View Full Version : "Open With" Virus
Aallmark
06-10-2010, 09:10 PM
I'm pretty sure I downloaded a rogue anti spyware by mistake. My computer task manager, run, and other progams have been disabled and every other application must be opened by selecting a program in an "open with" box. Most of the security websites I try to open won't work. Please help me, I'm trying to study and I don't need this right now!!!
classicsoftware
06-10-2010, 09:25 PM
Even though you don't have this exact infection. try the method here (http://www.bleepingcomputer.com/virus-removal/remove-win-antispyware-center)and post the log from the MBAM scan.
Aallmark
06-12-2010, 01:24 PM
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4190
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702
6/12/2010 1:08:53 PM
mbam-log-2010-06-12 (13-08-53).txt
Scan type: Full scan (C:\|D:\|)
Objects scanned: 539756
Time elapsed: 2 hour(s), 31 minute(s), 5 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 17
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\pragmarxbdriyuet (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Paladin Antivirus (Rogue.PaladinAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\pragma (Rootkit.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus (Rogue.PaladinAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\PRAGMA (Rootkit.TDSS) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\xmihoqeziwa (Trojan.Hiloti.Gen) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\WINDOWS\PRAGMArxbdriyuet (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator.EXPERIEN-7E2A47\Local Settings\Application Data\Gameztar Toolbar (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Program Files\Gameztar Toolbar (Adware.DoubleD) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\atcdfga.dll (Trojan.Hiloti.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator.EXPERIEN-7E2A47\Local Settings\Temp\ZotJgWZkMa.exe (Trojan.Hiloti.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\PRAGMArxbdriyuet\PRAGMAc.dll (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\WINDOWS\PRAGMArxbdriyuet\PRAGMAd.sys (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\WINDOWS\PRAGMArxbdriyuet\pragmaserf.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\PRAGMArxbdriyuet\pragmabbr.dll (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\WINDOWS\PRAGMArxbdriyuet\PRAGMAcfg.ini (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\WINDOWS\PRAGMArxbdriyuet\PRAGMAsrcr.dat (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users.WINDOWS\Application Data\pragmamfeklnmal.dll (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users.WINDOWS\Favorites\_favdata.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator.EXPERIEN-7E2A47\Local Settings\Temp\0.6574380635582815.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator.EXPERIEN-7E2A47\Local Settings\Temp\e.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator.EXPERIEN-7E2A47\Local Settings\Temp\PRAGMA6c51.tmp (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator.EXPERIEN-7E2A47\Local Settings\Temp\pragmamainqt.dll (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator.EXPERIEN-7E2A47\Local Settings\Application Data\ave.exe (Rogue.MultipleAV) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator.EXPERIEN-7E2A47\Local Settings\Application Data\MSASCui.exe (Rogue.MultipleAV) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator.EXPERIEN-7E2A47\Desktop\eXplorer.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
classicsoftware
06-12-2010, 09:19 PM
So, how is the system running.
Aallmark
06-12-2010, 09:45 PM
Much better. I got rid of the "open with" aspect a couple days but I had this "run as" thing that popped up that I supposed was blocking the virus. That's gone now. I'm still getting some adware (on IE) and the pages occasionally redirect (on Firefox/Opera) to a phony website or a website advertising a fake anti spyware program, so I imagine I still must have something.
classicsoftware
06-12-2010, 10:16 PM
Run MBAM again and post the log.
Aallmark
06-13-2010, 05:10 PM
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4190
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
6/13/2010 4:45:48 PM
mbam-log-2010-06-13 (16-45-48).txt
Scan type: Full scan (C:\|D:\|)
Objects scanned: 532580
Time elapsed: 4 hour(s), 13 minute(s), 7 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Aallmark
06-15-2010, 11:35 PM
Any help? Malwarebytes showed nothing but Spyware Doctor showed I have 2 threats (Application.TrackingCookies (6 infections-low threat) and Rootkit.TDSS (44 infections-medium threat)). I'm really scared about the rootkit-I read that it's basically impossible to remove. Is this true?
classicsoftware
06-16-2010, 06:56 AM
Post the log from Spyware Doctor. Did it remove it?
