I have been experiencing a real slow computer for the past week or so, and it seems to get slower everytime so i finally logged on here for some help. I downloaded the Kaspersky Internet Security 7 to remove these malwares, but they keep showing up everytime. I think i deleted a fair amount of files because of that . Some of them include Virtumonde, CashOn, Vundo, Exploit.Java.Gimsh, Agent, Monder, and many others. I have included the Kaspersky's report, SuperAntiSpyware report, Panda report, and the Hijack this log. I could not get the Malware bytes to run
Thanks in advance!!!
Protection : running
--------------------
Total scanned: 6060
Detected: 29642
Untreated: 0
Attacks blocked: 0
Start time: 2008-06-05 오전 12:24:07
Duration: 00:24:51
Detected
--------
Status Object
------ ------
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.trk File: C:\WINDOWS\system32\efcAQIBQ.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tro File: C:\WINDOWS\SYSTEM32\XXOVGODN.DLL
deleted: Trojan program Trojan-Downloader.Win32.VB.dck Running module: svchost.exe\svchost.exe
deleted: Trojan program Trojan-Downloader.Win32.VB.dck File: C:\WINDOWS\Fonts\svchost.exe
deleted: adware not-a-virus:AdWare.Win32.CashOn.ao File: c:\program files\shopguide\shpguide9c_c.dll//UPX
deleted: adware not-a-virus:AdWare.Win32.CashOn.ar File: c:\program files\webguide\webguide7a_c.dll//UPX
deleted: Trojan program Trojan.Win32.Pakes.cym File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP741\A0073129.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.trl File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP741\A0073133.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.trp File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP741\A0073134.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.trp File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP742\A0073170.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tro File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP744\A0073346.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.trk File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP744\A0073349.dll
deleted: adware not-a-virus:AdWare.Win32.CashOn.ao File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP744\A0073364.dll//UPX
deleted: adware not-a-virus:AdWare.Win32.CashOn.ar File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP744\A0073365.dll//UPX
deleted: Trojan program Exploit.Java.Gimsh.b File: C:\Documents and Settings\James Jun\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-396c70dc-1340662a.zip/vmain.class
disinfected: Trojan program Exploit.Java.Gimsh.b File: C:\Documents and Settings\James Jun\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6b13a7e7-1e967193.zip
deleted: adware not-a-virus:AdWare.Win32.Agent.vm File: C:\Documents and Settings\James Jun\Local Settings\Temp\tem18.tmp.exe//data0002
deleted: adware not-a-virus:AdWare.Win32.Agent.jb File: C:\Documents and Settings\James Jun\Local Settings\Temp\tem1C.tmp.exe//data0002
deleted: adware not-a-virus:AdWare.Win32.Agent.vm File: C:\Documents and Settings\James Jun\Local Settings\Temp\upd20.tmp.exe
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.trp File: C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\SBCDITM1\kb456456[2]
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tro File: C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\SBCDITM1\kb516107[1]
deleted: Trojan program Exploit.HTML.CodeBaseExec File: C:\Documents and Settings\owner\Local Settings\Temporary Internet Files\Content.IE5\MX3SXK3Q\ysb_downloads_manager[1].htm
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tsk File: C:\Documents and Settings\test\Local Settings\Temporary Internet Files\Content.IE5\FX5RCJ7O\kb456456[1]
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tsm File: C:\Documents and Settings\test\Local Settings\Temporary Internet Files\Content.IE5\FX5RCJ7O\kb516107[1]
deleted: adware not-a-virus:AdWare.Win32.Agent.vm File: C:\Program Files\ContextTool\ContextTool-2.dll
deleted: Trojan program Trojan-Downloader.Win32.VB.dck File: C:\WINDOWS\Fonts\a.zip/Setup.exe
deleted: Trojan program Trojan-Downloader.Win32.VB.dck File: C:\WINDOWS\Fonts\Setup.exe
disinfected: Trojan program Trojan-Downloader.Win32.VB.dck File: C:\WINDOWS\Fonts\'\!Easy ScreenSaver Studio 4.0.zip
disinfected: Trojan program Trojan-Downloader.Win32.VB.dck File: C:\WINDOWS\Fonts\'\Zylom Text Express DELUXE v1.4.0.zip
disinfected: Trojan program Trojan-Downloader.Win32.VB.dck File: C:\WINDOWS\Fonts\'\Zylom The legend of El Dorado Deluxe v1.0.zip
disinfected: Trojan program Trojan-Downloader.Win32.VB.dck File: C:\WINDOWS\Fonts\'\ZZZ Capture Flash 1.0.0.zip
disinfected: Trojan program Trojan-Downloader.Win32.VB.dck File: C:\WINDOWS\Fonts\'\ZZZ FLV to AVI Converter 1.xx.zip
disinfected: Trojan program Trojan-Downloader.Win32.VB.dck File: C:\WINDOWS\Fonts\'\[Utilities] Strata Foto 3D.zip
