Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Log [RESOLVED]


  • This topic is locked This topic is locked

#1
Iceblaster

Iceblaster

    Member

  • Member
  • PipPip
  • 17 posts
Logfile of HijackThis v1.99.1
Scan saved at 11:53:09 PM, on 8/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\aspi192038.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\isnotify.exe
C:\WINDOWS\system32\issearch.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\windows\system32\stonedrv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\AIM\aim.exe
C:\Documents and Settings\Administrator.REBORN\Application Data\?ymantec\m?hta.exe
C:\Windows\xpupdate.exe
C:\WINDOWS\system32\taskdir.exe
C:\Program Files\BraveSentry\BraveSentry.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\PROGRA~1\Grisoft\AVGFRE~1\avgwb.dat
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\COMMON~1\YMBOLS~1\scanregw.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Xfire\Xfire.exe
C:\Documents and Settings\Administrator.REBORN\My Documents\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: Acrobat IE Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE083} - C:\WINDOWS\system\ctldlg32.dll
O2 - BHO: (no name) - {5f4c3d09-b3b9-4f88-aa82-31332fee1c08} - C:\WINDOWS\system32\hp100.tmp
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {873eb32d-ae1a-4183-89bd-45a77f761be4} - C:\WINDOWS\system32\ixt0.dll
O2 - BHO: (no name) - {B68C8A40-B22E-4CCE-9F76-0B8C2B677556} - C:\WINDOWS\system32\awtss.dll
O2 - BHO: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
O3 - Toolbar: Safety Bar - {052b12f7-86fa-4921-8482-26c42316b522} - C:\Program Files\Safety Bar\Safety Bar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SpyQuake2.com] C:\Program Files\SpyQuake2.com\Spy-Quake2.exe /h
O4 - HKLM\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\RunServices: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKLM\..\RunServices: [SystemTools] C:\WINDOWS\system32\testtestt.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Vcy] C:\Documents and Settings\Administrator.REBORN\Application Data\?ymantec\m?hta.exe
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKCU\..\Run: [taskdir] C:\WINDOWS\system32\taskdir.exe
O4 - HKCU\..\Run: [BraveSentry] C:\Program Files\BraveSentry\BraveSentry.exe
O4 - HKCU\..\Run: [Aohh] "C:\PROGRA~1\COMMON~1\YMBOLS~1\scanregw.exe" -vt ndrv
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O15 - Trusted Zone: http://www.amaena.com
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O15 - Trusted Zone: http://scanner.sysprotect.com
O15 - Trusted Zone: http://*.systemdoctor.com
O15 - Trusted Zone: http://www.winantivirus.com
O15 - Trusted Zone: http://www.winantiviruspro.com
O15 - Trusted Zone: http://download.cdn.winsoftware.com
O15 - Trusted IP range: http://202.67.220.225
O15 - Trusted IP range: http://59.148.220.121
O15 - Trusted IP range: http://62.4.84.53
O15 - Trusted IP range: http://82.98.235.58
O15 - Trusted IP range: http://85.12.25.90
O16 - DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} (HGPlugin7USA Class) - http://gamedownload....GPlugin7USA.cab
O20 - AppInit_DLLs:
O20 - Winlogon Notify: artm_newreg - C:\Documents and Settings\All Users.WINDOWS\Documents\Settings\artm_new.dll
O20 - Winlogon Notify: awtss - C:\WINDOWS\system32\awtss.dll
O20 - Winlogon Notify: SensSrv - C:\WINDOWS\SYSTEM32\senssrv.dll
O20 - Winlogon Notify: winwil32 - C:\WINDOWS\SYSTEM32\winwil32.dll
O21 - SSODL: altmannsberger - {210b4043-35ca-4aa0-8796-191f9663dfb3} - C:\Documents and Settings\Administrator.REBORN\Application Data\Microsoft\SystemCertificatese.dll
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - C:\WINDOWS\system32\urroxtl.dll
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - C:\WINDOWS\system32\2236_28.dll (file missing)
O21 - SSODL: ggcdMd - {50F5B9E9-FA5F-1343-B48C-53227210DFC6} - C:\WINDOWS\system32\svsr.dll
O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner - C:\WINDOWS\system32\aspi192038.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

bizzam
help is appreciated u guys are the best :whistling:
  • 0

Advertisements


#2
Armodeluxe

Armodeluxe

    Member 2k

  • Retired Staff
  • 2,744 posts
Hi Iveblaster,

Your system is terribly infected. Problem with these infections nowadays is, it causes a lot of damage. Even if we clean the malware off your system, I can't guarantee that your system will be clean afterwards, because these infections/bundles leave a lot of leftovers behind that most scanners won't even recognise and logs won't show.
Also, I can't promise you we can repair all the damage it caused... Even after cleaning the malware, you can still get errors afterwards because of the damage. Solving these is not always possible since it will be searching for a needle in a haystack to find the right cause and solution.
So, we can try to clean this up and do what we can, but keep in mind that we can't solve ALL problems this malware already caused.

Please follow the instructions in the order below. From the moment you're done and post the logs, please don't reboot or shut down the computer until you hear from me again.

1) Download SDFix and save it to your desktop.

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • In Safe Mode, right click the SDFix.zip folder and choose Extract All,
  • Open the extracted folder and double click RunThis.bat to start the script.
  • Type Y to begin the script.
  • It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • Your system will take longer that normal to restart as the fixtool will be running and removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
  • Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log
2) After doing the above post this next log in a seperate post so it doesn't get cut off.

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
  • 0

#3
Iceblaster

Iceblaster

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Sdfix

SDFix Version 1.14
***************

Scan Time/Date:

02:57 PM
Sun 08/20/2006

Microsoft Windows XP [Version 5.1.2600]

Running from directory:
C:\Documents and Settings\Administrator.REBORN\Desktop\SDFix

Stage One...

Checking Services:

Service Name
***********

Service File Path
*************

Deleting Services
**************


Repairing SDBot Registry Changes....

Restoring Microsoft's default Hosts File

Adding Reg Key To Run On Reboot

Stage One Complete...

Rebooting!

Stage Two...

Removing Malware Files and Registry Entries
***********************************

Registry Cleaning Finished...

Checking For Malware Files...

C:\WINDOWS\system32\taskdir.exe

Backing Up and Deleting any Files Found....


Finished :whistling:



hijack this log
Logfile of HijackThis v1.99.1
Scan saved at 3:09:38 PM, on 8/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\aspi192038.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\isnotify.exe
C:\WINDOWS\system32\issearch.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM\aim.exe
C:\Documents and Settings\Administrator.REBORN\Application Data\?ymantec\m?hta.exe
C:\Windows\xpupdate.exe
C:\Program Files\BraveSentry\BraveSentry.exe
C:\PROGRA~1\COMMON~1\YMBOLS~1\scanregw.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrator.REBORN\My Documents\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: Acrobat IE Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE083} - C:\WINDOWS\system\ctldlg32.dll
O2 - BHO: (no name) - {5f4c3d09-b3b9-4f88-aa82-31332fee1c08} - C:\WINDOWS\system32\hp100.tmp (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {873eb32d-ae1a-4183-89bd-45a77f761be4} - C:\WINDOWS\system32\ixt0.dll
O2 - BHO: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
O2 - BHO: (no name) - {DD2DA556-36A9-47C5-9DB1-FC9057368EE7} - C:\WINDOWS\system32\awtss.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
O3 - Toolbar: Safety Bar - {052b12f7-86fa-4921-8482-26c42316b522} - C:\Program Files\Safety Bar\Safety Bar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SpyQuake2.com] C:\Program Files\SpyQuake2.com\Spy-Quake2.exe /h
O4 - HKLM\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunServices: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKLM\..\RunServices: [SystemTools] C:\WINDOWS\system32\testtestt.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Vcy] C:\Documents and Settings\Administrator.REBORN\Application Data\?ymantec\m?hta.exe
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKCU\..\Run: [taskdir] C:\WINDOWS\system32\taskdir.exe
O4 - HKCU\..\Run: [BraveSentry] C:\Program Files\BraveSentry\BraveSentry.exe
O4 - HKCU\..\Run: [Aohh] "C:\PROGRA~1\COMMON~1\YMBOLS~1\scanregw.exe" -vt ndrv
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O15 - Trusted Zone: http://www.amaena.com
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O15 - Trusted Zone: http://scanner.sysprotect.com
O15 - Trusted Zone: http://*.systemdoctor.com
O15 - Trusted Zone: http://www.winantivirus.com
O15 - Trusted Zone: http://www.winantiviruspro.com
O15 - Trusted Zone: http://download.cdn.winsoftware.com
O15 - Trusted IP range: http://202.67.220.225
O15 - Trusted IP range: http://59.148.220.121
O15 - Trusted IP range: http://62.4.84.53
O15 - Trusted IP range: http://82.98.235.58
O15 - Trusted IP range: http://85.12.25.90
O16 - DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} (HGPlugin7USA Class) - http://gamedownload....GPlugin7USA.cab
O20 - AppInit_DLLs:
O20 - Winlogon Notify: artm_newreg - C:\Documents and Settings\All Users.WINDOWS\Documents\Settings\artm_new.dll (file missing)
O20 - Winlogon Notify: awtss - C:\WINDOWS\system32\awtss.dll
O20 - Winlogon Notify: SensSrv - C:\WINDOWS\SYSTEM32\senssrv.dll
O20 - Winlogon Notify: winwil32 - winwil32.dll (file missing)
O21 - SSODL: altmannsberger - {210b4043-35ca-4aa0-8796-191f9663dfb3} - C:\Documents and Settings\Administrator.REBORN\Application Data\Microsoft\SystemCertificatese.dll (file missing)
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - C:\WINDOWS\system32\urroxtl.dll (file missing)
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - C:\WINDOWS\system32\2236_28.dll (file missing)
O21 - SSODL: ggcdMd - {50F5B9E9-FA5F-1343-B48C-53227210DFC6} - C:\WINDOWS\system32\svsr.dll (file missing)
O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner - C:\WINDOWS\system32\aspi192038.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
  • 0

