had some problems recently which i was able to fix with help from this site, but unfortunately for some reason it deleted my AVAST after trying to uninstall and reinstall it the computer would not run I was finally able to download and run AVG free which came with a whole list of viruses and deleted much of my windows files
i'm including the HiJack this log the Malware log and the logs I have from AVG that ran.......however at this point most of my system files are missing and there are several processes and programs running that I have never heard of and all my restore points are gone I'm thinking at this point its gonna have to be a full system format and reload but if someone could help me so i dont have to that would be great ty again
ALSO my users have gone from the computer and the hourglass never disappears from the screen
.........
HiJack This Dated Dec 21
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:22:39 PM, on 12/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system\msservice.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - E:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - E:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O15 - Trusted Zone: *.hotmail.com
O15 - Trusted Zone: *.live.com
O15 - Trusted Zone: *.msn.com
O15 - Trusted Zone: *.passport.com
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Bejeweled Twist\Images\stg_drm.ocx
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinn...GamesLoader.cab
O16 - DPF: {21BB8360-F943-447E-98F3-3C22345375A7} (CPlayFirstChocolatieControl Object) - http://zone.msn.com/...eb.1.0.0.15.cab
O16 - DPF: {226ACC34-3194-70E2-5AE7-864FCFE9E80D} (CPlayFirstmsiControl Object) - http://zone.msn.com/...msi.1.0.0.9.cab
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/...nx.1.0.0.87.cab
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://www.pogo.com/...erInstaller.CAB
O16 - DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8} (SolitaireRush Control) - http://www.worldwinn...litairerush.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} - http://zone.msn.com/...pcaploader1.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail....es/MSNPUpld.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinn...jattack/bja.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinn...d/bejeweled.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://zone.msn.com/...h2.1.0.0.68.cab
O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/...t/atomaders.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/...mjolauncher.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinn...ed/wwlaunch.cab
O16 - DPF: {935F9B04-0C7B-4454-A391-348C54AD7ADD} (Jolly Bear Games Player) - http://games.bigfish...BGamePlayer.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinn...jo/wordmojo.cab
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://www.worldwinn...cubis/cubis.cab
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinn...v46/sol/sol.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://cdn2.zone.msn...gr.cab31267.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinn...apit/swapit.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadbl...ivex/sabspx.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn...ro.cab56649.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://zone.msn.com/...tg.1.0.0.37.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://caebmm.imgag....crusher-cae.cab
O16 - DPF: {C7E002D6-324B-4500-883D-84B620FD8640} (Bridge Installer) - http://cdn2.zone.msn...6/heartbeat.cab
O16 - DPF: {C86FF4B0-AA1D-46D4-8612-025FB86583C7} (AstoundLauncher Control) - http://zone.msn.com/...undLauncher.cab
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) - http://www.worldwinn...paint/paint.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Forgotten Riddles - The Mayan Princess\Images\armhelper.ocx
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - http://www.worldwinn.../familyfeud.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/...outLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/...inematycoon.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://zone.msn.com/...sh.1.0.0.98.cab
O16 - DPF: {E12EB891-D000-421B-A8ED-EDE1BDCA14A0} (GolfSol Control) - http://www.worldwinn...sol/golfsol.cab
O16 - DPF: {FC4CAF5F-91BD-4DD9-ADC1-F3C737E37BC4} (CPlayFirstSweetopiaControl Object) - http://zone.msn.com/...ia.1.0.0.46.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - E:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: netstats - d3siGn3R - C:\WINDOWS\system\msservice.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NMSAccessU - Unknown owner - E:\Program Files\CDBurnerXP\NMSAccessU.exe
--
End of file - 9129 bytes
Malware Log dated Dec 21
Malwarebytes' Anti-Malware 1.31
Database version: 1528
Windows 5.1.2600 Service Pack 2
12/21/2008 3:19:00 AM
mbam-log-2008-12-21 (03-19-00).txt
Scan type: Full Scan (C:\|D:\|E:\|I:\|J:\|)
Objects scanned: 175503
Time elapsed: 1 hour(s), 24 minute(s), 13 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 9
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
AVG LOG dated Dec 21
"Scan ""Scan whole computer"" was finished."
