Welcome! Register for a free account (or login) > How does it work?
|
|
![]() ![]() |
Nov 22 2005, 10:58 AM
Post
#1
|
|
|
New Member ![]() Group: New Member Posts: 4 Joined: 22-November 05 Member No.: 44,505 Operating System: WIndows XP |
I have a problem that whenever I open IE a second explorer window opens up with the addess: http://540.filost.com/randomsites/banner.aspx, which links to AdultFriendFinder.com. The first explorer window stays on my selected home page, so there is no problem with that but I would quite like rid of this AdultFriendFinder. I have scanned with SpyBot and MS anti-spyware but they turned up nothing. I have also scanned with HJT but can't see anything obvious in the log. Can anyone help? Here is the HJT log: Logfile of HijackThis v1.99.1 Scan saved at 16:00:43, on 22/11/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\Program Files\CA\eTrust Antivirus\InoRpc.exe C:\Program Files\CA\eTrust Antivirus\InoRT.exe C:\Program Files\CA\eTrust Antivirus\InoTask.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE C:\Documents and Settings\Jacqueline McManus\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tesco.net/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.tesco.net R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Tesco internet access R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://www-cache.freeserve.com:8080;ftp=http://www-cache.freeserve.com:8080 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;<local> F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: Betfair Bar - {1D62BD48-16F6-4004-A54A-3C41E4955A87} - C:\Program Files\Betfair\BFTool_4.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon O4 - HKLM\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /O6 "USB002" /M "Stylus CX3600" O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.tesco.net O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM) O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab34120.cab O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.co.uk/SnapfishUKActivia.cab O16 - DPF: {4E6F9E15-C8E3-4E19-B987-04EF390E9824} - http://www.betfair.com/install/setup.cab O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1126728188703 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1131398914218 O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/..._1/axofupld.cab O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game15.zylomgames.com/activex/zylomgamesplayer.cab O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedCon...n/bin/cabsa.cab O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} (CBankshotZoneCtrl Class) - http://zone.msn.com/bingame/zpagames/zpa_pool.cab36107.cab O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/default/gf.cab O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab35645.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v5.cab O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - C:\WINDOWS\System32\vbsys2.dll O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe |
|
|
|
Dec 6 2005, 09:20 AM
Post
#2
|
|
|
New Member ![]() Group: New Member Posts: 4 Joined: 22-November 05 Member No.: 44,505 Operating System: WIndows XP |
http://forums.tomcoyote.org/index.php?showtopic=51829&hl= If anybody has time could you have a wee look please? Any help much appreciated. |
|
|
|
Dec 6 2005, 04:55 PM
Post
#3
|
|
![]() R.I.P Always in our hearts ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 3,879 Joined: 26-March 04 From: Clearwater, Florida Member No.: 3,363 Operating System: Windows98SE WindowsXpSP1Pro WindowsXpSP2Home |
Hello and welcome to TomCoyote forum. Sorry for the wait we are extremely busy. Let's get that HJT.exe off the Desktop. Do this for me, open your C:\ and RIGHT click a blank spot then make a new folder. Name it HJT, then move the HJT.exe into that folder. Now it looks like this: C:\HJT\HijackThis.exe and can now store logs and backups for safety. Follow these instructions in the posted order.
1) Download CCleaner from this link: http://www.ccleaner.com/ Review the instructions http://www.ccleaner.com/help/tour1.asp and please do not run it until I ask you to. 2) Download, update, configure and run these two programs: http://tomcoyote.org/aawsb.php The newest version of Ad-aware is 1.06 and Spybot 1.04. Even if you have these programs, use the link to get the newest version, update and configure them as in the link. Run Spybot first, reboot then run Ad-aware. Both programs back up what they remove so delete anything the programs say should be removed. 3) Ewido scan: Please download Ewido Security Suite it is a trial version of the program.