#4
Iceblaster

Iceblaster

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Administrator - 06-08-20 15:11:03.13
ComboFix 06.08.18 - Running from: C:\Program Files\Mozilla Firefox

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Documents and Settings\Administrator.REBORN\Application Data\Install.dat
C:\Program Files\Common Files\Y1123OU.exe
C:\WINDOWS\system32\isnotify.exe
C:\WINDOWS\system32\issearch.exe
C:\WINDOWS\xpupdate.exe
C:\WINDOWS\system32\ixt0.dll
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\All Users.WINDOWS\Documents\Settings
C:\Program Files\ToolBar888
C:\WINDOWS\system32\components
C:\Program Files\Common Files\{50F5B9E8-0708-2057-0924-040719040001}
C:\WINDOWS\system32\isnotify.exe
C:\WINDOWS\system32\issearch.exe
C:\WINDOWS\xpupdate.exe
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\QooBox\Purity\Documents and Settings\Administrator.REBORN\Application Data\YMANTE~1
C:\QooBox\Purity\Documents and Settings\Administrator.REBORN\Application Data\YMANTE~1\m?hta.exe
C:\QooBox\Purity\Program Files\Common Files\YMBOLS~1
C:\QooBox\Purity\Program Files\Common Files\YMBOLS~1\scanregw.exe
C:\QooBox\Purity\Program Files\Common Files\YMBOLS~1\?ymbols


((((((((((((((((((((((((((((((( Files Created from 2006-07-20 to 2006-08-20 ))))))))))))))))))))))))))))))))))


2006-08-20 14:57 90,112 C:\WINDOWS\system32\RegDACL.exe
2006-08-20 14:57 126,976 C:\WINDOWS\system32\zip.exe
2006-08-20 14:57 11,254 C:\WINDOWS\system32\locate.com
2006-08-19 15:18 46,592 C:\WINDOWS\system32\zlbw.dll
2006-08-19 05:16 8,984 C:\WINDOWS\system32\taskdir~.exe
2006-08-19 05:16 37,376 C:\WINDOWS\system32\aspi19938.exe
2006-08-19 05:16 37,376 C:\WINDOWS\system32\aspi192038.exe
2006-08-19 05:15 81,408 C:\WINDOWS\system32\mscdaux.dll
2006-08-19 05:15 63,775 C:\WINDOWS\system32\ipod.raw.exe
2006-08-19 05:15 57,344 C:\WINDOWS\system32\senssrv.dll
2006-08-19 05:15 18,608 C:\WINDOWS\xpupdate.exe
2006-08-19 05:15 15,088 C:\WINDOWS\system32\stonedrv.exe
2006-08-19 05:14 6,790 C:\WINDOWS\system32\dlh9jkdq7.exe
2006-08-19 05:14 6,787 C:\WINDOWS\system32\dlh9jkdq6.exe
2006-08-19 05:14 18,608 C:\WINDOWS\system32\dlh9jkdq2.exe
2006-08-19 05:14 16 C:\WINDOWS\system32\dlh9jkdq8.exe
2006-08-17 19:34 13,844 C:\WINDOWS\system32\emuupuur.exe
2006-08-12 19:34 1,024,310 C:\WINDOWS\system32\sstwa.bak2
2006-08-04 06:53 573,492 C:\WINDOWS\system32\awtss.dll
2006-08-04 06:53 449,360 C:\WINDOWS\system32\sstwa.bak1
2006-08-04 06:50 8,752 C:\WINDOWS\system32\isnotify.exe
2006-08-04 06:50 32,768 C:\WINDOWS\system32\issearch.exe
2006-08-04 06:48 81,920 C:\WINDOWS\system32\alg.dll
2006-08-04 06:48 40,973 C:\WINDOWS\system32\mljgebx.dll
2006-08-04 06:48 2 C:\WINDOWS\system32\wnscpsu.exe
2006-08-01 03:01 466 C:\WINDOWS\system32\register.reg
2006-08-01 03:01 122,880 C:\WINDOWS\system32\regdrop.exe
2006-08-01 02:19 98,304 C:\WINDOWS\system32\CmdLineExt.dll
2006-07-31 21:19 729,088 C:\WINDOWS\iun6002.exe
2006-07-24 20:39 73,216 C:\WINDOWS\ST6UNST.EXE
2006-07-24 20:39 249,856 C:\WINDOWS\Setup1.exe
2006-07-24 20:04 2,297,552 C:\WINDOWS\system32\d3dx9_26.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-08-20 15:12 -------- d-a------ C:\Program Files\Common Files
2006-08-20 15:10 -------- d-------- C:\Program Files\Mozilla Firefox
2006-08-20 15:07 -------- d-------- C:\Documents and Settings\Administrator.REBORN\Application Data\OpenOffice.org2
2006-08-20 15:02 90112 --a------ C:\WINDOWS\system32\RegDACL.exe
2006-08-20 15:02 126976 --a------ C:\WINDOWS\system32\zip.exe
2006-08-20 15:02 11254 --a------ C:\WINDOWS\system32\locate.com
2006-08-20 05:20 -------- d---s---- C:\Documents and Settings\Administrator.REBORN\Application Data\Microsoft
2006-08-20 00:54 -------- d-------- C:\Program Files\Steam
2006-08-19 23:57 -------- d-------- C:\Program Files\Media-Codec
2006-08-19 23:25 777472 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-08-19 23:25 4992 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys
2006-08-19 23:25 4288 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-08-19 23:25 27904 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-08-19 23:25 23424 --a------ C:\WINDOWS\system32\drivers\avgmfrs.sys
2006-08-19 23:25 -------- d-------- C:\Documents and Settings\Administrator.REBORN\Application Data\AVG7
2006-08-19 23:17 -------- d-------- C:\Program Files\CleanUp!
2006-08-19 19:35 1024310 ---hs---- C:\WINDOWS\system32\sstwa.bak2
2006-08-19 15:29 -------- d-------- C:\Documents and Settings\Administrator.REBORN\Application Data\Lavasoft
2006-08-19 15:28 -------- d-------- C:\Program Files\Lavasoft
2006-08-19 15:18 46592 --------- C:\WINDOWS\system32\zlbw.dll
2006-08-19 05:16 8984 --a------ C:\WINDOWS\system32\taskdir~.exe
2006-08-19 05:16 37376 --a------ C:\WINDOWS\system32\aspi19938.exe
2006-08-19 05:16 37376 --a------ C:\WINDOWS\system32\aspi192038.exe
2006-08-19 05:15 81408 --a------ C:\WINDOWS\system32\mscdaux.dll
2006-08-19 05:15 63775 --a------ C:\WINDOWS\system32\ipod.raw.exe
2006-08-19 05:15 57344 --a------ C:\WINDOWS\system32\senssrv.dll
2006-08-19 05:15 15088 --a------ C:\WINDOWS\system32\stonedrv.exe
2006-08-19 05:15 -------- d-------- C:\Program Files\BraveSentry
2006-08-19 05:14 6790 --a------ C:\WINDOWS\system32\dlh9jkdq7.exe
2006-08-19 05:14 6787 --a------ C:\WINDOWS\system32\dlh9jkdq6.exe
2006-08-19 05:14 18608 --a------ C:\WINDOWS\xpupdate.exe
2006-08-19 05:14 18608 --a------ C:\WINDOWS\system32\dlh9jkdq2.exe
2006-08-19 05:14 16 --a------ C:\WINDOWS\system32\dlh9jkdq8.exe
2006-08-19 02:01 -------- d-a------ C:\Program Files\FlashFXP
2006-08-19 01:16 -------- d-------- C:\Program Files\SwiftSwitch
2006-08-18 19:18 -------- d-------- C:\Program Files\UberSoldier
2006-08-18 18:34 -------- d---s---- C:\Program Files\Xfire
2006-08-17 21:17 -------- d-------- C:\Documents and Settings\Administrator.REBORN\Application Data\Macromedia
2006-08-17 19:34 13844 --a------ C:\WINDOWS\system32\emuupuur.exe
2006-08-17 16:13 8752 --a------ C:\WINDOWS\system32\isnotify.exe
2006-08-17 16:13 32768 --a------ C:\WINDOWS\system32\issearch.exe
2006-08-17 15:46 -------- d-------- C:\Program Files\OpenOffice.org 2.0
2006-08-15 19:53 2 --a------ C:\WINDOWS\system32\wnscpsu.exe
2006-08-13 18:46 -------- d-------- C:\Documents and Settings\Administrator.REBORN\Application Data\FlashFXP
2006-08-13 13:49 -------- d-------- C:\Documents and Settings\Administrator.REBORN\Application Data\uTorrent
2006-08-13 11:30 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-08-12 22:18 -------- d-------- C:\Program Files\Sierra
2006-08-12 19:35 -------- d-------- C:\Program Files\uTorrent
2006-08-12 19:35 -------- d-------- C:\Program Files\Safety Bar
2006-08-04 07:43 -------- d-------- C:\Program Files\GameSpy Arcade
2006-08-04 06:53 573492 ---hs---- C:\WINDOWS\system32\awtss.dll
2006-08-04 06:53 449360 ---hs---- C:\WINDOWS\system32\sstwa.bak1
2006-08-04 06:48 81920 --a------ C:\WINDOWS\system32\alg.dll
2006-08-04 06:48 40973 ---hs---- C:\WINDOWS\system32\mljgebx.dll
2006-08-03 08:16 -------- d-------- C:\Program Files\GrabIt
2006-08-03 07:37 -------- d-------- C:\Documents and Settings\Administrator.REBORN\Application Data\Newsbin
2006-08-03 07:26 -------- d-------- C:\Program Files\NewsReactor
2006-08-02 12:07 -------- d-------- C:\Program Files\Activision
2006-08-01 02:19 98304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2006-07-31 21:16 729088 --a------ C:\WINDOWS\iun6002.exe
2006-07-31 09:53 -------- d-------- C:\Program Files\NewsBin
2006-07-31 09:48 -------- d-------- C:\Program Files\NewsLeecher
2006-07-24 20:39 73216 --a------ C:\WINDOWS\ST6UNST.EXE
2006-07-24 20:39 249856 --------- C:\WINDOWS\Setup1.exe
2006-07-24 19:55 223128 --a------ C:\WINDOWS\system32\drivers\dtscsi.sys
2006-07-24 19:55 -------- d-------- C:\Program Files\DAEMON Tools
2006-07-24 19:52 96256 --a------ C:\WINDOWS\system32\drivers\sptd6877.sys
2006-07-24 19:52 643072 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2006-07-24 18:11 -------- d-------- C:\Documents and Settings\Administrator.REBORN\Application Data\teamspeak2
2006-07-23 03:31 -------- d-------- C:\Program Files\Winamp
2006-07-19 00:52 -------- d-------- C:\Documents and Settings\Administrator.REBORN\Application Data\Apple Computer
2006-07-14 22:55 60416 --a------ C:\WINDOWS\ALCFDRTM.EXE
2006-07-11 00:48 -------- d-------- C:\Program Files\QuickPar
2006-07-10 22:39 -------- d-------- C:\Program Files\Teamspeak2_RC2
2006-07-10 18:24 -------- d-------- C:\Documents and Settings\Administrator.REBORN\Application Data\FTPRush
2006-07-08 20:05 -------- d-------- C:\Documents and Settings\Administrator.REBORN\Application Data\Ventrilo
2006-07-08 20:03 -------- d-------- C:\Program Files\Ventrilo
2006-07-08 20:03 -------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
2006-07-07 12:46 -------- d-------- C:\Program Files\WinRAR
2006-06-24 14:59 -------- d-------- C:\Program Files\QuickTime
2006-06-24 14:58 -------- d-------- C:\Program Files\iTunes
2006-06-24 14:58 -------- d-------- C:\Program Files\iPod
2006-06-09 18:38 62 --ahs---- C:\Documents and Settings\Administrator.REBORN\Application Data\desktop.ini