"Infections found:";"37"
"Infected objects removed or healed:";"36"
"Not removed or healed:";"1"
"Spyware found:";"0"
"Spyware removed:";"0"
"Not removed:";"0"
"Warnings count:";"64"
"Information count:";"0"
"Scan started:";"Sunday, December 21, 2008, 3:31:00 AM"
"Scan finished:";"Sunday, December 21, 2008, 8:28:50 AM (4 hour(s) 57 minute(s) 49 second(s))"
"Total object scanned:";"899502"
"User who launched the scan:";"Donna"
"Infections"
"File";"Infection";"Result"
"C:\Qoobox\Quarantine\C\WINDOWS\system32\_mscdco_.exe.zip";"Trojan horse Generic12.JKJ";"Moved to Virus Vault"
"C:\Qoobox\Quarantine\C\WINDOWS\system32\_mscdco_.exe.zip:\mscdco. exe";"Trojan horse Generic12.JKJ";"Moved to Virus Vaul t"
"C:\WINDOWS\system32\cjqllf.dll";"Virus identified Worm/Generic_c. YH";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3P8CSHLY\af[1].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3P8CSHLY\ma[1].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3P8CSHLY\ma[2].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3P8CSHLY\msusp[1].bin";"Vi rus found D ropper.Bravix";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3P8CSHLY\no[1].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3P8CSHLY\ro[1].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3P8CSHLY\so[1].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3P8CSHLY\so[2].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3P8CSHLY\td[1].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3P8CSHLY\w1[1].bin";"Troja n horse Age nt.4.E";"Moved to Viru s V ault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3P8CSHLY\ws[1].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3P8CSHLY\ws[2].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3P8CSHLY\ws[3].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\978OP50J\ma[1].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\978OP50J\msusp[1].bin";"Vi rus found D ropper.Bravix";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\978OP50J\no[1].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\978OP50J\td[1].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\978OP50J\td[2].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\H07TIAQO\af[1].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\H07TIAQO\af[2].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\H07TIAQO\msusp[1].bin";"Vi rus found D ropper.Bravix";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\H07TIAQO\msusp[2].bin";"Vi rus found D ropper.Bravix";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\H07TIAQO\msusp[3].bin";"Vi rus found D ropper.Bravix";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\H07TIAQO\msusp[4].bin";"Vi rus found D ropper.Bravix";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\H07TIAQO\msusp[5].bin";"Vi rus found D ropper.Bravix";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\H07TIAQO\msusp[6].bin";"Vi rus found D ropper.Bravix";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\H07TIAQO\no[2].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\YHL1QCJT\msusp[2].bin";"Vi rus found D ropper.Bravix";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\YHL1QCJT\msusp[3].bin";"Vi rus found D ropper.Bravix";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\YHL1QCJT\ro[1].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\YHL1QCJT\ro[2].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\YHL1QCJT\so[1].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\YHL1QCJT\so[2].bin";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\system32\x.exe";"Trojan horse IRC/BackDoor.SdBot4.GYM" ;"Healed"