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.trv File: C:\WINDOWS\system32\clxyrqmv.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tsm File: C:\WINDOWS\system32\fbswyuhk.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tsm File: C:\WINDOWS\system32\mpqwhuwy.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tsm File: C:\WINDOWS\system32\nuniskpv.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.trd File: C:\WINDOWS\system32\pgtfcelt.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tro File: C:\WINDOWS\system32\psgcaofd.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tsk File: C:\WINDOWS\system32\qmlaglho.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tro File: C:\WINDOWS\system32\tkeeqjfo.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.trp File: C:\WINDOWS\system32\ukrqicog.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tsk File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP742\A0073171.dll
deleted: Trojan program Trojan-Downloader.Win32.VB.dck File: c:\windows\fonts\'\a-one dvd to mp3 ripper 4.22.zip/Setup.exe
deleted: Trojan program Trojan-Downloader.Win32.VB.dck File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP744\A0073366.exe
detected: riskware Hidden data sending Running process: C:\WINDOWS\explorer.exe
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tsk File: C:\WINDOWS\SYSTEM32\RAJKLNAL.DLL
deleted: adware not-a-virus:AdWare.Win32.Agent.vm File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP744\A0073371.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.vqd File: C:\WINDOWS\system32\gexpcrek.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.vqh File: C:\WINDOWS\SYSTEM32\JONSJFBE.DLL
deleted: adware not-a-virus:AdWare.Win32.CashOn.ao File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP746\A0074412.dll//UPX
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.vqf File: C:\DOCUME~1\555\LOCALS~1\Temp\kdxjieci.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.vqf File: C:\Documents and Settings\555\Local Settings\Temporary Internet Files\Content.IE5\SNS5IDUB\kb516107[1]
detected: riskware Hidden data sending Running process: C:\WINDOWS\Explorer.EXE
deleted: Trojan program Trojan.Win32.Monder.le File: C:\Documents and Settings\555\Local Settings\Temporary Internet Files\Content.IE5\6TWLQV2F\kb456456[1]
deleted: Trojan program Trojan.Win32.Monder.le File: C:\Documents and Settings\555\Local Settings\Temp\ovkfnebj.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.wdd File: C:\Documents and Settings\555\Local Settings\Temporary Internet Files\Content.IE5\SNS5IDUB\kb767887[1]
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.wdd File: C:\Documents and Settings\555\Local Settings\Temp\nnrpmgej.dll
detected: adware not-a-virus:AdWare.Win32.Virtumonde.wpv URL: http://62.4.83.200/w...e...E69&rid=mm2
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.wpu File: C:\WINDOWS\system32\egabfyap.dll
blocked: phishing address http://winanonymous.com/* URL: http://winanonymous....i..._4260&rdr=2
blocked: phishing address http://winanonymous.com/* URL: http://winanonymous.com/favicon.ico
deleted: adware not-a-virus:AdWare.Win32.CashOn.ar File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP746\A0074413.dll//UPX
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tsk File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP746\A0075391.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.wpu File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP747\A0077792.dll
not found: adware not-a-virus:AdWare.Win32.Virtumonde.wpu File: C:\Documents and Settings\555\Local Settings\Temporary Internet Files\Content.IE5\KNC38BC5\kb456456[1]
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.trc File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP740\A0073106.dll
not found: Trojan program Trojan-Downloader.Win32.VB.dck File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP744\A0073372.exe
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.trv File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP744\A0073373.dll
not found: adware not-a-virus:AdWare.Win32.Virtumonde.tsm File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP744\A0073374.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tsm File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP744\A0073375.dll
not found: adware not-a-virus:AdWare.Win32.Virtumonde.tsm File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP744\A0073376.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.trd File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP744\A0073377.dll
not found: adware not-a-virus:AdWare.Win32.Virtumonde.tro File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP744\A0073378.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tsk File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP744\A0073379.dll
not found: adware not-a-virus:AdWare.Win32.Virtumonde.tro File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP744\A0073380.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.trp File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP744\A0073381.dll
not found: adware not-a-virus:AdWare.Win32.Virtumonde.vqd File: C:\Documents and Settings\test\Local Settings\Temporary Internet Files\Content.IE5\YGW5JCML\kb456456[1]
deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\system32\ujpfpkck.dll
deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\MBMMONET.DLL
not found: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\system32\MBMMONET.DLL.kav
deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\system32\dcmcgfwp.dll
deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\system32\dbuhfpii.dll
not found: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\system32\dbuhfpii.dll.kav
deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Documents and Settings\test\Local Settings\Temporary Internet Files\Content.IE5\3ILFG6YK\kb767887[2]
detected: Trojan program Trojan.Win32.Monder.gen URL: http://85.17.166.168...2CD7AEC344C7E69
blocked: phishing address http://winanonymous.com/* URL: http://winanonymous....i..._4260&rdr=2
deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Documents and Settings\test\Local Settings\Temporary Internet Files\Content.IE5\3ILFG6YK\kb456456[1]
detected: Trojan program Trojan.Win32.Monder.gen URL: http://89.188.16.29/...?...E69&rid=mm2
deleted: Trojan program Trojan.Win32.Monder.gen File: C:\DOCUME~1\test\LOCALS~1\Temp\aqbjgelu.dll
blocked: phishing address http://winanonymous.com/* URL: http://winanonymous....i..._4260&rdr=2
deleted: adware not-a-virus:AdWare.Win32.CashOn.ao File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP749\A0078863.dll//UPX
deleted: Trojan program Trojan.Win32.Monder.gen File: C:\DOCUMENTS AND SETTINGS\JAMES JUN\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\8LGF0ZSV\KB456456[1]
deleted: Trojan program Trojan.Win32.Monder.gen File: C:\DOCUMENTS AND SETTINGS\JAMES JUN\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\8LGF0ZSV\KB767887[1]
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.vqh File: C:\DOCUMENTS AND SETTINGS\JAMES JUN\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\O1KHE7KD\KB516107[2]
deleted: adware not-a-virus:AdWare.Win32.CashOn.ar File: C:\System Volume Information\_restore{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP749\A0078864.dll//UPX
deleted: Trojan program Trojan.Win32.Monder.gen File: C:\SYSTEM VOLUME INFORMATION\_RESTORE{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP749\A0081854.DLL
SUPERAntiSpyware Scan Log
Generated 06/04/2008 at 08:53 PM
Application Version : 3.6.1000
Core Rules Database Version : 3474
Trace Rules Database Version: 1465
Scan type : Complete Scan
Total Scan Time : 02:56:53
Memory items scanned : 418
Memory threats detected : 0
Registry items scanned : 5907
Registry threats detected : 11
File items scanned : 134263
File threats detected : 120
Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{0CF5D165-517E-48B6-B3C7-3054A24F8BF6}
HKCR\CLSID\{0CF5D165-517E-48B6-B3C7-3054A24F8BF6}
HKCR\CLSID\{0CF5D165-517E-48B6-B3C7-3054A24F8BF6}\InprocServer32
HKCR\CLSID\{0CF5D165-517E-48B6-B3C7-3054A24F8BF6}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\EFCAQIBQ.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0CF5D165-517E-48B6-B3C7-3054A24F8BF6}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{0CF5D165-517E-48B6-B3C7-3054A24F8BF6}
HKCR\CLSID\{0CF5D165-517E-48B6-B3C7-3054A24F8BF6}
C:\SYSTEM VOLUME INFORMATION\_RESTORE{FB2DAEDB-FEC4-4398-96BD-AE64087A529C}\RP739\A0073086.DLL
Adware.Tracking Cookie
C:\Documents and Settings\555\Cookies\555@adnetserver[1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@2o7[2].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@ad-dtv[2].txt
C:\Documents and Settings\James Jun\Cookies\james jun@ad-indicator[1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][2].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][2].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][2].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][2].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@adbrite[1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@adcentriconline[1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@adecn[2].txt
C:\Documents and Settings\James Jun\Cookies\james jun@adnetserver[1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@adorigin[1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][2].txt
C:\Documents and Settings\James Jun\Cookies\james jun@adsrevenue[1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@adultadworld[1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@apmebf[1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@atdmt[2].txt
C:\Documents and Settings\James Jun\Cookies\james jun@atwola[1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@avsmedia[1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][2].txt
C:\Documents and Settings\James Jun\Cookies\james jun@banner[1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@chordfind[1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@clickbank[1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@clicksor[2].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][2].txt
C:\Documents and Settings\James Jun\Cookies\james jun@clicktorrent[1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@cpvfeed[2].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][2].txt
C:\Documents and Settings\James Jun\Cookies\james jun@doubleclick[1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@fastclick[1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@findarticles[2].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][2].txt
C:\Documents and Settings\James Jun\Cookies\james jun@freeadultmedia[1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@hitbox[2].txt
C:\Documents and Settings\James Jun\Cookies\james jun@hornymatches[2].txt
C:\Documents and Settings\James Jun\Cookies\james jun@hotbar[2].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@likecrack[1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][2].txt
C:\Documents and Settings\James Jun\Cookies\james jun@mediatraffic[1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@media[2].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][2].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][2].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][2].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@pornbase[2].txt
C:\Documents and Settings\James Jun\Cookies\james jun@pornoinside[1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][2].txt
C:\Documents and Settings\James Jun\Cookies\james jun@screensavers[1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@serving-sys[1].txt
C:\Documents and Settings\James Jun\Cookies\james jun@smartadserver[1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][2].txt
C:\Documents and Settings\James Jun\Cookies\james jun@traffic-tracker[1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][2].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][1].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][2].txt
C:\Documents and Settings\James Jun\Cookies\james [email protected][2].txt
C:\Documents and Settings\James Jun\Cookies\james jun@youporns[2].txt
C:\Documents and Settings\James Jun\Cookies\james jun@zedo[2].txt
Adware.Vundo Variant/Rel
HKLM\SOFTWARE\Microsoft\aoprndtws
HKLM\SOFTWARE\Microsoft\FCOVM
HKLM\SOFTWARE\Microsoft\RemoveRP
HKU\S-1-5-21-1482476501-329068152-725345543-1008\Software\Microsoft\rdfa
Trojan.Unknown Origin
C:\DOCUMENTS AND SETTINGS\JAMES JUN\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\C7KXMNI1\KB713501[1]
C:\WINDOWS\SYSTEM32\DGPYXJOM.EXE
C:\WINDOWS\SYSTEM32\EUHGWSKH.EXE
C:\WINDOWS\SYSTEM32\FWVYQWMI.EXE
C:\WINDOWS\SYSTEM32\NRACEQVM.EXE
C:\WINDOWS\SYSTEM32\OYSAQVDT.EXE
C:\WINDOWS\SYSTEM32\QAUWDQYM.EXE
C:\WINDOWS\SYSTEM32\TIVBLVHS.EXE
C:\WINDOWS\SYSTEM32\VRPATWWK.EXE
C:\WINDOWS\SYSTEM32\WCUPMXQE.EXE
C:\WINDOWS\SYSTEM32\WYCWBGEG.EXE
C:\WINDOWS\SYSTEM32\XAPCKGWY.EXE
C:\WINDOWS\SYSTEM32\XHNYTKDM.EXE
C:\WINDOWS\SYSTEM32\XKJDOLQU.EXE
Trace.Known Threat Sources
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\C7KXMNI1\i53b_bg1[1].gif
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\SBCDITM1\i53b_icon3[1].gif
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\C7KXMNI1\stats[1].jpg
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\2TUJCPEX\i53b_brd-top-1[1].gif
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\2TUJCPEX\crypt[1].htm
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\C7KXMNI1\i53b_boton2[1].gif
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\C7KXMNI1\i53b_brd-bot-1[1].gif
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\SBCDITM1\i53b_btn-updates[1].gif
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\C7KXMNI1\i53b_icon1[1].gif
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\C7KXMNI1\i53b_btn-overview[1].gif
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\6V65KV63\errorhandler[1].htm
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\2TUJCPEX\i53b_btn-features[1].gif
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\C7KXMNI1\i53b_t1[1].gif
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\2TUJCPEX\i53b_line2[1].gif
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\2TUJCPEX\CAG1AF4X.htm
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\SBCDITM1\i53b_icon5[1].gif
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\6V65KV63\i53b_btn-home[1].gif
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\6V65KV63\i53b_line3[1].gif
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\SBCDITM1\managers[1].htm
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\SBCDITM1\i53b_btn-purchase[1].gif