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"SpyQuake2.com"="C:\\Program Files\\SpyQuake2.com\\Spy-Quake2.exe /h"
"stonedrv"="c:\\windows\\system32\\stonedrv.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"Vcy"="C:\\Documents and Settings\\Administrator.REBORN\\Application Data\\?ymantec\\m?hta.exe"
"stonedrv"="c:\\windows\\system32\\stonedrv.exe"
"taskdir"="C:\\WINDOWS\\system32\\taskdir.exe"
"BraveSentry"="C:\\Program Files\\BraveSentry\\BraveSentry.exe"
"Aohh"="\"C:\\PROGRA~1\\COMMON~1\\YMBOLS~1\\scanregw.exe\" -vt ndrv"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservices]
"stonedrv"="c:\\windows\\system32\\stonedrv.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run]
"wininet.dll"="regperf.exe"
"dcomcfg.exe"="dcomcfg.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoResolveTrack"=dword:00000001
"NoLowDiskSpaceChecks"=dword:00000001
"NoActiveDesktop"=dword:00000000
"ClassicShell"=dword:00000000
"ForceActiveDesktopOn"=dword:00000000

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e2,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f3,01,00,00,25,00,00,00,7a,00,00,00,70,00,\
00,00,01,00,00,00

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoResolveTrack"=dword:00000001
"NoLowDiskSpaceChecks"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"DisableTaskMgr"=dword:00000001

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoResolveTrack"=dword:00000001
"NoLowDiskSpaceChecks"=dword:00000001

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"DisableTaskMgr"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"altmannsberger"="{210b4043-35ca-4aa0-8796-191f9663dfb3}"
"{2C1CD3D7-86AC-4068-93BC-A02304BB2236}"="DCOM Server 2236"
"{3F143C3A-1457-6CCA-03A7-7AA23B61E40F}"="OLE Automation Module"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtss
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winwil32


Completion time: Sun 08/20/2006 15:15:01.25
ComboFix.txt
  • 0

#5
Armodeluxe

Armodeluxe

    Member 2k

  • Retired Staff
  • 2,744 posts
Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlog...processutil.htm


Please print out or copy these instructions/tutorial to Notepad as the internet will not be available to you at certain points of the removal process (while in Safe Mode). Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.


1. Download and update Ewido.

First download Ewido anti-spyware from HERE and save that file to your desktop.
This is a 30 day trial of the program
  • Once you have downloaded Ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete, run Ewido and update the definition files.
  • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close Ewido anti-spyware, Do Not run a scan just yet


2. Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
3. Run Smitfraud Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.


4. Clean out your Temporary Internet files. Proceed as follows:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.

5. Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

6. Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.

7. Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Note: IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
8. Close Ewido and Reboot back into Normal Windows Mode

9. Run SmitfraudFix. Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #3 - Delete Trusted zone by typing 3 and press Enter

Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.

10. Please Post the following logs:
  • c:\rapport.txt
  • Ewido log
  • A new HijackThis log
  • A new combofix log
You may need several replies to post the requested logs, otherwise they might get cut off. Please don't reboot or shut down your computer after you've posted the logs until you hear from me again..