"Warnings"
"File";"Infection";"Result"
"C:\Documents and Settings\David\Cookies\david@advertising[1].txt" ;"Found Tracking cookie.Advertising";"Potentially dang erous objec t"
"C:\Documents and Settings\David\Cookies\david@advertising[1].txt: \advertising.com.1820df7a";"Found Tracking cookie.Adve rtising";"P otentially dangerous o bje ct"
"C:\Documents and Settings\David\Cookies\david@advertising[1].txt: \advertising.com.203aa218";"Found Tracking cookie.Adve rtising";"P otentially dangerous o bje ct"
"C:\Documents and Settings\David\Cookies\david@advertising[1].txt: \advertising.com.b624fa46";"Found Tracking cookie.Adve rtising";"P otentially dangerous o bje ct"
"C:\Documents and Settings\David\Cookies\david@advertising[1].txt: \advertising.com.f62113d5";"Found Tracking cookie.Adve rtising";"P otentially dangerous o bje ct"
"C:\Documents and Settings\David\Cookies\david@atdmt[2].txt";"Foun d Tracking cookie.Atdmt";"Potentially dangerous object "
"C:\Documents and Settings\David\Cookies\david@atdmt[2].txt:\atdmt .com.b3e33b5f";"Found Tracking cookie.Atdmt";"Potentia lly dangero us object"
"C:\Documents and Settings\David\Cookies\david@bluestreak[1].txt"; "Found Tracking cookie.Bluestreak";"Potentially danger ous object"
"C:\Documents and Settings\David\Cookies\david@bluestreak[1].txt:\ bluestreak.com.bf396750";"Found Tracking cookie.Bluest reak";"Pote ntially dangerous obje ct"
"C:\Documents and Settings\David\Cookies\david@casalemedia[2].txt" ;"Found Tracking cookie.Casalemedia";"Potentially dang erous objec t"
"C:\Documents and Settings\David\Cookies\david@casalemedia[2].txt: \casalemedia.com.1773afc";"Found Tracking cookie.Casal emedia";"Po tentially dangerous ob jec t"
"C:\Documents and Settings\David\Cookies\david@casalemedia[2].txt: \casalemedia.com.6a12b080";"Found Tracking cookie.Casa lemedia";"P otentially dangerous o bje ct"
"C:\Documents and Settings\David\Cookies\david@casalemedia[2].txt: \casalemedia.com.80ad4799";"Found Tracking cookie.Casa lemedia";"P otentially dangerous o bje ct"
"C:\Documents and Settings\David\Cookies\david@casalemedia[2].txt: \casalemedia.com.987e6b46";"Found Tracking cookie.Casa lemedia";"P otentially dangerous o bje ct"
"C:\Documents and Settings\David\Cookies\david@mediaplex[2].txt";" Found Tracking cookie.Mediaplex";"Potentially dangerou s object"
"C:\Documents and Settings\David\Cookies\david@mediaplex[2].txt:\m ediaplex.com.dc30fb3c";"Found Tracking cookie.Mediaple x";"Potenti ally dangerous object"
"C:\Documents and Settings\David\Cookies\david@mediaplex[2].txt:\m ediaplex.com.f652b123";"Found Tracking cookie.Mediaple x";"Potenti ally dangerous object"
"C:\Documents and Settings\Donna\Cookies\[email protected][2]. txt";"Found Tracking cookie.Yieldmanager";"Potentially dangerous object"
"C:\Documents and Settings\Donna\Cookies\[email protected][2]. txt:\ad.yieldmanager.com.539b0606";"Found Tracking coo kie.Yieldma nager";"Potentially da nge rous o bject"
"C:\Documents and Settings\Donna\Cookies\[email protected][2]. txt:\ad.yieldmanager.com.557bf2b0";"Found Tracking coo kie.Yieldma nager";"Potentially da nge rous o bject"
"C:\Documents and Settings\Donna\Cookies\[email protected][2]. txt:\ad.yieldmanager.com.87a9ab5d";"Found Tracking coo kie.Yieldma nager";"Potentially da nge rous o bject"
"C:\Documents and Settings\Donna\Cookies\[email protected][2]. txt:\ad.yieldmanager.com.b68f2b7b";"Found Tracking coo kie.Yieldma nager";"Potentially da nge rous o bject"
"C:\Documents and Settings\Donna\Cookies\[email protected][2]. txt:\ad.yieldmanager.com.e762f029";"Found Tracking coo kie.Yieldma nager";"Potentially da nge rous o bject"
"C:\Documents and Settings\Donna\Cookies\[email protected][2]. txt:\ad.yieldmanager.com.ff92306";"Found Tracking cook ie.Yieldman ager";"Potentially dan ger ous ob ject"
"C:\Documents and Settings\Donna\Cookies\donna@advertising[1].txt" ;"Found Tracking cookie.Advertising";"Potentially dang erous objec t"
"C:\Documents and Settings\Donna\Cookies\donna@advertising[1].txt: \advertising.com.203aa218";"Found Tracking cookie.Adve rtising";"P otentially dangerous o bje ct"
"C:\Documents and Settings\Donna\Cookies\donna@advertising[1].txt: \advertising.com.1820df7a";"Found Tracking cookie.Adve rtising";"P otentially dangerous o bje ct"
"C:\Documents and Settings\Donna\Cookies\donna@advertising[1].txt: \advertising.com.b624fa46";"Found Tracking cookie.Adve rtising";"P otentially dangerous o bje ct"
"C:\Documents and Settings\Donna\Cookies\donna@advertising[1].txt: \advertising.com.f62113d5";"Found Tracking cookie.Adve rtising";"P otentially dangerous o bje ct"
"C:\Documents and Settings\Donna\Cookies\donna@atdmt[1].txt";"Foun d Tracking cookie.Atdmt";"Potentially dangerous object "
"C:\Documents and Settings\Donna\Cookies\donna@atdmt[1].txt:\atdmt .com.b3e33b5f";"Found Tracking cookie.Atdmt";"Potentia lly dangero us object"
"C:\Documents and Settings\Donna\Cookies\[email protected][1].t xt";"Found Tracking cookie.Serving-sys";"Potentially d angerous ob ject"
"C:\Documents and Settings\Donna\Cookies\[email protected][1].t xt:\bs.serving-sys.com.5bf1f00f";"Found Tracking cooki e.Serving-s ys";"Potentially dange rou s obje ct"
"C:\Documents and Settings\Donna\Cookies\donna@casalemedia[2].txt" ;"Found Tracking cookie.Casalemedia";"Potentially dang erous objec t"
"C:\Documents and Settings\Donna\Cookies\donna@casalemedia[2].txt: \casalemedia.com.1773afc";"Found Tracking cookie.Casal emedia";"Po tentially dangerous ob jec t"
"C:\Documents and Settings\Donna\Cookies\donna@casalemedia[2].txt: \casalemedia.com.1d158016";"Found Tracking cookie.Casa lemedia";"P otentially dangerous o bje ct"
"C:\Documents and Settings\Donna\Cookies\donna@casalemedia[2].txt: \casalemedia.com.6a12b080";"Found Tracking cookie.Casa lemedia";"P otentially dangerous o bje ct"
"C:\Documents and Settings\Donna\Cookies\donna@casalemedia[2].txt: \casalemedia.com.80ad4799";"Found Tracking cookie.Casa lemedia";"P otentially dangerous o bje ct"
"C:\Documents and Settings\Donna\Cookies\donna@casalemedia[2].txt: \casalemedia.com.987e6b46";"Found Tracking cookie.Casa lemedia";"P otentially dangerous o bje ct"
"C:\Documents and Settings\Donna\Cookies\donna@doubleclick[1].txt" ;"Found Tracking cookie.Doubleclick";"Potentially dang erous objec t"
"C:\Documents and Settings\Donna\Cookies\donna@doubleclick[1].txt: \doubleclick.net.bf396750";"Found Tracking cookie.Doub leclick";"P otentially dangerous o bje ct"
"C:\Documents and Settings\Donna\Cookies\donna@mediaplex[1].txt";" Found Tracking cookie.Mediaplex";"Potentially dangerou s object"
"C:\Documents and Settings\Donna\Cookies\donna@mediaplex[1].txt:\m ediaplex.com.dc30fb3c";"Found Tracking cookie.Mediaple x";"Potenti ally dangerous object"
"C:\Documents and Settings\Donna\Cookies\donna@mediaplex[1].txt:\m ediaplex.com.f652b123";"Found Tracking cookie.Mediaple x";"Potenti ally dangerous object"
"C:\Documents and Settings\Donna\Cookies\[email protected][1 ].txt";"Found Tracking cookie.2o7";"Potentially danger ous object"
"C:\Documents and Settings\Donna\Cookies\[email protected][1 ].txt:\msnportal.112.2o7.net.7225be6f";"Found Tracking cookie.2o7 ";"Potentially dangero us object "
"C:\Documents and Settings\Donna\Cookies\donna@questionmarket[2].t xt";"Found Tracking cookie.Questionmarket";"Potentiall y dangerous object"
"C:\Documents and Settings\Donna\Cookies\donna@questionmarket[2].t xt:\questionmarket.com.3eb5a9f1";"Found Tracking cooki e.Questionm arket";"Potentially da nge rous o bject"
"C:\Documents and Settings\Donna\Cookies\donna@questionmarket[2].t xt:\questionmarket.com.4dd5e426";"Found Tracking cooki e.Questionm arket";"Potentially da nge rous o bject"
"C:\Documents and Settings\Donna\Cookies\donna@real[1].txt";"Found Tracking cookie.Real";"Potentially dangerous object"
"C:\Documents and Settings\Donna\Cookies\donna@real[1].txt:\real.c om.66561182";"Found Tracking cookie.Real";"Potentially dangerous object"
"C:\Documents and Settings\Donna\Cookies\donna@realmedia[1].txt";" Found Tracking cookie.Realmedia";"Potentially dangerou s object"
"C:\Documents and Settings\Donna\Cookies\donna@realmedia[1].txt:\r ealmedia.com.68087763";"Found Tracking cookie.Realmedi a";"Potenti ally dangerous object"
"C:\Documents and Settings\Donna\Cookies\donna@serving-sys[2].txt" ;"Found Tracking cookie.Serving-sys";"Potentially dang erous objec t"
"C:\Documents and Settings\Donna\Cookies\donna@serving-sys[2].txt: \serving-sys.com.255d6f2f";"Found Tracking cookie.Serv ing-sys";"P otentially dangerous o bje ct"
"C:\Documents and Settings\Donna\Cookies\donna@serving-sys[2].txt: \serving-sys.com.400f83f";"Found Tracking cookie.Servi ng-sys";"Po tentially dangerous ob jec t"
"C:\Documents and Settings\Donna\Cookies\donna@serving-sys[2].txt: \serving-sys.com.4b416ef8";"Found Tracking cookie.Serv ing-sys";"P otentially dangerous o bje ct"
"C:\Documents and Settings\Donna\Cookies\donna@serving-sys[2].txt: \serving-sys.com.606c3d3b";"Found Tracking cookie.Serv ing-sys";"P otentially dangerous o bje ct"
"C:\Documents and Settings\Donna\Cookies\donna@serving-sys[2].txt: \serving-sys.com.6a1cf9e8";"Found Tracking cookie.Serv ing-sys";"P otentially dangerous o bje ct"
"C:\Documents and Settings\Donna\Cookies\donna@serving-sys[2].txt: \serving-sys.com.c9034af6";"Found Tracking cookie.Serv ing-sys";"P otentially dangerous o bje ct"
"C:\Documents and Settings\Donna\Cookies\donna@zedo[1].txt";"Found Tracking cookie.Zedo";"Potentially dangerous object"
"C:\Documents and Settings\Donna\Cookies\donna@zedo[1].txt:\zedo.c om.27f1639b";"Found Tracking cookie.Zedo";"Potentially dangerous object"
"C:\Documents and Settings\Donna\Cookies\donna@zedo[1].txt:\zedo.c om.775ee79c";"Found Tracking cookie.Zedo";"Potentially dangerous object"
"C:\Documents and Settings\Donna\Cookies\donna@zedo[1].txt:\zedo.c om.c1dd09f2";"Found Tracking cookie.Zedo";"Potentially dangerous object"