If you are having problems with the updater, you can use this link to manually update Ewido. Ewido manual updates Once the updates are installed do the following:
**(Ewido for example has been flagging parts of AVG Anti-Virus, pcAnywhere and the game "Risk") 4) Run CCleaner, Windows & Applications when you run the registry cleaner (Issues) you will be prompted to backup before you can remove stuff, make sure you do. Then restart the computer and post a new HJT log and the Ewido scan results in this same thread along with any feedback you have. Thanks...pskelley TomCoyote forum Expert Member |
|
|
|
Dec 15 2005, 05:02 AM
Post
#4
|
|
|
New Member ![]() Group: New Member Posts: 4 Joined: 22-November 05 Member No.: 44,505 Operating System: WIndows XP |
Hi,
Firstly thanks very much for taking the time to reply. I have followed your instructions and unfortunately I am still having the same problem. I should say though, that it only happens the first time IE is launched after log on and not every time that it is launched. I know that this may not seem like much of an issue, but children use this computer and I do not want them to see this filth. Also, it's my computer and I would like to have control of it. Here are the HJT and Ewido logs. Any more help would be greatly appreciated. Chris. Logfile of HijackThis v1.99.1 Scan saved at 10:12:35, on 15/12/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\Program Files\ewido\security suite\ewidoguard.exe C:\Program Files\CA\eTrust Antivirus\InoRpc.exe C:\Program Files\CA\eTrust Antivirus\InoRT.exe C:\Program Files\CA\eTrust Antivirus\InoTask.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE C:\Program Files\QuickTime\qttask.exe C:\Anti Spy\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tesco.net/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.tesco.net R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Tesco internet access R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://stsbs:8080 F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: Betfair Bar - {1D62BD48-16F6-4004-A54A-3C41E4955A87} - C:\Program Files\Betfair\BFTool_4.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon O4 - HKLM\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /O6 "USB001" /M "Stylus CX3600" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.tesco.net O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM) O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab34120.cab O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.co.uk/SnapfishUKActivia.cab O16 - DPF: {4E6F9E15-C8E3-4E19-B987-04EF390E9824} - http://www.betfair.com/install/setup.cab O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1126728188703 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1131398914218 O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/..._1/axofupld.cab O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game15.zylomgames.com/activex/zylomgamesplayer.cab O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedCon...n/bin/cabsa.cab O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.sc-server1.bt.com/broadband/MotivePreQual.cab O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} (CBankshotZoneCtrl Class) - http://zone.msn.com/bingame/zpagames/zpa_pool.cab36107.cab O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/default/gf.cab O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab35645.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v5.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{E7AA54D2-2EB0-4A03-8081-B3A24E7B8EBD}: NameServer = 192.168.0.50 O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - C:\WINDOWS\System32\vbsys2.dll O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe -------------------------------------------------------- ewido security suite - Scan report --------------------------------------------------------- + Created on: 08:44:27, 15/12/2005 + Report-Checksum: E0B5BC79 + Scan result: C:\Program Files\BTopenworld\btwebcontrol.dll -> Dialer.Generic : Ignored C:\Program Files\BTopenworld ReInstall\btwebcontrol.dll -> Dialer.Generic : Ignored C:\Program Files\PC Healthcheck\Healthcheck.exe -> Heuristic.Win32.Dialer : Ignored HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{8A0DCBDA-6E20-489C-9041-C1E8A0352E75} -> Spyware.NetNucleus : Cleaned with backup C:\Documents and Settings\Dean Rennie\Cookies\dean rennie@122.2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\Documents and Settings\Dean Rennie\Cookies\dean rennie@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup C:\Documents and Settings\Dean Rennie\Cookies\dean rennie@ivwbox[1].txt -> Spyware.Cookie.Ivwbox : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\Cookies\jacqueline mcmanus@112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\Cookies\jacqueline mcmanus@adopt.euroclick[2].txt -> Spyware.Cookie.Euroclick : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\Cookies\jacqueline mcmanus@e-2dj6wfk4chazwbp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\Cookies\jacqueline mcmanus@e-2dj6wfkiahdjklo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\Cookies\jacqueline mcmanus@e-2dj6wfkiqmc5okq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\Cookies\jacqueline mcmanus@e-2dj6wfloopdzaco.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\Cookies\jacqueline mcmanus@e-2dj6wgkogmczckq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\Cookies\jacqueline mcmanus@e-2dj6wgkyamdpihq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\Cookies\jacqueline mcmanus@e-2dj6wgkyuod5kap.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\Cookies\jacqueline mcmanus@e-2dj6wjl4cgdpgcp.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\Cookies\jacqueline mcmanus@e-2dj6wjlownazoco.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\Cookies\jacqueline mcmanus@e-2dj6wjlyslc5eho.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\Cookies\jacqueline mcmanus@e-2dj6wjnygkczchp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\Cookies\jacqueline mcmanus@e-2dj6wjnyohazwho.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\Cookies\jacqueline mcmanus@microsofteup.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\Cookies\jacqueline mcmanus@microsoftuk.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\Cookies\jacqueline mcmanus@msnportal.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\Cookies\jacqueline mcmanus@service.liveperson[1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup C:\Documents and Settings\Jacqueline McManus\My Documents\BumperSetup-dm.exe -> Spyware.Trymedia : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@adopt.euroclick[1].txt -> Spyware.Cookie.Euroclick : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@adopt.specificclick[2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@cbs.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@cz6.clickzs[1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfk4aodjkdo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfk4chazwbp.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfk4elajabp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfk4ghd5ofo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfk4gkczifp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfk4ogazkfp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfk4ohcjoko.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfk4omazgdp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfk4sjdziap.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfk4umdzigo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfk4wgazwfq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfk4wnc5eeq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkiahc5mep.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkiclcjwcp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkiggdzmao.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkigldzwlq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkiknc5ifo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkikoazwap.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkiooajkgo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkiqkdpgko.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkiqmc5okq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkisiajocq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkiuldjekq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkocid5maq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkocoazwap.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkoejczmbp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkoglczceo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkokpdjwdp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkoohc5iko.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkooic5abo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkoqldzckp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkoqpcjscp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkyahdpoao.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkycmczwfo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkyojcjwao.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkyooczkaq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkyuhcpobp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfkywpdpgbo.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfl4amdzgko.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfl4cpdzido.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfl4eic5wcq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfl4ghd5igo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfl4kpcjefq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfl4oiazaep.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wflianazmbp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wflichajkbq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wflicncjago.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfliemdzahq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfligpczeco.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wflikocjwcp.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wflionazelo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wflionczwhp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wflioocpogo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wflioodpohp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wflisicpilo.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfliwgcjsfp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfliwnc5ekp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfliwnc5oep.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wflocgajeko.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wflochdpabo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wflokgc5oao.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wflokhcjahp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wflokmc5skp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wflowodjoep.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wflykocpicp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wflyukd5gep.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wflyuldpggp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfmicpazafq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfmieoc5gbo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfmigjcjafq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfmiohajmho.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfmiqkajoap.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfmiqlajgcp.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfmiukd5icq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfmiuocjmhp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfmiwmd5wko.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfmycmdpckq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfmyegdpieo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wfmyqnc5seq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wgk4cicpoap.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wgkiehcjcgp.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wgkigpdpmkq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wgkikjazweo.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wgkiugc5cgo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wgkiuod5abo.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wgkoeidpeap.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wgkogmczckq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wgkogmdzggq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wgkyqldpgfp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wgkywoc5abp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wglysldpcdo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjk4amdpchp.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjk4cidzcco.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjk4ehazmhq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjk4ehdziap.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjk4epazafp.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjk4gmc5kfo.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjk4kmajcco.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjk4kmc5whq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjk4knajshp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjk4ogazeap.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjk4omc5sco.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjk4shc5egp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjk4uoazglo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjk4wmajggo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkoajdzido.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkogiczkgp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkoopcpgko.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkoqlcpwko.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkoqldpgkq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkoqocpslq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkoumazacp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkoundjcbp.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkouodzmcp.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkowmdpkdo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkyghdzsdq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkygjd5gfq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkyogdzigo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkyonczchq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkyqhcjggo.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkyqoc5sfp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkyuhdzofo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkywgczwbo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjkywmc5caq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjl4ahd5aap.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjl4alcjoep.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjl4cgdpgcp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjl4ciajmfo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjl4khczoaq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjl4kmczebp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjl4qic5wgq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjl4uhc5scq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjl4uhc5wbo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjl4uhcpegp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjliapcjwdo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlicmcjecp.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjliepdzoeq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlikidpgho.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlikndjgcq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjliqldziaq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjliqpajseo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlisgdjklo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlisid5ego.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlismdpmgo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjloagajikp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjloamcpefo.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjloehczilq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjloejd5gap.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlogkazkbo.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjloopc5mep.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjloqpcpwbo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlosnazklo.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlosnazogo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlownazoco.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlycoc5mdo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlycod5cbo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlyegajeco.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlyejd5wfo.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlykicpadq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlyqlazkep.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlyqndpibp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlyqocjacp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlyshdjogp.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlysjcjiaq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlysjdjihp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlysnd5kbq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlyspajacq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjlywjd5klo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmiahajsgq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmicjcpwgq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmiclc5mgo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmiekcpgko.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmiendjogp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmiepdpcfo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmiggc5odq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmigmcpalp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmigpdzglp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmikidzwdp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmiogczwdq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmioiazkbp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmiojd5seo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmioncpiho.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmiqoajghp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmiuiazkbo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmiukc5afo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmiuncjikp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmyegdpwho.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmykidpwap.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmykmajoao.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmyohcjkao.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmyohdpkao.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmyopc5gfo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmyqndpsgo.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmysid5ifo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmysjdjkdo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmysnajmho.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmyumajicq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmywic5ccp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjmywjdzkdq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjny-1kd5og.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjny-1lazsg.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjnycmcpcep.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjnyeldjehp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjnygkczchp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjnyohazwho.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjnyojazcdq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjnyond5mlo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjnyopd5gho.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjnysmczogp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjnysodpkgp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjnyuiazmlo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@e-2dj6wjnyulc5kdq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@hypertracker[1].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@image.masterstats[1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@ivwbox[1].txt -> Spyware.Cookie.Ivwbox : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@msnportal.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@programs.wegcash[1].txt -> Spyware.Cookie.Wegcash : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@rotator.adjuggler[1].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@service.liveperson[2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@www.burstbeacon[1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup C:\Documents and Settings\James Gallacher\Cookies\james gallacher@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4klazcapaqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@112.2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@adopt.specificclick[1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@e-2dj6wfkyaicpkep.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@e-2dj6wfkyugc5kfp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@e-2dj6wflikgajiko.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@e-2dj6wflyuldpggp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@e-2dj6wfmikndjgdq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@e-2dj6wgkikjazweo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@e-2dj6wgkogmczckq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@e-2dj6wjkoopcpgko.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@e-2dj6wjliqldziaq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@e-2dj6wjloendzido.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@e-2dj6wjlyqndpibp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@e-2dj6wjlysnd5kbq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@e-2dj6wjmiendjogp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@e-2dj6wjmikkczekp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@e-2dj6wjmyahc5cco.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@e-2dj6wjmyohdpkao.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@e-2dj6wjnyohazwho.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@rotator.adjuggler[1].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\Cookies\james gallacher@thomascook.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\dia2.exe -> Heuristic.Win32.Dialer : Cleaned with backup C:\Documents and Settings\James Gallacher\Local Settings\Temp\dload.exe -> Downloader.Small.dg : Cleaned with backup C:\Documents and Settings\James Gallacher\My Documents\TowerBlasterSetup-dm.exe -> Spyware.Trymedia : Cleaned with backup C:\Downloads\AlienX-dm[1].exe -> Spyware.Trymedia : Cleaned with backup C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.RiskWare.Downloader.PopCap.a : Cleaned with backup C:\WINDOWS\sndman.exe -> Backdoor.Webdor.af : Cleaned with backup C:\WINDOWS\timer.exe -> Backdoor.Webdor.ag : Cleaned with backup ::Report End |
|
|
|
Dec 15 2005, 06:50 AM
Post
#5
|
|
![]() R.I.P Always in our hearts ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 3,879 Joined: 26-March 04 From: Clearwater, Florida Member No.: 3,363 Operating System: Windows98SE WindowsXpSP1Pro WindowsXpSP2Home |
Hello Chris and thanks for the feedback. Let me say this junk often does not come of as easy as it got on. It all depends on how bad the infection is. We have completed the first step and I will review the information you posted and give you the next saep, thanks...Phil
ewido: Here is information to help you control those cookies: http://www.mvps.org/winhelp2002/cookies.htm http://www.microsoft.com/windows/ie/using/...acy/config.mspx Logfile of HijackThis v1.99.1 Scan saved at 10:12:35, on 15/12/2005 Open HijackThis and choose "Do a system scan only" then check the box in front of these line items: O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) (next two, if you do not want those restrictions you may check and remove them) O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM) O16 - DPF: {4E6F9E15-C8E3-4E19-B987-04EF390E9824} - http://www.betfair.com/install/setup.cab (above is on the IESPYADS restricted list) O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game15.zylomgames.com/activex/zylomgamesplayer.cab O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} (CBankshotZoneCtrl Class) - http://zone.msn.com/bingame/zpagames/zpa_pool.cab36107.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v5.cab (above three can be left if you are 100% sure it is safe, many infections happen this way, the games are free, the infection that can come with them is not) O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - C:\WINDOWS\System32\vbsys2.dll see this link >>> http://www.sophos.com/virusinfo/analyses/trojadclickac.html Close all programs but HJT and all browser windows, then click on "Fix Checked" Enable hidden files&folders..reverse the process when finished. http://www.xtra.co.nz/help/0,,4155-1916458,00.html RIGHT Click on Start then click on Explore. Locate and delete these items: C:\WINDOWS\System32\vbsys2.dll <<< look for this file and delete it if is there C:\Windows\Prefetch\ >>> delete everything in this folder (NOT THE FOLDER) Prefetch info: http://www.windowsnetworking.com/articles_...refetch-XP.html I am assuming that you know this item is running from your services and that you know it is safe: O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe If this is not true make me aware of it. Empty the recycle bin and restart your computer. Post a new HJT log for a final look. Let me know how you are running now. Thanks...Phil |
|
|
|
Dec 15 2005, 10:06 AM
Post
#6
|
|
|
New Member ![]() Group: New Member Posts: 4 Joined: 22-November 05 Member No.: 44,505 Operating System: WIndows XP |
Superb, problem is gone now. Thanks so much. Here is the final HJT log if you're interested.