Aallmark
06-16-2010, 11:25 AM
I don't have the subscribed version of it, so I don't think I can do either.
classicsoftware
06-16-2010, 11:23 PM
Did it identify the file?
Aallmark
06-16-2010, 11:56 PM
Yeah, it gives the registry key and registry value.
classicsoftware
06-17-2010, 01:48 AM
And it is?
Post the info plus a hijackthis log....
Aallmark
06-19-2010, 05:11 PM
I ran the full scan and got a different result. The only thing is, I can't copy and paste the results. Do you want me to type them out?
Here's the HJT logfile:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:09:18 PM, on 6/19/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Spyware Doctor\upgrade.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Spyware Doctor\pctsGui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: PC Tools Browser Guard - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrow serrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 9357 bytes
Aallmark
06-24-2010, 02:10 PM
Hello? Is anyone there?
classicsoftware
06-25-2010, 12:45 AM
First disable Tea-Timer:
Turn off TeaTimer to remove those entries. Open Spybot S&D in advanced mode, click Tools > Resident, and remove the check from "Resident Tea-Timer". Reboot after unchecking the entry.
Did you run SAS and is there a log?
Type out the info from Spyware Doctor
Aallmark
06-27-2010, 03:41 PM
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 06/27/2010 at 03:06 PM
Application Version : 4.39.1002
Core Rules Database Version : 5066
Trace Rules Database Version: 2878
Scan type : Complete Scan
Total Scan Time : 01:40:04
Memory items scanned : 497
Memory threats detected : 0
Registry items scanned : 6073
Registry threats detected : 0
File items scanned : 23681
File threats detected : 207
Adware.Tracking Cookie
C:\Documents and Settings\Administrator.EXPERIEN-7E2A47\Cookies\administrator@atdmt[2].txt
C:\Documents and Settings\Administrator.EXPERIEN-7E2A47\Cookies\administrator@2o7[2].txt
C:\Documents and Settings\Administrator.EXPERIEN-7E2A47\Cookies\administrator@dc.tremormedia[2].txt
C:\Documents and Settings\Administrator.EXPERIEN-7E2A47\Cookies\administrator@doubleclick[1].txt
.media6degrees.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.specificclick.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.specificclick.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.specificclick.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.specificclick.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.specificclick.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.specificclick.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.specificclick.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.specificclick.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.specificclick.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.specificmedia.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.specificclick.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.imrworldwide.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.imrworldwide.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.collective-media.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.collective-media.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.collective-media.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.collective-media.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.atwola.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.at.atwola.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.at.atwola.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.specificmedia.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.kontera.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.kontera.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
rotator.adjuggler.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
rotator.adjuggler.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
www.burstbeacon.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application
Aallmark
06-27-2010, 03:45 PM
Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.dmtracker.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.apmebf.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.kontera.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.adopt.specificclick.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.at.atwola.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.edge.ru4.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.edge.ru4.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.specificclick.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.specificclick.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.specificclick.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
ads.mediageeks.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.sixapart.adbureau.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.iacas.adbureau.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.xiti.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.network.realmedia.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.warnerbros.112.2o7.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
cdn3.specificmedia.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.sixapart.adbureau.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.mediamatters.org [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.mediabistro.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.mediabistro.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.mediabistro.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.viacom.adbureau.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.viacom.adbureau.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.viacom.adbureau.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.a1.interclick.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.interclick.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.a1.interclick.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.a1.interclick.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.eb.adbureau.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.eb.adbureau.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.eb.adbureau.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.eb.adbureau.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.eb.adbureau.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.eb.adbureau.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
adserver.adreactor.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.a1.interclick.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.iacas.adbureau.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.iacas.adbureau.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.iacas.adbureau.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.iacas.adbureau.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.iacas.adbureau.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
web4.realtracker.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.adbureau.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.123count.com [ C:\Documents and Settings\Alex\Application
Aallmark
06-27-2010, 03:45 PM
Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.123count.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.123count.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.interclick.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.specificclick.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.apmebf.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
cdn4.specificclick.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.borders.112.2o7.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.nextag.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.nextag.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
server.iad.liveperson.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
server.iad.liveperson.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.chitika.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.findfreesheetmusic.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.findfreesheetmusic.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.findfreesheetmusic.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.shopit.112.2o7.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
adserving.cpxinteractive.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.adecn.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.adserver.adtechus.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.mediamatters.org [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.mediamatters.org [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
data.coremetrics.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.gostats.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
server.cpmstar.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.specificclick.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.adlegend.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.adlegend.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
ads.bridgetrack.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
wizard.liveperson.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
imediablast.com [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.msnbc.112.2o7.net [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.teens4hire.org [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
.teens4hire.org [ C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\ndvmgbz7.default\coo kies.sqlite ]
media.mtvnservices.com [ C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\Macromedia\Flash Player\#SharedObjects\C8JJB8X3 ]
objects.tremormedia.com [ C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\Macromedia\Flash Player\#SharedObjects\C8JJB8X3 ]
secure-us.imrworldwide.com [ C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\Macromedia\Flash Player\#SharedObjects\C8JJB8X3 ]
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@2o7[1].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@ads.pointroll[1].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@ads.undertone[1].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@atdmt[1].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@atdmt[3].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@cdn4.specificclick[1].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@cdn4.specificclick[3].txt
C:\Documents and Settings\LocalService.NT
Aallmark
06-27-2010, 03:46 PM
AUTHORITY\Cookies\system@clicksor[1].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@doubleclick[2].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@fastclick[1].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@imrworldwide[2].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@myroitracking[1].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@network.realmedia[1].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@network.realmedia[2].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@overture[2].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@pointroll[2].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@realmedia[1].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@realmedia[2].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@specificclick[2].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@specificclick[3].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@specificmedia[1].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@specificmedia[2].txt
