Logfile of HijackThis v1.99.1
Scan saved at 11:08:16, on 15-11-06
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\PDF-XChangeSDKEU\PDFSaver.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpyCatcher 2006\Protector.exe
C:\Program Files\SpyCatcher 2006\Scheduler daemon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher 2006\SCActiveBlock.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl05a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [PDFSaver] C:\Program Files\PDF-XChangeSDKEU\PDFSaver.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher 2006\Scheduler daemon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: PDF-Capture.lnk = C:\Program Files\PDF-XChangeSDKEU\PDFSaver.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups...plorer1_8us.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop...p/PCPitStop.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.truprint....rintActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcaf...90/mcinsctl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {9C024426-7859-4B2D-AB4C-B1E370AE7549} - http://us.mcafee.com...ScannerCtrl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcaf...,23/mcgdmgr.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.c...driveragent.cab
O20 - AppInit_DLLs: interceptor.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IIS Admin (IISADMIN) - Macrovision Corporation - (no file)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
And for added info the AVG and Panda scans are below
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 21:17:13 12-11-06
+ Scan result:
:mozilla.246:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.238:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.239:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.240:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.384:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.170:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.171:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.164:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.165:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.168:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.169:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.108:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Adviva : Cleaned.
:mozilla.31:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.303:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.117:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.118:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.119:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.450:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.16:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.17:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.68:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.237:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.67:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.69:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.155:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.429:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Linksynergy : Cleaned.
:mozilla.430:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Linksynergy : Cleaned.
:mozilla.173:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.174:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.376:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.377:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.472:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.340:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.341:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.342:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.343:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.254:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Quarterserver : Cleaned.
:mozilla.132:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.133:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.134:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.454:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.274:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.275:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.276:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.277:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.278:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.363:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.364:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.458:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.468:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.40:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.41:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.42:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.43:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.437:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Trafic : Cleaned.
:mozilla.183:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.222:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.223:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
::Report end
Incident Status Location
Potentially unwanted tool:application/regclean32 Not disinfected hkey_current_user\software\RegistryOptimizer.com
Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt[.anm.co.uk/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt[.atwola.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt[.realmedia.com/]
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt[.did-it.com/]
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt[.club.cdfreaks.com/]
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt[.cdfreaks.com/]
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\default.z0b\cookies.txt[.club.cdfreaks.com/]
Regards
Dave