Thanks again, Chris. Logfile of HijackThis v1.99.1 Scan saved at 15:43:35, on 15/12/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\Program Files\CA\eTrust Antivirus\InoRpc.exe C:\Program Files\CA\eTrust Antivirus\InoRT.exe C:\Program Files\CA\eTrust Antivirus\InoTask.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\rundll32.exe C:\Anti Spy\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tesco.net/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.tesco.net R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Tesco internet access R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=http://www-cache.freeserve.com:8080;gopher=http://stsbs:8080;http=http://www-cache.freeserve.com:8080;https=http://stsbs:8080 F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: Betfair Bar - {1D62BD48-16F6-4004-A54A-3C41E4955A87} - C:\Program Files\Betfair\BFTool_4.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon O4 - HKLM\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /O6 "USB001" /M "Stylus CX3600" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.tesco.net O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab34120.cab O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.co.uk/SnapfishUKActivia.cab O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1126728188703 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1131398914218 O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/..._1/axofupld.cab O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedCon...n/bin/cabsa.cab O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.sc-server1.bt.com/broadband/MotivePreQual.cab O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/default/gf.cab O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab35645.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{E7AA54D2-2EB0-4A03-8081-B3A24E7B8EBD}: NameServer = 192.168.0.50 O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing) |
|
|
|
Dec 15 2005, 10:32 AM
Post
#7
|
|
![]() R.I.P Always in our hearts ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 3,879 Joined: 26-March 04 From: Clearwater, Florida Member No.: 3,363 Operating System: Windows98SE WindowsXpSP1Pro WindowsXpSP2Home |
Hi Chris, thanks for the feedback, and glad that fixed your problem. Looking over the last log I spotted an item I believe you should remove. It seems to be associated with the ActiveX that IE-Spyad warned me about.
Here is that item: O3 - Toolbar: Betfair Bar - {1D62BD48-16F6-4004-A54A-3C41E4955A87} - C:\Program Files\Betfair\BFTool_4.dll I would use HJT to remove this item were I you. http://www.google.com/search?hl=en&q=Eric+...G=Google+Search http://www.bleepingcomputer.com/forums/ind...showtutorial=53 The balance of the log look great. Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online: http://boards.cexx.org/viewtopic.php?t=957 http://russelltexas.com/malware/allclear.htm http://forum.malwareremoval.com/viewtopic.php?t=14 http://www.bleepingcomputer.com/forums/topict2520.html Safe surfing and have a great Christmas...Phil Thanks...pskelley TomCoyote forum Expert Member If you are reading this information...thank a teacher, If you are reading it in English...thank a soldier. |
|
|
|
Dec 19 2005, 09:26 AM
Post
#8
|
|
![]() R.I.P Always in our hearts ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 3,879 Joined: 26-March 04 From: Clearwater, Florida Member No.: 3,363 Operating System: Windows98SE WindowsXpSP1Pro WindowsXpSP2Home |
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.
Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted. Make sure you use proper prevention to keep from having problems occur to your computer in the future. Coyote's Installed programs for prevention: http://forums.tomcoyote.org/index.php?showtopic=31418 The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online. Visit the CoyoteStore http://TomCoyote.org/coyotestore.php |
|
|
|
![]() ![]() |
|
Time is now: 9th February 2010 - 02:43 AM |