  • 0

#6
Iceblaster

Iceblaster

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
SmitFraudFix v2.81

Scan done at 16:30:47.89, Sun 08/20/2006
Run from C:\Documents and Settings\Administrator.REBORN\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"altmannsberger"="{210b4043-35ca-4aa0-8796-191f9663dfb3}"


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{2C1CD3D7-86AC-4068-93BC-A02304BB2236}"="DCOM Server 2236"

[HKEY_CLASSES_ROOT\CLSID\{2C1CD3D7-86AC-4068-93BC-A02304BB2236}\InProcServer32]
@="C:\WINDOWS\system32\2236_28.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{2C1CD3D7-86AC-4068-93BC-A02304BB2236}\InProcServer32]
@="C:\WINDOWS\system32\2236_28.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{3F143C3A-1457-6CCA-03A7-7AA23B61E40F}"="OLE Automation Module"


»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri

C:\WINDOWS\system32\2236_28.dll -> Missing File

C:\Documents and Settings\Administrator.REBORN\Application Data\Microsoft\SystemCertificatese.dll -> Missing File

C:\WINDOWS\system32\urroxtl.dll -> Missing File

C:\WINDOWS\system32\2236_28.dll -> Missing File

C:\WINDOWS\system32\svsr.dll -> Missing File

Edited by Iceblaster, 20 August 2006 - 06:16 PM.

  • 0

#7
Iceblaster

Iceblaster

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
ewdio
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 8:02:54 PM 8/20/2006

+ Scan result:



D:\Windows.old\Program Files\CxtPls\WinGenerics.dll -> Adware.Apropos : Cleaned with backup (quarantined).
D:\Windows.old\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined).
HKU\S-1-5-21-1078081533-602162358-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{052B12F7-86FA-4921-8482-26C42316B522} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1078081533-602162358-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{873EB32D-AE1A-4183-89BD-45A77F761BE4} -> Adware.Generic : Cleaned with backup (quarantined).
D:\Windows.old\Windows\JpeaN4XTx.exe.tcf -> Adware.Midaddle : Cleaned with backup (quarantined).
D:\Windows.old\Windows\4W.exe -> Adware.Midadle : Cleaned with backup (quarantined).
C:\WINDOWS\system32\alg.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\Program Files\DAEMON Tools\SetupDTSB.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\WINDOWS\system32\mljgebx.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\aspi192038.exe -> Backdoor.Rbot.bei : Cleaned with backup (quarantined).
C:\WINDOWS\system32\aspi19938.exe -> Backdoor.Rbot.bei : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\My Documents\WarezP2P_CWS.exe -> Downloader.Small : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{06849E9F-C8D7-4D59-B87D-784B7D6BE083} -> Logger.Agent.io : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE083} -> Logger.Agent.io : Cleaned with backup (quarantined).
HKU\S-1-5-21-1078081533-602162358-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{06849E9F-C8D7-4D59-B87D-784B7D6BE083} -> Logger.Agent.io : Cleaned with backup (quarantined).
C:\WINDOWS\system32\emuupuur.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Local Settings\Temp\q4ybpqoc.exe -> Not-A-Virus.Downloader.Win32.WinFixer.j : Cleaned with backup (quarantined).
:mozilla.208:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.209:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.378:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.379:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.670:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.100:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.101:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.102:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.103:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.104:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.105:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.106:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.107:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.108:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.109:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.10:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.110:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.111:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.112:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.113:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.114:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.115:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.116:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.117:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.118:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.119:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.11:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.120:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.121:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.12:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.13:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.14:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.158:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.15:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.161:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.162:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.16:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.17:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.18:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.19:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.206:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.207:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.20:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.21:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.22:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.23:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.24:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.25:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.26:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.27:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.28:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.29:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.30:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.31:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.32:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.33:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.34:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.35:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.36:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.37:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.38:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.39:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.40:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.41:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.49:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.50:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.511:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.51:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.520:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.52:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.53:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.54:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.555:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.55:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.56:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.577:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.57:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.58:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.59:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.608:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.60:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.613:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.61:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.62:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.63:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.645:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.647:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.64:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.65:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.667:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.66:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.674:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.67:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.68:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.69:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.6:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.703:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.70:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.71:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.728:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.72:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.73:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.74:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.75:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.76:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.77:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.79:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.7:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.80:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.81:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.82:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.83:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.84:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.85:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.863:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.86:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.87:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.88:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.89:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.8:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.92:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.93:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.94:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.95:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.96:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.97:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.98:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.99:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.9:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.216:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.221:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.223:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.224:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.225:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.226:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.226:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.227:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.228:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.245:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.246:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.247:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.393:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.394:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.395:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.595:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.657:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.738:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.756:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.246:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
:mozilla.247:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
:mozilla.248:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
:mozilla.337:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
:mozilla.409:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
:mozilla.218:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.228:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.251:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.252:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.253:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.806:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.807:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.808:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.151:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.152:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.153:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.154:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.155:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.156:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.157:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.206:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.207:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.208:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.209:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.210:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.211:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.212:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.213:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.464:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.465:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.466:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.467:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.468:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][3].txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.906:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
:mozilla.907:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
:mozilla.909:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
:mozilla.912:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
:mozilla.914:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
:mozilla.915:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
:mozilla.178:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.179:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.185:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.186:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.196:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.197:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.198:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.199:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.332:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.333:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.334:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.335:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.336:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.110:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.191:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.68:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt -> TrackingCookie.Bfast : Cleaned with backup (quarantined).
:mozilla.675:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
:mozilla.182:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
:mozilla.204:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
:mozilla.847:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
:mozilla.174:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.175:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.182:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.183:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.184:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.298:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.299:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.848:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.171:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.172:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.173:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.174:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.175:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.176:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.177:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.307:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.308:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.309:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.310:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.311:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.312:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.386:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.387:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.388:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.389:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.390:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.391:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.392:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.766:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
:mozilla.827:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
:mozilla.331:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.332:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.468:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.469:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.492:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.494:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.717:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.718:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.720:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.721:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.798:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.799:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.107:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.301:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.302:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.303:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\
  • 0

#8
Iceblaster

Iceblaster

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
:mozilla.303:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.304:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.305:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.30:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.31:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.32:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.33:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.34:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.35:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.36:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.37:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.38:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.39:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.40:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.41:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.42:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.43:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.173:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.176:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.177:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.178:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.178:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.179:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.180:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.181:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.181:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.187:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.188:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.189:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.190:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.643:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.425:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined).
:mozilla.426:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined).
:mozilla.687:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.768:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.413:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.414:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.415:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.416:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.417:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.418:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.419:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.688:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.689:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.690:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.691:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.692:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.693:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.694:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.695:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.769:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.770:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.771:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.772:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.773:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.774:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.775:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.776:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.101:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.102:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.103:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.104:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.105:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.106:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.107:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.108:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.109:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.110:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.111:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.112:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.113:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.114:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.117:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.118:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.128:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.129:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.130:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.130:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.131:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.131:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.132:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.132:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.133:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.133:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.134:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.134:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.135:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.135:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.136:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.136:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.137:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.137:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.138:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.138:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.139:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.139:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.140:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.140:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.141:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.141:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.142:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.142:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.143:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.143:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.144:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.144:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.145:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.145:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.146:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.146:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.147:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.147:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.148:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.148:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.149:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.549:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.550:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.551:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.552:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.553:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.554:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.172:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined).
:mozilla.783:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
:mozilla.784:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
:mozilla.785:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
:mozilla.593:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
:mozilla.739:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
:mozilla.815:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
:mozilla.185:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.186:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.187:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.188:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.189:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.190:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.191:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.192:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.193:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.194:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.195:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.211:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.212:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.213:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.214:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.215:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.217:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.222:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.225:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.227:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.741:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.742:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.743:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.744:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.760:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.761:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.762:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.763:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.764:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.765:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.126:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.128:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.129:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.130:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.131:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ubn1fgve.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.197:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.198:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.199:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.260:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.262:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.263:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.264:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.265:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.266:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.301:C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cookies.txt.old -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).


::Report end

hijack this
Logfile of HijackThis v1.99.1
Scan saved at 11:15:24 PM, on 11/6/2003
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Administrator.REBORN\My Documents\HijackThis.exe

R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\RunServices: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Vcy] C:\Documents and Settings\Administrator.REBORN\Application Data\?ymantec\m?hta.exe
O4 - HKCU\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKCU\..\Run: [Aohh] "C:\PROGRA~1\COMMON~1\YMBOLS~1\scanregw.exe" -vt ndrv
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} (HGPlugin7USA Class) - http://gamedownload....GPlugin7USA.cab
O20 - AppInit_DLLs:
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - C:\WINDOWS\system32\2236_28.dll (file missing)
O21 - SSODL: ggcdMd - {50F5B9E9-FA5F-1343-B48C-53227210DFC6} - C:\WINDOWS\system32\svsr.dll (file missing)
O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner - C:\WINDOWS\system32\aspi192038.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

Administrator - 03-11-06 23:08:16.51
ComboFix 06.08.18 - Running from: C:\Documents and Settings\Administrator.REBORN\My Documents

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\QooBox\Purity\Documents and Settings\Administrator.REBORN\Application Data\YMANTE~1
C:\QooBox\Purity\Documents and Settings\Administrator.REBORN\Application Data\YMANTE~1\m?hta.exe
C:\QooBox\Purity\Program Files\Common Files\YMBOLS~1
C:\QooBox\Purity\Program Files\Common Files\YMBOLS~1\scanregw.exe
C:\QooBox\Purity\Program Files\Common Files\YMBOLS~1\?ymbols


((((((((((((((((((((((((((((((( Files Created from 2003-10-06 to 2003-11-06 ))))))))))))))))))))))))))))))))))


No new files created in this timespan


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-08-19 22:25 777472 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-08-19 22:25 4992 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys
2006-08-19 22:25 4288 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-08-19 22:25 27904 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-08-19 22:25 23424 --a------ C:\WINDOWS\system32\drivers\avgmfrs.sys
2006-07-24 18:55 223128 --a------ C:\WINDOWS\system32\drivers\dtscsi.sys
2006-07-24 18:52 96256 --a------ C:\WINDOWS\system32\drivers\sptd6877.sys
2006-07-24 18:52 643072 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2006-06-10 17:45 12464 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2006-05-19 16:16 2560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2006-05-19 16:16 2432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2006-05-16 15:23 46080 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2006-05-03 11:50 1540608 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys
2005-12-06 10:11 35328 --a------ C:\WINDOWS\system32\drivers\sfsync03.sys
2005-11-22 08:44 3804416 -ra------ C:\WINDOWS\system32\drivers\alcxwdm.sys
2005-11-03 09:40 63488 --a------ C:\WINDOWS\system32\drivers\sfvfs02.sys
2005-09-30 05:11 78720 --a------ C:\WINDOWS\system32\drivers\Rtnicxp.sys
2005-08-10 07:44 50688 --a------ C:\WINDOWS\system32\drivers\sfdrv01.sys
2005-05-16 08:20 6656 --a------ C:\WINDOWS\system32\drivers\sfhlp02.sys
2005-03-14 13:27 359040 --a------ C:\WINDOWS\system32\drivers\tcpip.sys
2005-02-02 00:21 14408 --a------ C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2005-01-28 12:44 18944 --a------ C:\WINDOWS\system32\drivers\wpdusb.sys
2005-01-18 23:26 451584 --a------ C:\WINDOWS\system32\drivers\mrxsmb.sys
2004-10-08 18:48 262400 --a------ C:\WINDOWS\system32\drivers\http.sys
2004-09-29 17:28 134912 --a------ C:\WINDOWS\system32\drivers\ipnat.sys
2004-08-03 22:08 26496 --a------ C:\WINDOWS\system32\drivers\USBSTOR.SYS
2004-08-03 19:01 40840 --a------ C:\WINDOWS\system32\drivers\termdd.sys
2004-08-03 18:15 82944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2004-08-03 18:15 60800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2004-08-03 18:14 52736 --a------ C:\WINDOWS\system32\drivers\i8042prt.sys
2004-08-03 18:07 6400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2004-08-03 18:07 59264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2004-08-03 18:07 52864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2004-08-03 18:07 46464 --a------ C:\WINDOWS\system32\drivers\GAGP30KX.SYS
2004-08-03 18:07 2944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2004-08-03 18:07 171776 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2004-08-03 17:59 57472 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2004-08-03 17:58 7552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2004-08-03 17:58 5376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2004-08-03 17:58 4992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2004-08-03 17:39 142464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2004-08-03 17:15 145792 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2004-08-03 17:15 140928 --a------ C:\WINDOWS\system32\drivers\ks.sys
2004-08-03 17:08 60288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2004-08-03 17:08 48640 --a------ C:\WINDOWS\system32\drivers\stream.sys
2004-08-03 17:01 196864 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys
2003-11-06 23:03 1024275 ---hs---- C:\WINDOWS\system32\sstwa.bak2


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"stonedrv"="c:\\windows\\system32\\stonedrv.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"Vcy"="C:\\Documents and Settings\\Administrator.REBORN\\Application Data\\?ymantec\\m?hta.exe"
"stonedrv"="c:\\windows\\system32\\stonedrv.exe"
"Aohh"="\"C:\\PROGRA~1\\COMMON~1\\YMBOLS~1\\scanregw.exe\" -vt ndrv"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservices]
"stonedrv"="c:\\windows\\system32\\stonedrv.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoResolveTrack"=dword:00000001
"NoLowDiskSpaceChecks"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoResolveTrack"=dword:00000001
"NoLowDiskSpaceChecks"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"DisableTaskMgr"=dword:00000001

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoResolveTrack"=dword:00000001
"NoLowDiskSpaceChecks"=dword:00000001

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"DisableTaskMgr"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{2C1CD3D7-86AC-4068-93BC-A02304BB2236}"="DCOM Server 2236"
"{3F143C3A-1457-6CCA-03A7-7AA23B61E40F}"="OLE Automation Module"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtss
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winwil32


Completion time: Thu 11/06/2003 23:10:04.75
ComboFix.txt
ComboFix2.txt
  • 0

#9
Armodeluxe

Armodeluxe

    Member 2k

  • Retired Staff
  • 2,744 posts
Ok, good. Ewido got the most dangerous files. Before posting a new HijackThis log, please rename HijackThis.exe to something else like water.exe or food.exe cause you have a Vundo infection hiding from HijackThis.

Open HijackThis and click Scan. Put a check next to these:

R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKLM\..\RunServices: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKCU\..\Run: [Vcy] C:\Documents and Settings\Administrator.REBORN\Application Data\?ymantec\m?hta.exe
O4 - HKCU\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKCU\..\Run: [Aohh] "C:\PROGRA~1\COMMON~1\YMBOLS~1\scanregw.exe" -vt ndrv
O20 - AppInit_DLLs:
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - C:\WINDOWS\system32\2236_28.dll (file missing)
O21 - SSODL: ggcdMd - {50F5B9E9-FA5F-1343-B48C-53227210DFC6} - C:\WINDOWS\system32\svsr.dll (file missing)
O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner - C:\WINDOWS\system32\aspi192038.exe (file missing)


Close all other windows except HijackThis and click Fix Checked.

Go to Start > Run and type this into the run box and click OK.

sc delete aspi113210

Now please copy the following text in the code box to Notepad. Make sure there is no empty line above REGEDIT4. In Notepad go to File > Save As. Name it Fixit.reg, in the drop down box at the bottom choose "All Files", and save it on your desktop. Then double click on Fixit.reg and let it merge with the registry..

REGEDIT4

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"DisableTaskMgr"=dword:00000000

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"DisableTaskMgr"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\sharedtaskscheduler]
"{2C1CD3D7-86AC-4068-93BC-A02304BB2236}"=-
"{3F143C3A-1457-6CCA-03A7-7AA23B61E40F}"=-

Boot into safe mode and delete these files if still present:

C:\WINDOWS\system32\zlbw.dll
C:\WINDOWS\system32\taskdir~.exe
C:\WINDOWS\system32\mscdaux.dll
C:\WINDOWS\system32\ipod.raw.exe
C:\WINDOWS\system32\senssrv.dll
C:\WINDOWS\system32\stonedrv.exe
C:\WINDOWS\system32\dlh9jkdq7.exe
C:\WINDOWS\system32\dlh9jkdq6.exe
C:\WINDOWS\xpupdate.exe
C:\WINDOWS\system32\dlh9jkdq2.exe
C:\WINDOWS\system32\dlh9jkdq8.exe
C:\WINDOWS\system32\wnscpsu.exe

Reboot back to normal mode.

Please download VundoFix.exe
to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above
instructions starting from "Click the Scan for Vundo button." when
VundoFix appears at reboot.
  • 0

#10
Iceblaster

Iceblaster

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
VundoFix V6.1.1

Checking Java version...

Java version is 1.5.0.6

Scan started at 1:56:18 PM 8/21/2006

Listing files found while scanning....

C:\WINDOWS\system32\awtss.dll
C:\WINDOWS\system32\sstwa.ini
C:\WINDOWS\system32\sstwa.bak1
C:\WINDOWS\system32\sstwa.bak2

Beginning removal...

Attempting to delete C:\WINDOWS\system32\awtss.dll
C:\WINDOWS\system32\awtss.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\sstwa.ini
C:\WINDOWS\system32\sstwa.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\sstwa.bak1
C:\WINDOWS\system32\sstwa.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\sstwa.bak2
C:\WINDOWS\system32\sstwa.bak2 Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.1.1

Checking Java version...

Java version is 1.5.0.6

Scan started at 2:06:32 PM 8/21/2006

Listing files found while scanning....

C:\WINDOWS\system32\awtss.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\awtss.dll
C:\WINDOWS\system32\awtss.dll Has been deleted!

Performing Repairs to the registry.
Done!

Logfile of HijackThis v1.99.1
Scan saved at 2:16:10 PM, on 8/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrator.REBORN\My Documents\water.exe.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {B2573CBD-5DEC-4AAD-AF6F-C14DA4FA128C} - C:\WINDOWS\system32\awtss.dll (file missing)
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} (HGPlugin7USA Class) - http://gamedownload....GPlugin7USA.cab
O20 - Winlogon Notify: winwil32 - winwil32.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
  • 0

Advertisements


#11
Armodeluxe

Armodeluxe

    Member 2k

  • Retired Staff
  • 2,744 posts
Open HijackThis and click Scan. Put a check next to these:

O2 - BHO: (no name) - {B2573CBD-5DEC-4AAD-AF6F-C14DA4FA128C} - C:\WINDOWS\system32\awtss.dll (file missing)
O20 - Winlogon Notify: winwil32 - winwil32.dll (file missing)


Close all other windows except HijackThis and click Fix Checked.

Please do an online scan with Kaspersky WebScanner. If you have any quarantined items in your antivirus, please delete those archives before the scan.

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

  • 0

#12
Iceblaster

Iceblaster

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
web site down??
  • 0

#13
Armodeluxe

Armodeluxe

    Member 2k

  • Retired Staff
  • 2,744 posts
Nope, I just checked the link, it's working.

Few possibilities:

Notice! A new version of Kaspersky Virus Scanner was added on August 8, 2006. If you have installed a previous version, you must unistall that program first before installing the new version. To uninstall, please go to the computer control panel and select "Add/Remove Programs." Reboot when done.

If that's not the case, run these programs and then try again:

1) Download the Hoster Here

Unzip Hoster to your desktop

Open up the Hoster program.
  • Make sure that the "make hosts writable?" button in the upper right corner is enabled.
  • Click back up Host files
  • then click Restore orginal host files
  • close program
2) Please download WinHelp2002's DelDomains by right-clicking on the following link, and choosing "Save Target As":
http://www.mvps.org/.../DelDomains.inf
Save the file to the desktop. Then go to the desktop, right click on DelDomains.inf, and choose Install. You may not see any noticeable changes or prompts; this is normal. Then please restart your computer,
  • 0

#14
Iceblaster

Iceblaster

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, August 23, 2006 8:12:06 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 23/08/2006
Kaspersky Anti-Virus database records: 217724
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan Statistics:
Total number of scanned objects: 245562
Number of viruses found: 70
Number of infected objects: 1294 / 0
Number of suspicious objects: 0
Duration of the scan process: 04:09:18