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\2TUJCPEX\i53b_btn-download[1].gif
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\SBCDITM1\CASDY3GL.htm
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\6V65KV63\CAIZUNUL.htm
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\2TUJCPEX\i53b_boton4[1].gif
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\O1KHE7KD\CARYS371.htm
C:\Documents and Settings\James Jun\Local Settings\Temporary Internet Files\Content.IE5\8LGF0ZSV\CAC1MB4L.htm
;*******************************************************************************
********************************************************************************
*
*******************
ANALYSIS: 2008-06-05 00:20:21
PROTECTIONS: 2
MALWARE: 63
SUSPECTS: 1
;*******************************************************************************
********************************************************************************
*
*******************
PROTECTIONS
Description Version Active Updated
;===============================================================================
================================================================================
=
===================
Avira AntiVir Windows Workstation 0.0.0.0 No No
Kaspersky Internet Security 7.0.1.325 Yes Yes
;===============================================================================
================================================================================
=
===================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===============================================================================
================================================================================
=
===================
00139059 Cookie/Traffic Marketplace TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.trafficmp.com/]
00139059 Cookie/Traffic Marketplace TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.trafficmp.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\test\Application Data\Mozilla\Firefox\Profiles\kvabs16r.default\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\555\Cookies\555@casalemedia[1].txt
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\test\Application Data\Mozilla\Firefox\Profiles\kvabs16r.default\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\test\Application Data\Mozilla\Firefox\Profiles\kvabs16r.default\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\555\Application Data\Mozilla\Firefox\Profiles\9tlq6kdf.default\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\555\Application Data\Mozilla\Firefox\Profiles\9tlq6kdf.default\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\555\Application Data\Mozilla\Firefox\Profiles\9tlq6kdf.default\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\555\Application Data\Mozilla\Firefox\Profiles\9tlq6kdf.default\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\555\Application Data\Mozilla\Firefox\Profiles\9tlq6kdf.default\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\555\Application Data\Mozilla\Firefox\Profiles\9tlq6kdf.default\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\555\Application Data\Mozilla\Firefox\Profiles\9tlq6kdf.default\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\test\Application Data\Mozilla\Firefox\Profiles\kvabs16r.default\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\test\Application Data\Mozilla\Firefox\Profiles\kvabs16r.default\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\555\Application Data\Mozilla\Firefox\Profiles\9tlq6kdf.default\cookies.txt[.casalemedia.com/]
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\test\Application Data\Mozilla\Firefox\Profiles\kvabs16r.default\cookies.txt[.doubleclick.net/]
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\555\Application Data\Mozilla\Firefox\Profiles\9tlq6kdf.default\cookies.txt[.doubleclick.net/]
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.doubleclick.net/]
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.doubleclick.net/]
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.atdmt.com/]
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.atdmt.com/]
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\test\Application Data\Mozilla\Firefox\Profiles\kvabs16r.default\cookies.txt[.atdmt.com/]
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\555\Application Data\Mozilla\Firefox\Profiles\9tlq6kdf.default\cookies.txt[.atdmt.com/]
00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\555\Application Data\Mozilla\Firefox\Profiles\9tlq6kdf.default\cookies.txt[.tradedoubler.com/]
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\test\Application Data\Mozilla\Firefox\Profiles\kvabs16r.default\cookies.txt[.247realmedia.com/]
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.247realmedia.com/]
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\test\Application Data\Mozilla\Firefox\Profiles\kvabs16r.default\cookies.txt[.247realmedia.com/]
00145433 Cookie/Mammamediasolutions TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.targetnet.com/]
00145453 Cookie/Bfast TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.bfast.com/]
00145453 Cookie/Bfast TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.bfast.com/]
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\test\Application Data\Mozilla\Firefox\Profiles\kvabs16r.default\cookies.txt[.fastclick.net/]
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\555\Application Data\Mozilla\Firefox\Profiles\9tlq6kdf.default\cookies.txt[.fastclick.net/]
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.fastclick.net/]
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\555\Application Data\Mozilla\Firefox\Profiles\9tlq6kdf.default\cookies.txt[.fastclick.net/]
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\555\Application Data\Mozilla\Firefox\Profiles\9tlq6kdf.default\cookies.txt[.fastclick.net/]
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\555\Application Data\Mozilla\Firefox\Profiles\9tlq6kdf.default\cookies.txt[.tribalfusion.com/]
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.tribalfusion.com/]
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\test\Application Data\Mozilla\Firefox\Profiles\kvabs16r.default\cookies.txt[.tribalfusion.com/]
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.mediaplex.com/]
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.mediaplex.com/]
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\test\Application Data\Mozilla\Firefox\Profiles\kvabs16r.default\cookies.txt[.mediaplex.com/]
00145792 Cookie/SexList TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.sexlist.com/]
00145792 Cookie/SexList TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.sexlist.com/]
00145792 Cookie/SexList TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.sexlist.com/]
00145792 Cookie/SexList TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.sexlist.com/]
00145792 Cookie/SexList TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.sexlist.com/]
00145807 Cookie/Linksynergy TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.linksynergy.com/]
00145807 Cookie/Linksynergy TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.linksynergy.com/]
00147806 Cookie/7search TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.7search.com/]
00147806 Cookie/7search TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.7search.com/]
00147824 Cookie/Clickbank TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.clickbank.net/]
00149064 Cookie/Maxserving TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.maxserving.com/]
00159564 Cookie/WUpd TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.revenue.net/]
00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.com.com/]
00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.com.com/]
00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\test\Application Data\Mozilla\Firefox\Profiles\kvabs16r.default\cookies.txt[.com.com/]
00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\555\Application Data\Mozilla\Firefox\Profiles\9tlq6kdf.default\cookies.txt[.com.com/]
00167647 Cookie/Yadro TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.yadro.ru/]
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\test\Application Data\Mozilla\Firefox\Profiles\kvabs16r.default\cookies.txt[.xiti.com/]
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.xiti.com/]
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.xiti.com/]
00167724 Cookie/HotLog TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.hotlog.ru/]
00167744 Cookie/GoStats TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.gostats.com/]
00167744 Cookie/GoStats TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.gostats.com/]
00167744 Cookie/GoStats TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.gostats.com/]
00167744 Cookie/GoStats TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.gostats.com/]
00167744 Cookie/GoStats TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.gostats.com/]
00167744 Cookie/GoStats TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.gostats.com/]
00167744 Cookie/GoStats TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.gostats.com/]
00167744 Cookie/GoStats TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.gostats.com/]
00167749 Cookie/Toplist TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.toplist.cz/]
00167749 Cookie/Toplist TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.toplist.cz/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\555\Application Data\Mozilla\Firefox\Profiles\9tlq6kdf.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\James Jun\Application Data\Mozilla\Firefox\Profiles\n7lf11n2.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Data\Mozilla\Firefox\Profiles\4ymkg2it.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\owner\Application Da
Edited by jsh911119, 11 June 2008 - 08:12 PM.