booting, but now will boot into Safe Mode.
3. Uninstall programs
Please click on Start and then select Control Panel and click Add or Remove programs. Find the following programs and click Remove:

AutoUpdate
inet20004

4. Delete files
Please right click on Start and select Explore. Navigate to the following pathway and delete the file:

C:\winnt\system32\muwemafyh.exe <- you will be deleting the muwemafyh.exe file
C:\WINNT\system32\adajsaaa.exe <- you will be deleting the adajsaaa.exe file

5. Delete folders
Please right click Start and select Explore and navigate to the following pathway and delete the folder:

C:\Program Files\AutoUpdate <- you will be deleting the Autoupdate folder
C:\WINNT\inet20004 <- you will be deleting the inet20004 folder

Please restart your computer into normal mode

6. Panda Activescan
Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report
7. Uninstall list
Open HijackThis, click Config, click Misc Tools
Click "Open Uninstall Manager"
Click "Save List" (generates uninstall_list.txt)
Click Save, copy and paste the results in your next post.

Please post an updated HijackThis log, along with all the requested logs
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP