PDA

View Full Version : HJT Log


panther_base
02-14-2008, 10:57 AM
I've been having some issues with my pc lately. It runs extremely slow from what it used to. So in covering the bases I ran a HJT scan just in case.



Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:52:36 AM, on 2/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\DigitalPersona\Bin\DPWinLct.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\DigitalPersona\Bin\DpHost.exe
C:\Program Files\WildBlue Security Center\Anti-Virus\fsgk32st.exe
C:\Program Files\WildBlue Security Center\Common\FSMA32.EXE
C:\Program Files\WildBlue Security Center\Anti-Virus\FSGK32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\WildBlue Security Center\Common\FSMB32.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe
C:\Program Files\WildBlue Security Center\Common\FCH32.EXE
C:\Program Files\WildBlue Security Center\Common\FAMEH32.EXE
C:\Program Files\WildBlue Security Center\Anti-Virus\fsqh.exe
C:\Program Files\WildBlue Security Center\FSAUA\program\fsaua.exe
C:\Program Files\WildBlue Security Center\Anti-Virus\fssm32.exe
C:\Program Files\WildBlue Security Center\FWES\Program\fsdfwd.exe
C:\Program Files\WildBlue Security Center\FSAUA\program\fsus.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\DigitalPersona\Bin\DPAgnt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\WildBlue Security Center\Common\FSM32.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ResChanger 2005\ResChanger2005.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WildBlue Security Center\FSGUI\fsguidll.exe
C:\Program Files\WildBlue Security Center\Anti-Virus\fsav32.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Kaza\Desktop\Downloaded Files\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Spybot - Search & Destroy\SDHelper.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {F4D76F09-7896-458a-890F-E1F05C46069F} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Launch PC Probe II] "C:\Program Files\ASUS\PC Probe II\Probe2.exe" 1
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC315NC Webcam
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"

panther_base
02-14-2008, 10:57 AM
O4 - HKLM\..\Run: [DPAgnt] C:\Program Files\DigitalPersona\Bin\DPAgnt.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\WildBlue Security Center\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\WildBlue Security Center\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ResChanger 2005] C:\Program Files\ResChanger 2005\ResChanger2005.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: TrayMin315.exe.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - [url]http://favorites.live.com/quickadd.aspx[/url]
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - [url]https://support.microsoft.com/OAS/ActiveX/MSDcode.cab[/url]
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - [url]http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab[/url]
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - [url]http://www.acclaim.com/cabs/acclaim_v5.cab[/url]
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - [url]http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1172865851812[/url]
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - [url]http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab[/url]
O20 - Winlogon Notify: DPWLN - C:\WINDOWS\system32\DPWLEvHd.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Windows XP FUS Manager (DPFUSMgr) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHost.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - Unknown owner - C:\Program Files\WildBlue Security Center\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\WildBlue Security Center\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\WildBlue Security Center\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\WildBlue Security Center\Common\FSMA32.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 10788 bytes

classicsoftware
02-14-2008, 11:16 AM
I don't see anything in your log. I also see you are running enough stuff to stun a pack a elephants.

Please do this to rule out malware and then we can look at freeing up some resources.

Please do the following:


Download this file - combofix.exe (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) to your Desktop (it needs to be run from the Desktop). Double click combofix.exe & follow the prompts.
When finished, it will produce a log for you.


Note:

Do not mouseclick Combofix's window while it is running. That may cause the program to stall...

Then:


Re-boot the system
Post the Combofix Log
Post a new HJT log
Tell us how the system is running.

panther_base
02-14-2008, 01:02 PM
I downloaded Combofix to my desktop and tried running it, all I get when I try to run it is a small window that says Combofix and has a loading bar. After the bar reads that it's loaded the windows closes and nothing else happens

panther_base
02-14-2008, 03:55 PM
I managed to run combofix here's the log

ComboFix 08-02-14.3 - Kaza 2008-02-14 13:42:21.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.660 [GMT -6:00]
Running from: C:\Documents and Settings\Kaza\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
* Resident AV is active


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Kaza\Application Data\macromedia\Flash Player\#SharedObjects\MTKJSMB3\www.broadcaster.com
C:\Documents and Settings\Kaza\Application Data\macromedia\Flash Player\#SharedObjects\MTKJSMB3\www.broadcaster.com \played_list.sol
C:\Documents and Settings\Kaza\Application Data\macromedia\Flash Player\#SharedObjects\MTKJSMB3\www.broadcaster.com \video_queue.sol
C:\Documents and Settings\Kaza\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www .broadcaster.com
C:\Documents and Settings\Kaza\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www .broadcaster.com\settings.sol
C:\WINDOWS\Downloaded Program Files\ODCTOOLS

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\nm

panther_base
02-14-2008, 03:56 PM
((((((((((((((((((((((((( Files Created from 2008-01-14 to 2008-02-14 )))))))))))))))))))))))))))))))
.

2008-02-12 08:57 . 2008-02-12 08:57 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-12 08:57 . 2008-02-12 08:57 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-11 18:50 . 2008-02-11 18:50 <DIR> d-------- C:\Documents and Settings\Kaza\Application Data\Canon
2008-02-08 12:32 . 2008-02-08 12:32 <DIR> d-------- C:\Program Files\Common Files\INCA Shared
2008-02-08 09:48 . 2008-02-08 09:48 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-02-08 08:56 . 2008-02-10 13:51 <DIR> d-------- C:\Documents and Settings\Kaza\Application Data\F-Secure
2008-02-07 21:49 . 2008-02-14 13:07 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-02-07 19:18 . 2008-02-07 19:19 <DIR> d-------- C:\Program Files\Microsoft IntelliType Pro
2008-02-07 00:29 . 2008-02-13 09:06 <DIR> d-------- C:\Program Files\WildBlue Security Center
2008-02-07 00:29 . 2008-02-07 00:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\F-Secure
2008-02-07 00:29 . 2007-06-01 07:14 58,128 --a------ C:\WINDOWS\system32\drivers\fsdfw.sys
2008-02-07 00:29 . 2007-06-01 07:14 37,008 --a------ C:\WINDOWS\system32\drivers\fsndis5.sys
2008-02-07 00:25 . 2008-02-07 00:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\fssg
2008-01-28 09:55 . 2008-01-28 09:55 <DIR> d--h----- C:\Documents and Settings\All Users\Application Data\CanonBJ
2008-01-28 09:55 . 2007-03-18 23:00 215,040 --a------ C:\WINDOWS\system32\CNMLM8S.DLL
2008-01-28 09:54 . 2008-01-28 09:54 <DIR> d-------- C:\Program Files\Canon

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-02-10 19:57 --------- d-----w C:\Program Files\Bots
2008-02-09 04:21 --------- d-----w C:\Program Files\LimeWire
2008-02-08 18:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-08 15:44 --------- d-----w C:\Program Files\Common Files\Real
2008-02-08 03:43 21 ----a-w C:\Program Files\Common Files\appop.log
2008-02-08 03:41 --------- d-----w C:\Program Files\InterVideo
2008-02-08 00:58 --------- d-----w C:\Program Files\Trillian
2008-02-07 06:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-01-19 22:00 --------- d-----w C:\Documents and Settings\Kaza\Application Data\dvdcss
2007-12-30 05:29 --------- d-----w C:\Documents and Settings\Kaza\Application Data\Media Player Classic
2007-12-22 17:05 --------- d-----w C:\Program Files\THQ
2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ResChanger 2005"="C:\Program Files\ResChanger 2005\ResChanger2005.exe" [2005-05-26 18:30 885248]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2007-04-24 20:49 68856]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2005-04-14 21:01 77824 C:\WINDOWS\SOUNDMAN.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00 132496]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 11:22 7700480]
"Launch PC Probe II"="C:\Program Files\ASUS\PC Probe II\Probe2.exe" [ ]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" [2004-11-09 11:38 532480]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06 40048]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2004-06-09 14:37 40960]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2004-06-03 02:50 204800]
"DPAgnt"="C:\Program Files\DigitalPersona\Bin\DPAgnt.exe" [2004-10-13 17:24 913408]
"nwiz"="nwiz.exe" [2006-10-22 11:22 1622016 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 11:22 86016]
"F-Secure Manager"="C:\Program Files\WildBlue Security Center\Common\FSM32.exe" [2007-06-01 07:19 183208]
"F-Secure TNB"="C:\Program Files\WildBlue Security Center\FSGUI\TNBUtil.exe" [2007-06-01 07:17 740208]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 02:51 172032]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-08 09:32 185896]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-03-13 19:36:10 113664]
TrayMin315.exe.lnk - C:\Program Files\Philips\Philips SPC315NC Webcam\TrayMin315.exe [2007-07-07 16:25:43 278528]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DPWLN ]
C:\WINDOWS\system32\DPWLEvHd.dll 2004-10-13 17:29 102400 C:\WINDOWS\system32\DPWLEvHd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch Ai Booster]
--a------ 2005-06-16 15:36 3627520 C:\Program Files\ASUS\Ai Booster\OverClk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 11:22 1622016 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VO Clock]


R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys [2007-06-01 07:14]
R1 F-Secure HIPS;F-Secure HIPS;C:\Program Files\WildBlue Security Center\HIPS\fshs.sys [2008-02-13 09:01]
R3 amdtools;AMD Special Tools Driver;C:\WINDOWS\system32\DRIVERS\amdtools.sys [2006-06-07 13:15]
R3 dpK0Bx01;Fingerprint Reader Filter Driver;C:\WINDOWS\system32\DRIVERS\dpK0Bx01.sys [2004-08-04 15:58]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\WildBlue Security Center\Anti-Virus\minifilter\fsgk.sys [2007-05-28 03:15]
R3 kbdcap;kbdcap;C:\WINDOWS\system32\drivers\kbdcap.s ys [2007-03-07 21:47]
R3 UsbdpFP;Fingerprint Reader Class Driver;C:\WINDOWS\system32\DRIVERS\UsbdpFP.sys [2004-08-04 15:59]
S0 AmdAcpi;AmdAcpi Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\AmdAcpi.sys []
S3 geebers12;geebers12;C:\Documents and Settings\Kaza\Desktop\Game Cheats\uce-fixedload\nvid888.sys []
S3 mgau;mgau;C:\WINDOWS\system32\DRIVERS\mgaum.sys [2001-08-17 12:50]
S3 Revolution1;Revolution1;C:\Documents and Settings\Kaza\Desktop\Game Cheats\Revolution_7\SHAK3.sys []
S3 samhid;samhid;C:\WINDOWS\system32\drivers\samhid.s ys []
S3 TSHAK3T1;TSHAK3T1;C:\Documents and Settings\Kaza\Desktop\Downloaded Files\Hacking package for Bots\Hacking package for Bots\RE 3.2\spuce.sys []
S3 wdm_au8830;Aureal Vortex 8830 Audio Driver (WDM);C:\WINDOWS\system32\drivers\adm8830.sys [2001-08-17 06:19]
S3 xp1;xp1;C:\Documents and Settings\Kaza\Desktop\MS Hacking\xpengine\xp.sys []
S4 F-Secure Filter;F-Secure File System Filter;C:\Program Files\WildBlue Security Center\Anti-Virus\Win2K\FSfilter.sys [2007-05-28 03:15]
S4 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\WildBlue Security Center\Anti-Virus\Win2K\FSrec.sys [2007-05-28 03:15]

[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{07b159c5-c77a-11db-85a2-806d6172696f}]
\Shell\AutoRun\command - D:\ASUSACPI.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-14 19:48:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
************************************************** ************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [url]http://www.gmer.net[/url]
Rootkit scan 2008-02-14 13:47:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

************************************************** ************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\DigitalPersona\Bin\DpOFeedb.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\DigitalPersona\Bin\DPWinLct.exe
C:\Program Files\DigitalPersona\Bin\DpHost.exe
C:\Program Files\WildBlue Security Center\Anti-Virus\fsgk32st.exe
C:\Program Files\WildBlue Security Center\Common\FSMA32.EXE
C:\Program Files\WildBlue Security Center\Anti-Virus\FSGK32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\WildBlue Security Center\Common\FSMB32.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe
C:\Program Files\WildBlue Security Center\Common\FCH32.EXE
C:\Program Files\WildBlue Security Center\Common\FAMEH32.EXE
C:\Program Files\WildBlue Security Center\Anti-Virus\fsqh.exe
C:\Program Files\WildBlue Security Center\FSAUA\program\fsaua.exe
C:\Program Files\WildBlue Security Center\FWES\Program\fsdfwd.exe
C:\Program Files\WildBlue Security Center\Anti-Virus\fssm32.exe
C:\Program Files\WildBlue Security Center\FSAUA\program\fsus.exe
C:\Program Files\WildBlue Security Center\Anti-Virus\fsav32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\WildBlue Security Center\FSGUI\fsguidll.exe
C:\WINDOWS\system32\rundll32.exe
.
************************************************** ************************
.
Completion time: 2008-02-14 13:50:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-14 19:50:24
.
2008-02-14 05:57:44 --- E O F ---

panther_base
02-14-2008, 03:57 PM
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 1:56:47 PM, on 2/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\DigitalPersona\Bin\DPWinLct.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\DigitalPersona\Bin\DpHost.exe
C:\Program Files\WildBlue Security Center\Anti-Virus\fsgk32st.exe
C:\Program Files\WildBlue Security Center\Common\FSMA32.EXE
C:\Program Files\WildBlue Security Center\Anti-Virus\FSGK32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\WildBlue Security Center\Common\FSMB32.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe
C:\Program Files\WildBlue Security Center\Common\FCH32.EXE
C:\Program Files\WildBlue Security Center\Common\FAMEH32.EXE
C:\Program Files\WildBlue Security Center\Anti-Virus\fsqh.exe
C:\Program Files\WildBlue Security Center\FSAUA\program\fsaua.exe
C:\Program Files\WildBlue Security Center\FWES\Program\fsdfwd.exe
C:\Program Files\WildBlue Security Center\Anti-Virus\fssm32.exe
C:\Program Files\WildBlue Security Center\FSAUA\program\fsus.exe
C:\Program Files\WildBlue Security Center\Anti-Virus\fsav32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\DigitalPersona\Bin\DPAgnt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\WildBlue Security Center\Common\FSM32.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\WildBlue Security Center\FSGUI\fsguidll.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ResChanger 2005\ResChanger2005.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Philips\Philips SPC315NC Webcam\TrayMin315.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Kaza\Desktop\Downloaded Files\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Spybot - Search & Destroy\SDHelper.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {F4D76F09-7896-458a-890F-E1F05C46069F} - (no file)

panther_base
02-14-2008, 03:57 PM
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Launch PC Probe II] "C:\Program Files\ASUS\PC Probe II\Probe2.exe" 1
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC315NC Webcam
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [DPAgnt] C:\Program Files\DigitalPersona\Bin\DPAgnt.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\WildBlue Security Center\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\WildBlue Security Center\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ResChanger 2005] C:\Program Files\ResChanger 2005\ResChanger2005.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: TrayMin315.exe.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - [url]http://favorites.live.com/quickadd.aspx[/url]
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - [url]https://support.microsoft.com/OAS/ActiveX/MSDcode.cab[/url]
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - [url]http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab[/url]
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - [url]http://www.acclaim.com/cabs/acclaim_v5.cab[/url]
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - [url]http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1172865851812[/url]
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - [url]http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab[/url]
O20 - Winlogon Notify: DPWLN - C:\WINDOWS\system32\DPWLEvHd.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Windows XP FUS Manager (DPFUSMgr) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHost.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - Unknown owner - C:\Program Files\WildBlue Security Center\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\WildBlue Security Center\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\WildBlue Security Center\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\WildBlue Security Center\Common\FSMA32.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 10733 bytes

classicsoftware
02-14-2008, 05:49 PM
How is the system running??????

panther_base
02-14-2008, 07:42 PM
somewhat faster, there's a noticeable difference it's still slower than it should be though

classicsoftware
02-15-2008, 05:55 AM
Download AVG Anti-Spyware from HERE (http://www.ewido.net/en/download/)
Install AVG Anti-Spyware
Double-click the icon on Desktop to launch AVG Anti-Spyware
You will need to update AVG Anti-Spyware to the latest definition files.
On the top of the main screen click Shield and then [active] to change it to inactive
On the top of the main screen click Update and then Start Update.
Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
Once in the Settings screen click on "Recommended actions" and then select "Quarantine".


Close ALL open Windows / Programs / Folders. Run AVG Anti-Spyware with it's updated definitions: (...it's important that all windows must be closed)

* Click Scanner and then the Scan tab
* Click Complete System Scan to begin scanning.

Once the scan is complete do the following:
* If you have any infections you will prompted, then select "Apply all actions"
* Once finished, click the Save report button, then click Save Report As and save it to your Desktop. (make sure to remember where you saved that file, this is important).

Close AVG Anti-Spyware and Reboot.

Post the logs and let me know how things seem to be running...

panther_base
02-15-2008, 02:34 PM
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 12:20:05 PM 2/15/2008

+ Scan result:



C:\Documents and Settings\Kaza\Desktop\Online Games\MS Hacking\ggk\g_poison.exe -> Backdoor.Iroffer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{728581E4-DFBA-4678-A43E-D0B13B4227EA}\RP290\A0077739.exe -> Backdoor.Iroffer : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaza\Desktop\Online Games\MS Hacking\xpengine\xp.sys -> Rootkit.Agent : Cleaned with backup (quarantined).
:mozilla.703:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.704:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.100:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.101:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.102:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.103:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.104:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.105:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.106:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.107:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.108:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.109:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.110:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.111:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.112:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.113:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.114:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.115:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.116:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.117:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.118:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.119:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.120:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.121:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.122:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.123:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.124:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.249:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.478:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.510:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.567:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.58:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\uahrxe7n.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.

panther_base
02-15-2008, 02:35 PM
:mozilla.634:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.656:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.733:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.782:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.95:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.96:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.97:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.989:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.98:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.99:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.643:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.644:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.645:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.841:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.955:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.956:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Kaza\Cookies\kaza@3.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Kaza\Cookies\kaza@ads.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.198:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.199:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.200:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.201:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.202:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.203:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.204:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.205:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.206:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.141:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.142:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.143:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.144:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.145:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.40:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.6:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\uahrxe7n.default\coo kies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.861:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.456:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.672:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.968:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.602:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.603:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.234:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.235:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.236:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.237:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.238:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.239:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.240:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.241:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.242:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.243:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.702:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Documents and Settings\Kaza\Cookies\kaza@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.633:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Dealtime : Cleaned.
:mozilla.59:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.796:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.817:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.818:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.819:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.820:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.825:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.826:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Esomniture : Cleaned.

panther_base
02-15-2008, 02:35 PM
:mozilla.827:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.828:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.829:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.192:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.193:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.194:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.195:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.196:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.197:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.46:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\uahrxe7n.default\coo kies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.47:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\uahrxe7n.default\coo kies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.48:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\uahrxe7n.default\coo kies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.49:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\uahrxe7n.default\coo kies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.50:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\uahrxe7n.default\coo kies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.51:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\uahrxe7n.default\coo kies.txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Kaza\Cookies\kaza@CAFTOASM.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.87:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.88:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.89:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.90:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.91:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.298:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.299:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.400:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.64:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.661:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.67:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.253:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.254:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.255:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.256:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.257:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.330:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.348:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.349:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.369:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.560:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.561:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.586:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.587:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.720:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.750:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.756:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.790:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.804:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.897:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.898:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.906:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.675:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.220:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.221:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.850:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.852:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.911:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.912:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Kaza\Cookies\kaza@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.131:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.132:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.33:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\uahrxe7n.default\coo kies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.16:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.815:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.816:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.128:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Overture : Cleaned.

panther_base
02-15-2008, 02:37 PM
:mozilla.129:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.130:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.752:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Kaza\Cookies\kaza@data4.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
:mozilla.543:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.544:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.545:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.546:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.547:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.548:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.549:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.550:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.551:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.10:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\uahrxe7n.default\coo kies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.11:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\uahrxe7n.default\coo kies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.182:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.183:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.474:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Real : Cleaned.
:mozilla.475:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Real : Cleaned.
:mozilla.476:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Kaza\Cookies\kaza@CA8UXX86.txt -> TrackingCookie.Real : Cleaned.
:mozilla.286:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.287:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.288:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.289:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.290:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.434:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.435:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.436:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.437:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.438:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.439:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.440:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.441:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.442:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.443:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.444:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.445:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.446:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.447:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.785:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.536:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.537:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.538:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.539:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.540:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.541:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.507:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Skype : Cleaned.
:mozilla.508:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Skype : Cleaned.
C:\Documents and Settings\Kaza\Cookies\kaza@news.skype[1].txt -> TrackingCookie.Skype : Cleaned.
C:\Documents and Settings\Kaza\Cookies\kaza@skype[1].txt -> TrackingCookie.Skype : Cleaned.
:mozilla.570:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.571:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Statcounter : Cleaned.

panther_base
02-15-2008, 02:37 PM
:mozilla.308:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.309:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.310:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.311:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Kaza\Cookies\kaza@CAW3IMH1.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Kaza\Cookies\kaza@anad.tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.292:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Tracking101 : Cleaned.
:mozilla.185:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.186:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.187:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.188:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.189:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.190:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.191:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.71:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.723:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.724:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.725:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.726:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.727:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.728:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.13:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\uahrxe7n.default\coo kies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.482:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Kaza\Cookies\kaza@m.webtrends[2].txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.533:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\Kaza\Cookies\kaza@yadro[2].txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.27:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.28:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.29:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.30:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.31:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.32:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.33:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.34:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.35:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Kaza\Cookies\kaza@CAA734SN.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.448:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.449:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.450:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.451:C:\Documents and Settings\Kaza\Application Data\Mozilla\Firefox\Profiles\3kcyxkmc.default\coo kies.txt -> TrackingCookie.Zedo : Cleaned.

Report End

panther_base
02-15-2008, 02:40 PM
so far it seems that's pretty well fixed the slowing down issues

classicsoftware
02-15-2008, 03:04 PM
* Click here (http://support.f-secure.com/enu/home/ols3.shtml) to use the F-Secure Online Scanner
It's explained there with images how to allow the ActiveX to start the scan, so read that first.
Then click the F-Secure Online Scanner Next Generation Beta link.
Once the ActiveX is installed, you should accept the License terms by clicking OK below to start the scan.
Click the Full System Scan button.
It will start to download scanner components and databases. This can take a while.
The main scan will start.
Once the scan finished scanning, click the Automatic cleaning (recommended) button
It could be possible that your firewall gives an alert - allow it, because that's a connection you establish to submit infected files to F-Secure.
The cleaning can take a while, so please be patient.
Then click the Show report button and copy and paste what's present under results in your next reply.

panther_base
02-15-2008, 03:53 PM
I'm running the online scan now, but I wanted to say, I use F-Secure Internet Security as my antivirus/firewall

panther_base
02-16-2008, 11:17 AM
Scanning Report
Friday, February 15, 2008 13:59:15 - 09:11:56

Computer name: GENX
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\
Result: 3 malware found
HackTool.Win32.Injecter.l (virus)

* System

Rootkit.V (virus)

* C:\RECYCLER\S-1-5-21-329068152-412668190-839522115-1002\DC5\GGK.SYS (Renamed & Submitted)

W32/Keylog.CGA (virus)

* C:\DOCUMENTS AND SETTINGS\KAZA\DESKTOP\ONLINE GAMES\GAME CHEATS\TRAINERV4.3\TRAINERV4.3.EXE (Submitted)

Statistics
Scanned:

* Files: 89377
* System: 3635
* Not scanned: 8

Actions:

* Disinfected: 0
* Renamed: 1
* Deleted: 0
* None: 2
* Submitted: 2

Files not scanned:

* C:\PAGEFILE.SYS
* C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
* C:\WINDOWS\SYSTEM32\CONFIG\SAM
* C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
* C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
* C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM
* C:\DOCUMENTS AND SETTINGS\KAZA\DESKTOP\ONLINE GAMES\GAME CHEATS\PLVL99999KILLS\INJEC-TOR.EXE
* C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\092D7E51918F 3D599AB753357D044E3A_5B6CC714-37A2-4A22-BE97-F85134D2477D

classicsoftware
02-16-2008, 01:29 PM
Download install and run AVG Anti-Rootkit Free (http://free.grisoft.com/doc/downloads-products/us/frt/0?prd=arw)

Post the log from AVG and a new Hijackthis log.

panther_base
02-17-2008, 12:19 AM
AVG Root Kit Scan came up clean, here's the hjt log


Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 10:17:26 PM, on 2/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\DigitalPersona\Bin\DPWinLct.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\msco rsvw.exe
C:\Program Files\DigitalPersona\Bin\DpHost.exe
C:\Program Files\WildBlue Security Center\Anti-Virus\fsgk32st.exe
C:\Program Files\WildBlue Security Center\Common\FSMA32.EXE
C:\Program Files\WildBlue Security Center\Anti-Virus\FSGK32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\WildBlue Security Center\Common\FSMB32.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WildBlue Security Center\Common\FCH32.EXE
C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe
C:\Program Files\WildBlue Security Center\Common\FAMEH32.EXE
C:\Program Files\WildBlue Security Center\Anti-Virus\fsqh.exe
C:\Program Files\WildBlue Security Center\FSAUA\program\fsaua.exe
C:\Program Files\WildBlue Security Center\Anti-Virus\fssm32.exe
C:\Program Files\WildBlue Security Center\FWES\Program\fsdfwd.exe
C:\Program Files\WildBlue Security Center\FSAUA\program\fsus.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\DigitalPersona\Bin\DPAgnt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\WildBlue Security Center\Common\FSM32.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\WildBlue Security Center\FSGUI\fsguidll.exe
C:\Program Files\ResChanger 2005\ResChanger2005.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WildBlue Security Center\Anti-Virus\fsav32.exe
C:\Documents and Settings\Kaza\Desktop\Downloaded Files\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Spybot - Search & Destroy\SDHelper.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

panther_base
02-17-2008, 12:20 AM
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {F4D76F09-7896-458a-890F-E1F05C46069F} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Launch PC Probe II] "C:\Program Files\ASUS\PC Probe II\Probe2.exe" 1
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC315NC Webcam
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [DPAgnt] C:\Program Files\DigitalPersona\Bin\DPAgnt.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\WildBlue Security Center\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\WildBlue Security Center\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ResChanger 2005] C:\Program Files\ResChanger 2005\ResChanger2005.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: TrayMin315.exe.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - [url]http://favorites.live.com/quickadd.aspx[/url]
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - [url]https://support.microsoft.com/OAS/ActiveX/MSDcode.cab[/url]
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {664088B0-6AF3-4514-AF9D-A0DC3A3DF24A} (F-Secure Online Scanner 3.3) - [url]http://support.f-secure.com/ols3beta/fscax.cab[/url]
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - [url]http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab[/url]
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - [url]http://www.acclaim.com/cabs/acclaim_v5.cab[/url]
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - [url]http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1172865851812[/url]
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - [url]http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab[/url]
O20 - Winlogon Notify: DPWLN - C:\WINDOWS\system32\DPWLEvHd.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Windows XP FUS Manager (DPFUSMgr) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHost.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - Unknown owner - C:\Program Files\WildBlue Security Center\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\WildBlue Security Center\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\WildBlue Security Center\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\WildBlue Security Center\Common\FSMA32.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 11238 bytes

classicsoftware
02-17-2008, 12:42 AM
I can't see anything else in your logs. You need to get rid of Kazaa and avoid game cracks and poker sites. These are the holy grail of getting infected.

Get rid of those and post one more HJT log and let me know if it is still running well.

panther_base
02-17-2008, 12:55 AM
I've never had Kazaa on this system, so I'm not sure how it got there, I didn't see it on the hjt list and I removed the ones I knew weren't supposed to be there, if there's anymore could you point them out?


Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 10:52:35 PM, on 2/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\DigitalPersona\Bin\DPWinLct.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\msco rsvw.exe
C:\Program Files\DigitalPersona\Bin\DpHost.exe
C:\Program Files\WildBlue Security Center\Anti-Virus\fsgk32st.exe
C:\Program Files\WildBlue Security Center\Common\FSMA32.EXE
C:\Program Files\WildBlue Security Center\Anti-Virus\FSGK32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\WildBlue Security Center\Common\FSMB32.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WildBlue Security Center\Common\FCH32.EXE
C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe
C:\Program Files\WildBlue Security Center\Common\FAMEH32.EXE
C:\Program Files\WildBlue Security Center\Anti-Virus\fsqh.exe
C:\Program Files\WildBlue Security Center\FSAUA\program\fsaua.exe
C:\Program Files\WildBlue Security Center\Anti-Virus\fssm32.exe
C:\Program Files\WildBlue Security Center\FWES\Program\fsdfwd.exe
C:\Program Files\WildBlue Security Center\FSAUA\program\fsus.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\DigitalPersona\Bin\DPAgnt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\WildBlue Security Center\Common\FSM32.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\WildBlue Security Center\FSGUI\fsguidll.exe
C:\Program Files\ResChanger 2005\ResChanger2005.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WildBlue Security Center\Anti-Virus\fsav32.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\Kaza\Desktop\Downloaded Files\HiJackThis_v2.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Spybot - Search & Destroy\SDHelper.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll

panther_base
02-17-2008, 12:56 AM
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {F4D76F09-7896-458a-890F-E1F05C46069F} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Launch PC Probe II] "C:\Program Files\ASUS\PC Probe II\Probe2.exe" 1
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC315NC Webcam
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [DPAgnt] C:\Program Files\DigitalPersona\Bin\DPAgnt.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\WildBlue Security Center\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\WildBlue Security Center\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ResChanger 2005] C:\Program Files\ResChanger 2005\ResChanger2005.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: TrayMin315.exe.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - [url]http://favorites.live.com/quickadd.aspx[/url]
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - [url]https://support.microsoft.com/OAS/ActiveX/MSDcode.cab[/url]
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {664088B0-6AF3-4514-AF9D-A0DC3A3DF24A} (F-Secure Online Scanner 3.3) - [url]http://support.f-secure.com/ols3beta/fscax.cab[/url]
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - [url]http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab[/url]
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - [url]http://www.acclaim.com/cabs/acclaim_v5.cab[/url]
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - [url]http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1172865851812[/url]
O20 - Winlogon Notify: DPWLN - C:\WINDOWS\system32\DPWLEvHd.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Windows XP FUS Manager (DPFUSMgr) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHost.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - Unknown owner - C:\Program Files\WildBlue Security Center\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\WildBlue Security Center\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\WildBlue Security Center\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\WildBlue Security Center\Common\FSMA32.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 10292 bytes

classicsoftware
02-17-2008, 01:02 AM
I've never had Kazaa on this system, so I'm not sure how it got there, I didn't see it on the hjt list and I removed the ones I knew weren't supposed to be there, if there's anymore could you point them out?l

You removed things with Hijackthis? What did you remove? You could be masking more infections. Why didn't you say that at the beginning?

panther_base
02-17-2008, 01:14 AM
I haven't removed anything with Hijack This, I've done everything you've told me, how you've told me, sorry for the confusion.

classicsoftware
02-17-2008, 01:29 AM
What do yo mean by:
I removed the ones I knew weren't supposed to be there, if there's anymore could you point them out?l

Please explain what this means?

How is the system running.

I think I confused you user name Kaza with Kazza. Sorry about that. I did you were getting gaming cracks and that is a major source of infection along with:

Music Sharing
Porn Sites
Gambling Sites

panther_base
02-17-2008, 01:41 AM
Please explain what this means?

Start>Search>All Files>File Name>Delete, the only ones I did this to were the files from programs I knew I had uninstalled and the files were left behind.

classicsoftware
02-17-2008, 01:46 AM
Please delete the following file:

C:\DOCUMENTS AND SETTINGS\KAZA\DESKTOP\ONLINE GAMES\GAME CHEATS\TRAINERV4.3\TRAINERV4.3.EXE

Please remove all restore points.

do one more sweep with the F-secure on line scanner.

Post the results.

panther_base
02-18-2008, 09:59 AM
Scanning Report
Sunday, February 17, 2008 17:30:39 - 07:53:13

Computer name: GENX
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\
Result: 1 malware found
W32/Keylog.CGA (virus)

* C:\RECYCLER\S-1-5-21-329068152-412668190-839522115-1002\DC33.EXE (Submitted)

Statistics
Scanned:

* Files: 90919
* System: 3653
* Not scanned: 7

Actions:

* Disinfected: 0
* Renamed: 0
* Deleted: 0
* None: 1
* Submitted: 1

Files not scanned:

* C:\PAGEFILE.SYS
* C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
* C:\WINDOWS\SYSTEM32\CONFIG\SAM
* C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
* C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
* C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM
* C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\092D7E51918F 3D599AB753357D044E3A_5B6CC714-37A2-4A22-BE97-F85134D2477D

Options
Scanning engines:

* F-Secure USS: 2.20.0
* F-Secure Hydra: 2.6.7470, 2008-02-17
* F-Secure AVP: 7.0.171, 2008-02-17
* F-Secure Pegasus: 1.20.0, 2008-01-13
* F-Secure Blacklight: 1.0.64

Scanning options:

* Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX ANI AVB BAT CMD JPG LSP MAP MHT MIF PHP POT SWF WMF NWS TAR
* Use Advanced heuristics

classicsoftware
02-19-2008, 12:30 AM
If you deleted the restore points, then empty the re-cycle bin and then create a new restore point.

You should be good to go.

How to Protect Yourself While On-Line


Make sure you have an up to date Antivirus. Scan Regularly. There are many free versions:

AVAST (http://www.avast.com/eng/download-avast-home.html)
AVG (http://free.grisoft.com/freeweb.php/doc/2/)
Antivir (http://www.free-av.com/antivirus/allinonen.html)


Make sure you have a software firewall and if you are on broadband, get behind a NAT router. There are also free versions:

Kerio (http://www.sunbelt-software.com/Home-Home-Office/Sunbelt-Personal-Firewall/)
Sygate (http://www.filehippo.com/download_sygate_personal_firewall/)
Zone Alarm (http://www.zonealarm.com/store/content/catalog/products/sku_list_za.jsp%3bjsessionid=BzJnZDxzyCUCcyZMB2t0Q co5IgutuYlrOMI5snmy1ZptQ2vOr1l1!776180791!-1062696904!7551!7552!-2099742426!-1062696903!7551!7552)

Keep Windows up to date.
Keep all of your software up to date. You can check on your software with the Secunia Software Inspector (http://secunia.com/software_inspector/). Sign up for e-mail notification and they will tell you when to check your system again.
Use Firefox (http://www.mozilla.org/products/) with the NoScript (http://noscript.net/) extension as your web browser.
Download, install and keep an updated version of SpywareBlaster (http://www.javacoolsoftware.com/sbdownload.html).
Do NOT click on links in any I.M. program.
Use Thunderbird (http://www.mozilla.com/en-US/thunderbird/) in place of Outlook or Outlook Express.
DO NOT open attachments from ANYONE. Download them, and scan them with your AV before opening and only if your expect to receive them.
If you use IE download a copy of IE-Spyad (http://www.spywarewarrior.com/uiuc/resource.htm).

panther_base
02-19-2008, 03:02 PM
Use Firefox with the NoScript extension as your web browser.

I do use Firefox as my default browser, but some sites won't run on Firefox, like the F-Secure Online Scanner.

Make sure you have a software firewall and if you are on broadband, get behind a NAT router.

I have firewall software and I've been using only broadband for the last 7 years. Never heard of a NAT router before and I know you guys are always kind of busy here, but would you mind explaining what this does? I know it's extra protection, but what in particular does it protect.


Also...

Thank you for your help, it's very much appreciated.