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\system@viacom.adbureau[1].txt
.at.atwola.com [ C:\Documents and Settings\Maryann\Application Data\Mozilla\Firefox\Profiles\rves9tnn.default\coo kies.sqlite ]
.atdmt.com [ C:\Documents and Settings\Maryann\Application Data\Mozilla\Firefox\Profiles\rves9tnn.default\coo kies.sqlite ]
.atdmt.com [ C:\Documents and Settings\Maryann\Application Data\Mozilla\Firefox\Profiles\rves9tnn.default\coo kies.sqlite ]
cdn.at.atwola.com [ C:\Documents and Settings\Maryann\Application Data\Mozilla\Firefox\Profiles\rves9tnn.default\coo kies.sqlite ]
.tacoda.net [ C:\Documents and Settings\Maryann\Application Data\Mozilla\Firefox\Profiles\rves9tnn.default\coo kies.sqlite ]
.tacoda.net [ C:\Documents and Settings\Maryann\Application Data\Mozilla\Firefox\Profiles\rves9tnn.default\coo kies.sqlite ]
.tacoda.net [ C:\Documents and Settings\Maryann\Application Data\Mozilla\Firefox\Profiles\rves9tnn.default\coo kies.sqlite ]
.tacoda.net [ C:\Documents and Settings\Maryann\Application Data\Mozilla\Firefox\Profiles\rves9tnn.default\coo kies.sqlite ]
.tacoda.net [ C:\Documents and Settings\Maryann\Application Data\Mozilla\Firefox\Profiles\rves9tnn.default\coo kies.sqlite ]
.tacoda.net [ C:\Documents and Settings\Maryann\Application Data\Mozilla\Firefox\Profiles\rves9tnn.default\coo kies.sqlite ]
.atwola.com [ C:\Documents and Settings\Maryann\Application Data\Mozilla\Firefox\Profiles\rves9tnn.default\coo kies.sqlite ]
.at.atwola.com [ C:\Documents and Settings\Maryann\Application Data\Mozilla\Firefox\Profiles\rves9tnn.default\coo kies.sqlite ]
.at.atwola.com [ C:\Documents and Settings\Maryann\Application Data\Mozilla\Firefox\Profiles\rves9tnn.default\coo kies.sqlite ]
.advertising.com [ C:\Documents and Settings\Maryann\Application Data\Mozilla\Firefox\Profiles\rves9tnn.default\coo kies.sqlite ]
.advertising.com [ C:\Documents and Settings\Maryann\Application Data\Mozilla\Firefox\Profiles\rves9tnn.default\coo kies.sqlite ]
.questionmarket.com [ C:\Documents and Settings\Maryann\Application Data\Mozilla\Firefox\Profiles\rves9tnn.default\coo kies.sqlite ]
.questionmarket.com [ C:\Documents and Settings\Maryann\Application Data\Mozilla\Firefox\Profiles\rves9tnn.default\coo kies.sqlite ]
.questionmarket.com [ C:\Documents and Settings\Maryann\Application Data\Mozilla\Firefox\Profiles\rves9tnn.default\coo kies.sqlite ]
core.insightexpressai.com [ C:\Documents and Settings\NetworkService.NT AUTHORITY\Application Data\Macromedia\Flash Player\#SharedObjects\T5RJHKYX ]
objects.tremormedia.com [ C:\Documents and Settings\NetworkService.NT AUTHORITY\Application Data\Macromedia\Flash Player\#SharedObjects\T5RJHKYX ]
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@ad.yieldmanager[1].txt
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@ads.bighealthtree[1].txt
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@ads.financialcontent[2].txt
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@ads.gossipcenter[1].txt
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@ads.undertone[2].txt
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@adserver.adtechus[1].txt
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@advertise[2].txt
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@advertise[3].txt
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@apmebf[1].txt
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@atdmt[1].txt
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@bizzclick[1].txt
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@dc.tremormedia[2].txt
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@doubleclick[1].txt
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@doubleclick[2].txt
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@fastclick[2].txt
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@network.realmedia[1].txt
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\system@realmedia[1].txt
classicsoftware
06-27-2010, 09:14 PM
How does the system run? Any different?
Aallmark
06-28-2010, 12:08 PM
Eh...maybe. I'm still getting popups and such. I should get to work on posting that SpyWare Doctor information.
Aallmark
06-30-2010, 01:25 PM
I also forgot to mention that I often lose audio and upon clicking on the speaker icon, I get a message saying "there are no active mixer devices available." I researched this problem and found a solution (clicking start -> run -> services.msc -> windows audio -> changing service status from "stopped" to "start") but this is only temporary. Also, my taskbar and eventually internet browser will be changed to the old, tan Windows theme without my intervention.
classicsoftware
06-30-2010, 10:55 PM
Personally, you either have a really deep seated infection or a Windows installation that has coughed up a hair ball.
Let's take a shot in the dark. Please follow the instructions (http://www.bleepingcomputer.com/virus-removal/remove-tdss-tdl3-alureon-rootkit-using-tdsskiller) here for removal of a root kit infectiom
Aallmark
07-05-2010, 01:11 PM
I thought everything was going much better after following your advice (exceptions: my regularly scheduled Spyware Doctor scan is still picking up rootkits, I'm getting a notification upon startup for the Windows Genuine Advantage installation (I'm pretty sure it's not the virus version, but I don't know how it got there)) until I was trying to vote for a Pepsi grant for my mother and I got a blue screen.
classicsoftware
07-05-2010, 11:04 PM
Please run the scan I asked you to run
Aallmark
07-08-2010, 10:18 AM
The rootkit one? I did that. Should I do it again?
classicsoftware
07-08-2010, 02:56 PM
The rootkit one? I did that. Should I do it again?
Post the results.....
vBulletin v3.6.1, Copyright ©2000-2012, Jelsoft Enterprises Ltd.