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\My Documents\BSINSTALL.exe/WISE0024.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\Documents and Settings\Administrator\My Documents\BSINSTALL.exe WiseSFX: infected - 1 skipped
C:\Documents and Settings\Administrator\My Documents\BSINSTALL.exe WiseSFX Dropper: infected - 1 skipped
C:\Documents and Settings\Administrator.REBORN\Application Data\Aim\Iceblaster232\cert8.db Object is locked skipped
C:\Documents and Settings\Administrator.REBORN\Application Data\Aim\Iceblaster232\key3.db Object is locked skipped
C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\cert8.db Object is locked skipped
C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\history.dat Object is locked skipped
C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\key3.db Object is locked skipped
C:\Documents and Settings\Administrator.REBORN\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\parent.lock Object is locked skipped
C:\Documents and Settings\Administrator.REBORN\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator.REBORN\Desktop\SDFix\backups\backups.zip/backups/taskdir.exe Infected: Trojan-Proxy.Win32.Lager.aq skipped
C:\Documents and Settings\Administrator.REBORN\Desktop\SDFix\backups\backups.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Administrator.REBORN\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Administrator.REBORN\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator.REBORN\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator.REBORN\Local Settings\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Administrator.REBORN\Local Settings\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Administrator.REBORN\Local Settings\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Administrator.REBORN\Local Settings\Application Data\Mozilla\Firefox\Profiles\fvalxnpf.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Administrator.REBORN\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator.REBORN\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator.REBORN\My Documents\SmitfraudFix.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Administrator.REBORN\My Documents\SmitfraudFix.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Administrator.REBORN\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator.REBORN\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\install\Applications\mIRC\mIRC.exe/data.rar/mIRC/mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
C:\install\Applications\mIRC\mIRC.exe/data.rar Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
C:\install\Applications\mIRC\mIRC.exe RarSFX: infected - 2 skipped
C:\install\wpi\common\cmdow.exe Infected: not-a-virus:RiskTool.Win32.HideWindows skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
C:\Program Files\Steam\Steam.log Object is locked skipped
C:\Program Files\Steam\SteamApps\half-life 2 content.gcf Object is locked skipped
C:\Program Files\Steam\SteamApps\half-life 2 demo.gcf Object is locked skipped
C:\Program Files\Steam\SteamApps\source engine.gcf Object is locked skipped
C:\Program Files\Steam\SteamApps\source materials.gcf Object is locked skipped
C:\Program Files\Steam\SteamApps\source models.gcf Object is locked skipped
C:\Program Files\Steam\SteamApps\source sounds.gcf Object is locked skipped
C:\Program Files\Steam\SteamApps\winui.gcf Object is locked skipped
C:\Program Files\Steam\SteamLogs\SteamStats.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP53\A0028379.exe Object is locked skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP53\A0028394.dll Infected: not-a-virus:AdWare.Win32.Softomate.q skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP53\A0029411.exe Infected: Trojan-Downloader.Win32.Small.dnk skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP53\A0029417.exe Object is locked skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP53\A0029430.dll Infected: not-a-virus:AdWare.Win32.SearchAssistant.h skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP53\A0029431.dll Infected: not-a-virus:AdWare.Win32.SearchAssistant.h skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP53\A0029432.dll Infected: not-a-virus:AdWare.Win32.SearchAssistant.h skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP53\A0029433.dll Infected: not-a-virus:AdWare.Win32.SearchAssistant.h skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP53\A0029444.exe Infected: not-a-virus:Downloader.Win32.Agent.h skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP53\A0029448.exe Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP53\A0029449.dll Infected: not-a-virus:AdWare.Win32.PurityScan.en skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP53\A0029450.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.by skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP53\A0029454.exe Infected: not-a-virus:Downloader.Win32.WinFixer.j skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP53\A0029455.exe Infected: not-a-virus:Downloader.Win32.WinFixer.i skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP54\A0029589.exe Object is locked skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP54\A0029590.dll Infected: Trojan-Downloader.Win32.Agent.aly skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP54\A0029617.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.da skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP54\A0029618.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.da skipped
C:\System Volume Information\_restore{C0E44D59-F8E1-4E06-9398-370744D5A710}\RP63\change.log Object is locked skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP122\A0021656.exe Infected: not-a-virus:AdWare.Win32.Mirar.d skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP122\A0021657.dll Infected: not-a-virus:AdWare.Win32.BookedSpace.g skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP122\A0021658.dll Infected: not-a-virus:AdWare.Win32.BookedSpace.g skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP122\A0021659.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP122\A0021660.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP122\A0021661.exe Infected: not-a-virus:AdWare.Win32.RK.f skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP122\A0021662.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP122\A0021663.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP122\A0021664.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP122\A0021665.dll Infected: not-a-virus:AdWare.Win32.RK.e skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP122\A0021666.exe Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP122\A0021667.dll Infected: not-a-virus:AdWare.Win32.Mirar.b skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP122\A0021668.exe Infected: not-a-virus:AdWare.Win32.BookedSpace.e skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP87\A0012997.dll Infected: not-a-virus:AdWare.Win32.180Solutions.a skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP87\A0013011.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP87\A0013012.dll Infected: not-a-virus:AdWare.Win32.NewDotNet.i skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP87\A0013013.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP87\A0013026.dll Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP87\A0013048.dll Infected: not-a-virus:AdWare.Win32.180Solutions.a skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP87\A0013066.exe Infected: not-a-virus:AdWare.Win32.SurfSide.as skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP87\A0013068.exe/InpB/Ssk.exe Infected: not-a-virus:AdWare.Win32.SurfSide.as skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP87\A0013068.exe/InpB Infected: not-a-virus:AdWare.Win32.SurfSide.as skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP87\A0013068.exe CAB: infected - 2 skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP88\A0016114.dll Infected: not-a-virus:AdWare.Win32.Mirar.e skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP92\A0017349.exe Infected: not-a-virus:Server-Proxy.Win32.MarketScore.k skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP92\A0017365.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP92\A0017368.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.n skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP92\A0017369.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP92\A0017373.exe Infected: Trojan-Downloader.Win32.VB.ys skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP92\A0017376.EXE Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP92\A0017377.exe/data0002 Infected: not-a-virus:AdWare.Win32.BookedSpace.e skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP92\A0017377.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP92\A0017379.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP92\A0017389.dll Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP92\A0017390.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP93\A0017457.exe Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP93\A0017458.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP93\A0017459.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped
C:\System Volume Information\_restore{D8139BB7-B354-4855-BF38-440F3725661C}\RP94\A0018390.dll Infected: not-a-virus:AdWare.Win32.NewDotNet.i skipped
C:\VundoFix Backups\awtss.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.da skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\cmdow.exe Infected: not-a-virus:RiskTool.Win32.HideWindows skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\dtscsi.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd6877.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\78ff506d87a415b775\i386\1394bus.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\4mmdat.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\61883.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\6to4svc.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\ac97ali.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\ac97via.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\access.cp_ Object is locked skipped
D:\78ff506d87a415b775\i386\accwiz.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\acgenral.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\aclayers.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\aclua.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\aclui.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\acpi.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\acspecfc.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\activ.ht_ Object is locked skipped
D:\78ff506d87a415b775\i386\activeds.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\activsvc.ht_ Object is locked skipped
D:\78ff506d87a415b775\i386\actlan.ht_ Object is locked skipped
D:\78ff506d87a415b775\i386\actmovie.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\actshell.ht_ Object is locked skipped
D:\78ff506d87a415b775\i386\actxprxy.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\acxtrnal.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\adcjavas.in_ Object is locked skipped
D:\78ff506d87a415b775\i386\adcvbs.in_ Object is locked skipped
D:\78ff506d87a415b775\i386\adeskerr.ht_ Object is locked skipped
D:\78ff506d87a415b775\i386\admexs.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\admjoy.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\admparse.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\admwprox.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\adojavas.in_ Object is locked skipped
D:\78ff506d87a415b775\i386\adovbs.in_ Object is locked skipped
D:\78ff506d87a415b775\i386\adsiis51.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\adsldp.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\adsldpc.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\adsmsext.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\adsnt.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\adv01nt5.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\adv02nt5.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\adv05nt5.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\adv07nt5.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\adv08nt5.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\adv09nt5.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\adv11nt5.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\advapi32.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\advpack.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\aec.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\afd.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\agentanm.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\agentctl.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\agentdp2.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\agentdpv.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\agentmpx.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\agentpsh.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\agentsr.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\agentsvr.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\agp440.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\agpcpq.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\agtctl15.tl_ Object is locked skipped
D:\78ff506d87a415b775\i386\agtintl.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\agtscrp2.js_ Object is locked skipped
D:\78ff506d87a415b775\i386\agtscrpt.js_ Object is locked skipped
D:\78ff506d87a415b775\i386\ahui.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\alg.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\alim1541.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\alrsvc.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\amdagp.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\amdk6.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\amdk7.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\amstream.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\an983.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\appconf.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\apphelp.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\apphelp.sd_ Object is locked skipped
D:\78ff506d87a415b775\i386\apph_sp.sd_ Object is locked skipped
D:\78ff506d87a415b775\i386\appmgmts.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\appmgr.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\apps.ch_ Object is locked skipped
D:\78ff506d87a415b775\i386\apps_sp.ch_ Object is locked skipped
D:\78ff506d87a415b775\i386\appwiz.cp_ Object is locked skipped
D:\78ff506d87a415b775\i386\aqueue.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\arial.tt_ Object is locked skipped
D:\78ff506d87a415b775\i386\arialbd.tt_ Object is locked skipped
D:\78ff506d87a415b775\i386\arp1394.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\asctrls.oc_ Object is locked skipped
D:\78ff506d87a415b775\i386\asferror.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\asp51.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\asr_fmt.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\asycfilt.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\asyncmac.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\at.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\atapi.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati1btxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati1mdxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati1pdxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati1raxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati1rvxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati1snxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati1ttxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati1tuxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati1xbxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati1xsxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati1xwdm.in_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati2cqag.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati2dvaa.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati2dvag.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati2mtaa.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati2mtag.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati3d1ag.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati3d2ag.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\ati3duag.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\atiixpaa.in_ Object is locked skipped
D:\78ff506d87a415b775\i386\atiixpag.in_ Object is locked skipped
D:\78ff506d87a415b775\i386\atinbtxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\atinmdxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\atinpdxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\atinraxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\atinrvxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\atinsnxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\atinttxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\atintuxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\atinxbxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\atinxsxx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\ativdaxx.ax_ Object is locked skipped
D:\78ff506d87a415b775\i386\ativmc20.co_ Object is locked skipped
D:\78ff506d87a415b775\i386\ativmvxx.ax_ Object is locked skipped
D:\78ff506d87a415b775\i386\ativtmxx.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\ativvaxx.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\atixpwdm.in_ Object is locked skipped
D:\78ff506d87a415b775\i386\atl.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\atm.ch_ Object is locked skipped
D:\78ff506d87a415b775\i386\atmadm.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\atmarpc.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\atmfd.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\atmlane.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\atmlib.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\atv01nt5.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\atv02nt5.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\atv04nt5.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\atv06nt5.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\atv10nt5.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\audiosrv.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\auditusr.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\authz.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\autoconv.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\autolfn.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\autoupdt.ht_ Object is locked skipped
D:\78ff506d87a415b775\i386\au_plcy.ht_ Object is locked skipped
D:\78ff506d87a415b775\i386\avc.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\avcstrm.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\avifil32.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\basesrv.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\batmeter.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\batt.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\bdaplgin.ax_ Object is locked skipped
D:\78ff506d87a415b775\i386\bdasup.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\bidispl.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\bitsprx2.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\bitsprx3.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\blackbox.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\blastcln.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\blutooth.ch_ Object is locked skipped
D:\78ff506d87a415b775\i386\bridge.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\browselc.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\browser.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\browseui.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\browsewm.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\bth.in_ Object is locked skipped
D:\78ff506d87a415b775\i386\bthci.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\bthenum.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\bthmodem.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\bthpan.in_ Object is locked skipped
D:\78ff506d87a415b775\i386\bthpan.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\bthport.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\bthprint.in_ Object is locked skipped
D:\78ff506d87a415b775\i386\bthprint.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\bthprops.cp_ Object is locked skipped
D:\78ff506d87a415b775\i386\bthserv.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\bthspp.in_ Object is locked skipped
D:\78ff506d87a415b775\i386\bthusb.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\btpanui.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cabview.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\callcont.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\camocx.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\catsrv.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\catsrvps.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\catsrvut.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\ccdecode.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\cdfs.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\cdfview.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cdm.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cdosys.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cdrom.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\certcli.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\certmgr.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\certwiz.oc_ Object is locked skipped
D:\78ff506d87a415b775\i386\cewmdm.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cfgbkend.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cfgmgr32.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\ch7xxnt5.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\changer.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\cimwin32.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cimwin32.mf_ Object is locked skipped
D:\78ff506d87a415b775\i386\cimwin32.mo_ Object is locked skipped
D:\78ff506d87a415b775\i386\cinfo.xm_ Object is locked skipped
D:\78ff506d87a415b775\i386\ciodm.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cipher.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\cisvc.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\classpnp.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\clbcatex.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\clbcatq.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cleanmgr.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\cli.mo_ Object is locked skipped
D:\78ff506d87a415b775\i386\cliconfg.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cliconfg.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\cliconfg.rl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cliegali.mf_ Object is locked skipped
D:\78ff506d87a415b775\i386\cliegali.mo_ Object is locked skipped
D:\78ff506d87a415b775\i386\clipbrd.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\clipsrv.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\clusapi.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cmbatt.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\cmcfg32.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cmd.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\cmdial32.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cmdl32.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\cmmon32.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\cmprops.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cmsetacl.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cmstp.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\cmutil.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cnbjmon.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cnbjmon2.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cnfgprts.oc_ Object is locked skipped
D:\78ff506d87a415b775\i386\coadmin.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\colbact.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\comadmin.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\comctl32.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\comdlg32.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\comexp.ch_ Object is locked skipped
D:\78ff506d87a415b775\i386\comic.tt_ Object is locked skipped
D:\78ff506d87a415b775\i386\compact.wm_ Object is locked skipped
D:\78ff506d87a415b775\i386\compatui.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\compfilt.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\compstui.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\comrepl.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\comres.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\comsvcs.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\comuid.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\conf.ad_ Object is locked skipped
D:\78ff506d87a415b775\i386\conf.ch_ Object is locked skipped
D:\78ff506d87a415b775\i386\conf.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\conf.hl_ Object is locked skipped
D:\78ff506d87a415b775\i386\conf1.ch_ Object is locked skipped
D:\78ff506d87a415b775\i386\confmrsl.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\conime.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\connect.cn_ Object is locked skipped
D:\78ff506d87a415b775\i386\connect.hl_ Object is locked skipped
D:\78ff506d87a415b775\i386\corpol.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\courtney.ac_ Object is locked skipped
D:\78ff506d87a415b775\i386\cpanel_p.ch_ Object is locked skipped
D:\78ff506d87a415b775\i386\cpanel_w.ch_ Object is locked skipped
D:\78ff506d87a415b775\i386\credui.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\crusoe.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\crypt32.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cryptdlg.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cryptdll.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cryptext.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cryptnet.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cryptsvc.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cryptui.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cscdll.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cscript.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\cscui.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\csrsrv.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\csrss.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\csv.xs_ Object is locked skipped
D:\78ff506d87a415b775\i386\ctfmon.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\ctmasetp.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\custsat.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\cwrwdm.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\cxthsfs2.ct_ Object is locked skipped
D:\78ff506d87a415b775\i386\c_28603.nl_ Object is locked skipped
D:\78ff506d87a415b775\i386\d3d8.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\d3d8thk.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\d3d9.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\d3dim700.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\danim.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dao360.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dataclen.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dataspec.xm_ Object is locked skipped
D:\78ff506d87a415b775\i386\datetime.ch_ Object is locked skipped
D:\78ff506d87a415b775\i386\davcdata.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\davclnt.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\daxctle.oc_ Object is locked skipped
D:\78ff506d87a415b775\i386\dbmsrpcn.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dbnetlib.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dbnmpntw.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dcache.bi_ Object is locked skipped
D:\78ff506d87a415b775\i386\dcap32.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dciman32.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\ddeshare.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\ddraw.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\ddrawex.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\defrag.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\desk.cp_ Object is locked skipped
D:\78ff506d87a415b775\i386\devenum.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\devmgr.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dfrgfat.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\dfrgntfs.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\dfrgsnap.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dfrgui.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dfsshlex.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dgnet.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dhcpcsvc.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dhtmled.oc_ Object is locked skipped
D:\78ff506d87a415b775\i386\dialer.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\diantz.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\digcore.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\digest.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\digopt.ms_ Object is locked skipped
D:\78ff506d87a415b775\i386\digreqex.ms_ Object is locked skipped
D:\78ff506d87a415b775\i386\dinput.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dinput8.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\directdb.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\disk.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\diskdump.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\diskpart.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\dlimport.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\dllhost.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\dlttape.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\dmadmin.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\dmband.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dmboot.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\dmcompos.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dmdskmgr.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dmime.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dmio.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\dmloader.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dmremote.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\dmscript.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dmserver.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dmstyle.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dmsynth.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dmusic.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dmusic.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\dmutil.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dnsapi.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dnsrslvr.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\docprop2.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dosx.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\dot4.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\dplaysvr.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\dplayx.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dpmodemx.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dpnaddr.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dpnet.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dpnhpast.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dpnhupnp.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dpnlobby.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dpnsvr.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\dpvacm.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dpvoice.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dpvsetup.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\dpvvox.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dpwsockx.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\drm.in_ Object is locked skipped
D:\78ff506d87a415b775\i386\drmclien.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\drmk.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\drmkaud.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\drmstor.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\drmv2clt.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\drprov.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\ds16gt.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\ds32gt.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dsdmo.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dsdmoprp.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dshowext.ax_ Object is locked skipped
D:\78ff506d87a415b775\i386\dskquop.ch_ Object is locked skipped
D:\78ff506d87a415b775\i386\dskquota.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dsound.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dsound3d.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dsprop.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dsprpres.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dsquery.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dssec.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dssenh.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dsuiext.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dswave.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dtsgnup.ht_ Object is locked skipped
D:\78ff506d87a415b775\i386\dumprep.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\duser.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dvdupgrd.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\dwwin.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\dx7vb.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dx8vb.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dxdiag.ch_ Object is locked skipped
D:\78ff506d87a415b775\i386\dxdiag.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\dxdiagn.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dxg.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\dxmasf.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dxtmsft.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\dxtrans.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\earl.ac_ Object is locked skipped
D:\78ff506d87a415b775\i386\efsadu.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\els.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\encapi.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\encdec.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\ep9res.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\epcl5res.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\epn1600.gp_ Object is locked skipped
D:\78ff506d87a415b775\i386\error.js_ Object is locked skipped
D:\78ff506d87a415b775\i386\ersvc.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\es.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\esent.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\esscli.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\essm2e.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\eudcedit.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\evcon.ch_ Object is locked skipped
D:\78ff506d87a415b775\i386\evcreate.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\eventlog.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\evntagnt.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\evntcmd.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\evntrprv.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\evntwin.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\evtgprov.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\explorer.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\expsrv.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\exstrace.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\extmgr.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\extrac32.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\fastfat.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\fastprox.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\faultrep.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fdc.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\fdeploy.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\feclient.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\filefldp.ch_ Object is locked skipped
D:\78ff506d87a415b775\i386\filefldw.ch_ Object is locked skipped
D:\78ff506d87a415b775\i386\filelist.xm_ Object is locked skipped
D:\78ff506d87a415b775\i386\filemgmt.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\file_srv.ch_ Object is locked skipped
D:\78ff506d87a415b775\i386\filters.xm_ Object is locked skipped
D:\78ff506d87a415b775\i386\findstr.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\firewall.cp_ Object is locked skipped
D:\78ff506d87a415b775\i386\flash.oc_ Object is locked skipped
D:\78ff506d87a415b775\i386\fldrclnr.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\flpydisk.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\fltlib.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fltmc.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\fltmgr.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\fontext.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fontview.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\forehe.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\fp4.ca_ Object is locked skipped
D:\78ff506d87a415b775\i386\fp40ext.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fp40ext.in_ Object is locked skipped
D:\78ff506d87a415b775\i386\framebuf.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\framedyn.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fsquirt.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\ftp.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\ftpmib.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\ftpsv251.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fwcfg.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxsapi.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxsclnt.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxscom.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxscomex.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxscover.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxsdrv.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxsevent.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxsext32.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxsmon.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxsocm.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxsocm.in_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxsperf.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxsres.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxsst.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxssvc.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxst30.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxstiff.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxsui.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxswzrd.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\fxsxp32.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\g400.in_ Object is locked skipped
D:\78ff506d87a415b775\i386\gagp30kx.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\gameenum.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\gckernel.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\gdi32.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\georgia.tt_ Object is locked skipped
D:\78ff506d87a415b775\i386\glu32.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\gpedit.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\gpkcsp.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\gpkrsrc.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\gprslt.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\gptext.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\greenshd.gi_ Object is locked skipped
D:\78ff506d87a415b775\i386\grpconv.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\grserial.sy_ Object is locked skipped
D:\78ff506d87a415b775\i386\guitrn.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\guitrn_a.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\gzip.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\h323.ts_ Object is locked skipped
D:\78ff506d87a415b775\i386\h323cc.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\h323msp.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\hal.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\halaacpi.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\halacpi.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\halapic.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\halmacpi.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\halmps.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\halsp.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\hardware.ch_ Object is locked skipped
D:\78ff506d87a415b775\i386\hardware.hl_ Object is locked skipped
D:\78ff506d87a415b775\i386\hccoin.dl_ Object is locked skipped
D:\78ff506d87a415b775\i386\hdwwiz.cp_ Object is locked skipped
D:\78ff506d87a415b775\i386\helpctr.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\helpsvc.ex_ Object is locked skipped
D:\78ff506d87a415b775\i386\hform.xs_ Object is lo
  • 0

#15
Armodeluxe

Armodeluxe

    Member 2k

  • Retired Staff
  • 2,744 posts
The log got cut off cause it was too long to fit into one post. Please check where it was cut off and post the remaining section too.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP