This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT Log - PC won't browse web

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My (other) PC has internet connectivity (ping works fine) but neither Firefox nor IE can browse to any page on the internet. IE gives an error box: "IE could not open the search page" and the status line shows: "Downloading from site: res://C:\WINDOWS\system32\shdoclc.dll/dnserror.html"

The affected PC's IPCONFIG response is similar to a working PC on the same subnet. I can use Windows file sharing between the 2 pc's (connected via a router).

Thanks for helping!
/Mundi

Here's my HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 9:58:13 PM, on 11/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\VNC4\WinVNC4.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ufrjik.exe
C:\WINDOWS\system32\skypeupd.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
c:\My Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [\\ANTARES\EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P40 "\\ANTARES\EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Update Layer] ufrjik.exe
O4 - HKLM\..\Run: [Skype updater] skypeupd.exe
O4 - HKLM\..\Run: [Microsoft] winupd.exe
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exe
O4 - HKLM\..\RunServices: [Windows Update Layer] ufrjik.exe
O4 - HKLM\..\RunServices: [Skype updater] skypeupd.exe
O4 - HKLM\..\RunServices: [Microsoft] winupd.exe
O4 - HKCU\..\Run: [Windows Update Layer] ufrjik.exe
O4 - HKCU\..\Run: [Microsoft] winupd.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O21 - SSODL: Sndeterr - {522B6EBE-6F2F-445C-BA36-002BFF99746C} - C:\WINDOWS\system32\ipvassys.dll
O21 - SSODL: Logofdoc - {DAF4EBA1-8B97-473E-A2FC-38E2CB2ED489} - C:\WINDOWS\system32\bromaman.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\VNC4\WinVNC4.exe" -service (file missing)
torrmundi

Welcome to Tom Coyote

Download SDFix and save it to your desktop.

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • In Safe Mode, right click the SDFix.zip folder and choose Extract All,
  • Open the extracted folder and double click RunThis.bat to start the script.
  • Type Y to begin the script.
  • It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • Your system will take longer that normal to restart as the fixtool will be running and removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
  • Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log
Thanks bamajim
Bamijim,

Thanks for the help. Here's the SDFIX log, followed by the new HJT log.

After running SDFix, i can use IE to browse to Google and search, but then clicking upon any search link, I got nothing further. Firefox gets less; it won't load Google completely.

/torrmundi
———————————————————–

SDFix: Version 1.36
——————-

Scan run on:
Sat 11/11/2006

Time:
06:51 PM

Microsoft Windows XP [Version 5.1.2600]

Running from: C:\Documents and Settings\[removed]\Desktop\SDFix

Stage One…

Checking Services…

Name:
—–
SVKP

Path:
—-
\??\C:\WINDOWS\system32\SVKP.sys

SVKP Deleted…

Repairing Registry…


Restoring Default Hosts File…

Stage One Complete

Rebooting…

Stage Two…

Checking For Malware:
——————–

C:\WINDOWS\system32\i
C:\WINDOWS\system32\SVKP.SYS
C:\WINDOWS\system32\winupd.exe

Backing Up and Removing any Files Found…

Final Check:

Services:
———


Files:
——


Any files removed are saved to the SDFix\backups Folder

FINISHED
———————————————————–
Logfile of HijackThis v1.99.1
Scan saved at 7:41:35 PM, on 11/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\VNC4\WinVNC4.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE
C:\WINDOWS\system32\skypeupd.exe
C:\WINDOWS\system32\ufrjik.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\John\Application Data\Microsoft\Internet Explorer\Quick Launch\TOTALCMD.EXE
c:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [\\ANTARES\EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P40 "\\ANTARES\EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [Skype updater] skypeupd.exe
O4 - HKLM\..\Run: [Windows Update Layer] ufrjik.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exe
O4 - HKLM\..\RunServices: [Windows Update Layer] ufrjik.exe
O4 - HKLM\..\RunServices: [Skype updater] skypeupd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Windows Update Layer] ufrjik.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O21 - SSODL: Sndeterr - {522B6EBE-6F2F-445C-BA36-002BFF99746C} - C:\WINDOWS\system32\ipvassys.dll
O21 - SSODL: Logofdoc - {DAF4EBA1-8B97-473E-A2FC-38E2CB2ED489} - C:\WINDOWS\system32\bromaman.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\VNC4\WinVNC4.exe" -service (file missing)
torrmundi

Your welocme, sounds like we are making a little progress

We need to temporarily disable Norton Scriptblocking
To disable Norton AntiVirus Script Blocking:1. Start Norton AntiVirus.
If Norton AntiVirus is installed as part of Norton SystemWorks or Norton Internet Security, then start that program.
2. Click Options.
If you see a menu, click Norton AntiVirus.
3. In the left pane, click Script Blocking.
4. In the right pane, uncheck Enable Script Blocking (recommended).
5. Click OK.
We need to make sure we can see hidden files and foldersClick Start.
Click My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab.
Under the Hidden files and folders heading select Show hidden files and folders.
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Uncheck the Hide file extensions for known file types.
Click OK.
First Please download the Killbox.1)Save it to the desktop and run it.
2) Select "Delete on Reboot", and then select "All files".
3) Copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\WINDOWS\system32\ufrjik.exe


4) Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
5) Click the red-and-white "Delete File" button.  Click "Yes" at the Delete on Reboot prompt.  Click "No" at the Pending Operations prompt.
Next rerun Hijackthis (scan only) and place checks beside the following entries (if found)O4 - HKLM\..\Run: [Windows Update Layer] ufrjik.exe
O4 - HKLM\..\RunServices: [Windows Update Layer] ufrjik.exe
O4 - HKCU\..\Run: [Windows Update Layer] ufrjik.exe

Close all other open windows except Hijackthis and Select "Fix checked"

Reboot your PC->>Reboot your PC->>Rerun Hijackthis and post a fresh log

thanks bamajim
Bamajim,

After using Killbox & HJT to remove files, then rebooting, it seems like Firefox was browsing OK, thru Google to other sites. I was able to run Real's auto-updater on RealMedia Player as well. But then I started IE and it all we nt back to no internet access, for IE or Firefox. RealMedia Player reports no internet connection as well.

Here's the HJT log, after all that.

Thanks,
/torrmundi

—————————————–
Logfile of HijackThis v1.99.1
Scan saved at 10:27:32 PM, on 11/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\VNC4\WinVNC4.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\skypeupd.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [\\ANTARES\EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P40 "\\ANTARES\EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [Skype updater] skypeupd.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunServices: [Skype updater] skypeupd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O21 - SSODL: Sndeterr - {522B6EBE-6F2F-445C-BA36-002BFF99746C} - C:\WINDOWS\system32\ipvassys.dll
O21 - SSODL: Logofdoc - {DAF4EBA1-8B97-473E-A2FC-38E2CB2ED489} - C:\WINDOWS\system32\bromaman.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\VNC4\WinVNC4.exe" -service (file missing)
torrmundi

Looking better

First Please download hosterAnd Save it to your Desktop
Rt Click Hoster.zip->>Extract all->>Extract it to your Desktop
Open The Hoster folder->>Double Click Hoster.exe (It will look like a yeild sign with a stop light in the center)
When the program Opens Click The "Restore Original Hosts" Button
Close the Hoster program when complete
Next Go here and Download AVG Anti-Spyware
(30 day free trial version) Save it to Your Desktop
 
Double Click AVG Anti-Spyware-setup
(It will create its own folder)
Once the program starts You will be at the Status menuUnder "Your computers Security"
Click change status on Resident shield to inactive
Click Update now (next to last update)
After the update loads
Under Automatic updates Uncheck download and install updates automatically(recommended)
(you can always select maual updates the next day)
At the top toolbar Click Scanner Then the settings tabUnder How to act? Set default action for detected malwareTo Quarantine
Under how to scan All boxes should be checked
Under Possibly unwanted software All boxes should be checked
Under reports Select Automatically generate report after every scan
Uncheck Only if threats were found
Under what to scan Scan every file should be highlited
Exit AVG(But do not run it yet)
 
Reboot into Safe Mode
This can be done byRestart your PC, and after it starts, but before you see the Windows Splash screen
Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
Use your arrow keys and select Safe Mode and then Enter
Run AVG Anti-SpywareClick scanner
Select Complete system scan
Once the scan finishesSelect Apply all actions (The items found will be quarantined)
Click save report as (Another window will open)
Save it to your desktop
(By default It will be saved in the AVG folder as)
C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports
Exit AVG
 
Reboot your PC in Normal Mode->>Re run Hijackthis and post a fresh Hijackthis log.Double click the report-scan txt. you saved to your desktop
It will open in Notepad
Copy and paste that report as a reply to this thread
Your reply should includea fresh Hijackthis log
your report_scan.txt log from AVG
thanks bamajim
Hi Bamajim, All completed. I had to install AVG on another machine, update it there, then transfer the update files to the bad PC. After all steps are done, neither Firefox, nor IE will browse. I do notice that right after a reboot, I can sometimes get some connectivity, although it is very slow connectivity. ——————————————————— AVGAnti-Spyware-ScanReport ——————————————————— +Createdat: 6:49:25AM11/14/2006 +Scanresult: C:\DocumentsandSettings\Ivan\winser.exe->Backdoor.Rbot:Cleaned. C:\SystemVolumeInformation\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP2\A0001040.exe->Backdoor.Rbot:Cleaned. C:\DocumentsandSettings\Ivan\vncs.exe->Backdoor.Rbot.bmr:Cleaned. C:\WINDOWS\system32\gqgn.exe->Backdoor.Rbot.bmr:Cleaned. :mozilla.368:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.247realmedia:Cleaned. :mozilla.369:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.247realmedia:Cleaned. :mozilla.370:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.247realmedia:Cleaned. :mozilla.588:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.247realmedia:Cleaned. :mozilla.589:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.247realmedia:Cleaned. :mozilla.590:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.247realmedia:Cleaned. :mozilla.100:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.101:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.102:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.103:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.104:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.105:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.106:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.107:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.108:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.109:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.110:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.111:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.112:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.113:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.114:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.114:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.115:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.115:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.116:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.116:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.117:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.117:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.118:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.118:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.119:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.119:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.120:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.120:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.121:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.121:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.122:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.122:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.123:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.123:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.124:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.124:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.125:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.126:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.127:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.128:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.129:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.130:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.131:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.132:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.133:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.134:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.135:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.136:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.137:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.138:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.139:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.140:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.141:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.142:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.143:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.144:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.145:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.146:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.235:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.311:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.350:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.403:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.472:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.496:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.530:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.534:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.559:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.591:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.638:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.702:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.739:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.804:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.80:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.81:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.82:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.83:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.84:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.85:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.862:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.864:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.86:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.87:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.88:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.89:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.90:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.91:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.92:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.93:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.941:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.94:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.95:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.96:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.97:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.98:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. :mozilla.99:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.2o7:Cleaned. C:\DocumentsandSettings\Anya\Cookies\anya@2o7[2].txt->TrackingCookie.2o7:Cleaned. C:\DocumentsandSettings\Anya\Cookies\anya@gateway.122.2o7[1].txt->TrackingCookie.2o7:Cleaned. C:\DocumentsandSettings\Anya\Cookies\anya@msnportal.112.2o7[1].txt->TrackingCookie.2o7:Cleaned. C:\DocumentsandSettings\Ivan\Cookies\ivan@2o7[2].txt->TrackingCookie.2o7:Cleaned. C:\DocumentsandSettings\Ivan\Cookies\ivan@gateway.122.2o7[1].txt->TrackingCookie.2o7:Cleaned. C:\DocumentsandSettings\Ivan\Cookies\ivan@msnportal.112.2o7[1].txt->TrackingCookie.2o7:Cleaned. :mozilla.329:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Aavalue:Cleaned. :mozilla.330:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Aavalue:Cleaned. :mozilla.331:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Aavalue:Cleaned. :mozilla.332:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Aavalue:Cleaned. :mozilla.333:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Aavalue:Cleaned. :mozilla.334:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Aavalue:Cleaned. :mozilla.335:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Aavalue:Cleaned. :mozilla.336:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Aavalue:Cleaned. :mozilla.337:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Aavalue:Cleaned. :mozilla.338:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Aavalue:Cleaned. :mozilla.339:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Aavalue:Cleaned. :mozilla.211:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Adbrite:Cleaned. :mozilla.212:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Adbrite:Cleaned. :mozilla.213:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Adbrite:Cleaned. :mozilla.247:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adbrite:Cleaned. :mozilla.248:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adbrite:Cleaned. :mozilla.249:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adbrite:Cleaned. :mozilla.758:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adbrite:Cleaned. :mozilla.759:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adbrite:Cleaned. :mozilla.760:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adbrite:Cleaned. :mozilla.761:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adbrite:Cleaned. :mozilla.923:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Adbrite:Cleaned. :mozilla.924:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Adbrite:Cleaned. :mozilla.380:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Addynamix:Cleaned. :mozilla.114:C:\DocumentsandSettings\Admin\ApplicationData\Mozilla\Firefox\Profiles\li25yagx.default\cookies.txt->TrackingCookie.Adjuggler:Cleaned. :mozilla.915:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adocean:Cleaned. :mozilla.916:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adocean:Cleaned. :mozilla.884:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adrevolver:Cleaned. :mozilla.885:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adrevolver:Cleaned. :mozilla.886:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adrevolver:Cleaned. :mozilla.887:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adrevolver:Cleaned. :mozilla.888:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adrevolver:Cleaned. C:\DocumentsandSettings\Ivan\Cookies\ivan@adrevolver[2].txt->TrackingCookie.Adrevolver:Cleaned. :mozilla.111:C:\DocumentsandSettings\Admin\ApplicationData\Mozilla\Firefox\Profiles\li25yagx.default\cookies.txt->TrackingCookie.Adserver:Cleaned. :mozilla.112:C:\DocumentsandSettings\Admin\ApplicationData\Mozilla\Firefox\Profiles\li25yagx.default\cookies.txt->TrackingCookie.Adserver:Cleaned. :mozilla.670:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adserver:Cleaned. :mozilla.671:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adserver:Cleaned. :mozilla.672:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adserver:Cleaned. :mozilla.673:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adserver:Cleaned. :mozilla.674:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adserver:Cleaned. :mozilla.911:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Adserver:Cleaned. :mozilla.912:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Adserver:Cleaned. :mozilla.913:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Adserver:Cleaned. :mozilla.681:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adtech:Cleaned. :mozilla.682:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Adtech:Cleaned. :mozilla.103:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Advertising:Cleaned. :mozilla.65:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Advertising:Cleaned. :mozilla.67:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Advertising:Cleaned. :mozilla.68:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Advertising:Cleaned. :mozilla.73:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Advertising:Cleaned. :mozilla.74:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Advertising:Cleaned. :mozilla.83:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Advertising:Cleaned. :mozilla.84:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Advertising:Cleaned. :mozilla.94:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Advertising:Cleaned. :mozilla.98:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Advertising:Cleaned. C:\DocumentsandSettings\Ivan\Cookies\ivan@advertising[2].txt->TrackingCookie.Advertising:Cleaned. :mozilla.10:C:\DocumentsandSettings\John\ApplicationData\Mozilla\Firefox\Profiles\xojl87y3.default\cookies.txt->TrackingCookie.Atdmt:Cleaned. :mozilla.177:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Atdmt:Cleaned. :mozilla.208:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Atdmt:Cleaned. C:\DocumentsandSettings\Ivan\Cookies\ivan@atdmt[2].txt->TrackingCookie.Atdmt:Cleaned. :mozilla.586:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Bfast:Cleaned. :mozilla.854:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Bfast:Cleaned. :mozilla.458:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Bluemountain:Cleaned. :mozilla.497:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Bluestreak:Cleaned. :mozilla.614:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Bluestreak:Cleaned. :mozilla.567:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Bridgetrack:Cleaned. :mozilla.104:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Burstnet:Cleaned. :mozilla.77:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Burstnet:Cleaned. :mozilla.78:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Burstnet:Cleaned. :mozilla.226:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Casalemedia:Cleaned. :mozilla.227:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Casalemedia:Cleaned. :mozilla.228:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Casalemedia:Cleaned. :mozilla.355:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Casalemedia:Cleaned. :mozilla.356:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Casalemedia:Cleaned. C:\DocumentsandSettings\Ivan\Cookies\ivan@casalemedia[1].txt->TrackingCookie.Casalemedia:Cleaned. :mozilla.729:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Clickzs:Cleaned. :mozilla.730:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Clickzs:Cleaned. :mozilla.785:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Clickzs:Cleaned. :mozilla.786:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Clickzs:Cleaned. :mozilla.155:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Com:Cleaned. :mozilla.344:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Com:Cleaned. :mozilla.345:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Com:Cleaned. :mozilla.80:C:\DocumentsandSettings\Admin\ApplicationData\Mozilla\Firefox\Profiles\li25yagx.default\cookies.txt->TrackingCookie.Com:Cleaned. :mozilla.81:C:\DocumentsandSettings\Admin\ApplicationData\Mozilla\Firefox\Profiles\li25yagx.default\cookies.txt->TrackingCookie.Com:Cleaned. :mozilla.407:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Coremetrics:Cleaned. :mozilla.60:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Doubleclick:Cleaned. :mozilla.626:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Doubleclick:Cleaned. :mozilla.6:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Doubleclick:Cleaned. :mozilla.7:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Doubleclick:Cleaned. :mozilla.7:C:\DocumentsandSettings\John\ApplicationData\Mozilla\Firefox\Profiles\xojl87y3.default\cookies.txt->TrackingCookie.Doubleclick:Cleaned. :mozilla.898:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Doubleclick:Cleaned. :mozilla.8:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Doubleclick:Cleaned. C:\DocumentsandSettings\Ivan\Cookies\ivan@doubleclick[1].txt->TrackingCookie.Doubleclick:Cleaned. C:\DocumentsandSettings\Ivan\Cookies\[removed][1].txt->TrackingCookie.Enhance:Cleaned. :mozilla.812:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Estat:Cleaned. :mozilla.227:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Euroclick:Cleaned. :mozilla.228:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Euroclick:Cleaned. :mozilla.229:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Euroclick:Cleaned. :mozilla.230:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Euroclick:Cleaned. :mozilla.231:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Euroclick:Cleaned. :mozilla.937:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Euroclick:Cleaned. :mozilla.209:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Falkag:Cleaned. :mozilla.79:C:\DocumentsandSettings\Admin\ApplicationData\Mozilla\Firefox\Profiles\li25yagx.default\cookies.txt->TrackingCookie.Falkag:Cleaned. :mozilla.105:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Fastclick:Cleaned. :mozilla.63:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Fastclick:Cleaned. C:\DocumentsandSettings\Ivan\Cookies\ivan@fastclick[2].txt->TrackingCookie.Fastclick:Cleaned. C:\DocumentsandSettings\Ivan\Cookies\[removed][1].txt->TrackingCookie.Fastclick:Cleaned. C:\DocumentsandSettings\Ivan\Cookies\[removed][2].txt->TrackingCookie.Goclick:Cleaned. :mozilla.29:C:\DocumentsandSettings\Admin\ApplicationData\Mozilla\Firefox\Profiles\li25yagx.default\cookies.txt->TrackingCookie.Googleadservices:Cleaned. :mozilla.44:C:\DocumentsandSettings\Admin\ApplicationData\Mozilla\Firefox\Profiles\li25yagx.default\cookies.txt->TrackingCookie.Googleadservices:Cleaned. :mozilla.185:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.186:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.187:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.188:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.189:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.190:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.191:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.192:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.193:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.194:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.195:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.196:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.197:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.198:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.199:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.385:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.386:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.591:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.593:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.594:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.595:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.596:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.597:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.598:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.599:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.600:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.603:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.604:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.605:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.690:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.691:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.833:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.914:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.923:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.924:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.952:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.953:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.964:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.965:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.966:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hitbox:Cleaned. :mozilla.936:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hotlog:Cleaned. :mozilla.955:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Hypertracker:Cleaned. :mozilla.782:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Kmpads:Cleaned. :mozilla.783:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Kmpads:Cleaned. :mozilla.784:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Kmpads:Cleaned. :mozilla.36:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Linksynergy:Cleaned. :mozilla.37:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Linksynergy:Cleaned. :mozilla.553:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Liveperson:Cleaned. :mozilla.555:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Liveperson:Cleaned. :mozilla.556:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Liveperson:Cleaned. :mozilla.575:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Liveperson:Cleaned. :mozilla.576:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Liveperson:Cleaned. :mozilla.577:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Liveperson:Cleaned. :mozilla.819:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Liveperson:Cleaned. :mozilla.820:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Liveperson:Cleaned. :mozilla.821:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Liveperson:Cleaned. :mozilla.574:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Masterstats:Cleaned. :mozilla.652:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Mediaplex:Cleaned. :mozilla.653:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Mediaplex:Cleaned. :mozilla.774:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Mediaplex:Cleaned. :mozilla.117:C:\DocumentsandSettings\Admin\ApplicationData\Mozilla\Firefox\Profiles\li25yagx.default\cookies.txt->TrackingCookie.Myaffiliateprogram:Cleaned. :mozilla.543:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Myaffiliateprogram:Cleaned. :mozilla.171:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Overture:Cleaned. :mozilla.172:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Overture:Cleaned. :mozilla.173:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Overture:Cleaned. :mozilla.452:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Overture:Cleaned. :mozilla.453:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Overture:Cleaned. :mozilla.474:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Overture:Cleaned. :mozilla.485:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Overture:Cleaned. :mozilla.443:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Pointroll:Cleaned. :mozilla.444:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Pointroll:Cleaned. :mozilla.445:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Pointroll:Cleaned. :mozilla.446:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Pointroll:Cleaned. :mozilla.606:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Pointroll:Cleaned. :mozilla.607:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Pointroll:Cleaned. :mozilla.608:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Pointroll:Cleaned. :mozilla.609:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Pointroll:Cleaned. C:\DocumentsandSettings\Ivan\Cookies\[removed][1].txt->TrackingCookie.Pointroll:Cleaned. :mozilla.511:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Qksrv:Cleaned. :mozilla.512:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Qksrv:Cleaned. :mozilla.791:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Qksrv:Cleaned. :mozilla.792:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Qksrv:Cleaned. :mozilla.26:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Questionmarket:Cleaned. :mozilla.27:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Questionmarket:Cleaned. :mozilla.775:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Questionmarket:Cleaned. C:\DocumentsandSettings\Ivan\Cookies\ivan@questionmarket[2].txt->TrackingCookie.Questionmarket:Cleaned. :mozilla.856:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Revenue:Cleaned. :mozilla.870:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Revenue:Cleaned. :mozilla.649:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Ru4:Cleaned. :mozilla.650:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Ru4:Cleaned. :mozilla.722:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Ru4:Cleaned. :mozilla.723:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Ru4:Cleaned. C:\DocumentsandSettings\Ivan\Cookies\ivan@edge.ru4[1].txt->TrackingCookie.Ru4:Cleaned. :mozilla.714:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Serving-sys:Cleaned. :mozilla.715:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Serving-sys:Cleaned. :mozilla.716:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Serving-sys:Cleaned. :mozilla.717:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Serving-sys:Cleaned. :mozilla.718:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Serving-sys:Cleaned. :mozilla.796:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Serving-sys:Cleaned. :mozilla.797:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Serving-sys:Cleaned. :mozilla.798:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Serving-sys:Cleaned. :mozilla.799:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Serving-sys:Cleaned. :mozilla.677:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Specificclick:Cleaned. :mozilla.723:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Specificclick:Cleaned. C:\DocumentsandSettings\Ivan\Cookies\[removed][1].txt->TrackingCookie.Specificclick:Cleaned. :mozilla.855:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Spylog:Cleaned. :mozilla.147:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :mozilla.148:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :mozilla.149:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :mozilla.150:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :mozilla.151:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :mozilla.152:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :mozilla.153:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :mozilla.154:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :mozilla.155:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :mozilla.157:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :mozilla.158:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :mozilla.159:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :mozilla.160:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :mozilla.161:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :mozilla.162:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :mozilla.163:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :mozilla.164:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :mozilla.165:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :mozilla.166:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned. :
Got cut off! Here's the rest:

:mozilla.167:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.168:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.170:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.171:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.173:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.174:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.175:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.176:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.177:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.178:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.20:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.21:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.22:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.23:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.24:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.25:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.26:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.27:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.28:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Statcounter:Cleaned.
:mozilla.29:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Tacoda:Cleaned.
:mozilla.30:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Tacoda:Cleaned.
:mozilla.31:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Tacoda:Cleaned.
:mozilla.62:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Tacoda:Cleaned.
:mozilla.64:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Tacoda:Cleaned.
:mozilla.731:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Targetnet:Cleaned.
:mozilla.701:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Trafficmp:Cleaned.
:mozilla.702:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Trafficmp:Cleaned.
:mozilla.703:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Trafficmp:Cleaned.
:mozilla.866:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Trafficmp:Cleaned.
:mozilla.867:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Trafficmp:Cleaned.
:mozilla.868:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Trafficmp:Cleaned.
C:\DocumentsandSettings\Ivan\Cookies\ivan@trafficmp[1].txt->TrackingCookie.Trafficmp:Cleaned.
:mozilla.108:C:\DocumentsandSettings\Admin\ApplicationData\Mozilla\Firefox\Profiles\li25yagx.default\cookies.txt->TrackingCookie.Tribalfusion:Cleaned.
:mozilla.113:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Tribalfusion:Cleaned.
:mozilla.79:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Tribalfusion:Cleaned.
C:\DocumentsandSettings\Ivan\Cookies\ivan@tribalfusion[1].txt->TrackingCookie.Tribalfusion:Cleaned.
:mozilla.830:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Valuead:Cleaned.
:mozilla.831:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Valuead:Cleaned.
:mozilla.832:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Valuead:Cleaned.
:mozilla.833:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Valuead:Cleaned.
:mozilla.834:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Valuead:Cleaned.
:mozilla.835:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Valuead:Cleaned.
:mozilla.465:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Valueclick:Cleaned.
:mozilla.466:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Valueclick:Cleaned.
:mozilla.467:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Valueclick:Cleaned.
:mozilla.932:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Valueclick:Cleaned.
:mozilla.933:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Valueclick:Cleaned.
C:\DocumentsandSettings\Ivan\Cookies\ivan@valueclick[1].txt->TrackingCookie.Valueclick:Cleaned.
:mozilla.110:C:\DocumentsandSettings\Admin\ApplicationData\Mozilla\Firefox\Profiles\li25yagx.default\cookies.txt->TrackingCookie.Web-stat:Cleaned.
:mozilla.565:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Webtrendslive:Cleaned.
:mozilla.566:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Webtrendslive:Cleaned.
:mozilla.162:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Yieldmanager:Cleaned.
:mozilla.163:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Yieldmanager:Cleaned.
:mozilla.164:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Yieldmanager:Cleaned.
:mozilla.166:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Yieldmanager:Cleaned.
:mozilla.406:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Yieldmanager:Cleaned.
:mozilla.407:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Yieldmanager:Cleaned.
:mozilla.408:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Yieldmanager:Cleaned.
:mozilla.409:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Yieldmanager:Cleaned.
:mozilla.410:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Yieldmanager:Cleaned.
:mozilla.411:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Yieldmanager:Cleaned.
:mozilla.412:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Yieldmanager:Cleaned.
:mozilla.43:C:\DocumentsandSettings\Admin\ApplicationData\Mozilla\Firefox\Profiles\li25yagx.default\cookies.txt->TrackingCookie.Yieldmanager:Cleaned.
:mozilla.933:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Yieldmanager:Cleaned.
:mozilla.934:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Yieldmanager:Cleaned.
C:\DocumentsandSettings\Ivan\Cookies\[removed][1].txt->TrackingCookie.Yieldmanager:Cleaned.
:mozilla.599:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Zedo:Cleaned.
:mozilla.600:C:\DocumentsandSettings\Ivan\ApplicationData\Mozilla\Firefox\Profiles\p2b7i2n9.default\cookies.txt->TrackingCookie.Zedo:Cleaned.
:mozilla.842:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Zedo:Cleaned.
:mozilla.843:C:\DocumentsandSettings\Anya\ApplicationData\Mozilla\Firefox\Profiles\ms2hn98v.default\cookies.txt->TrackingCookie.Zedo:Cleaned.


::Reportend
——————————————————–

Logfile of HijackThis v1.99.1
Scan saved at 7:04:02 AM, on 11/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\VNC4\WinVNC4.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\skypeupd.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Documents and Settings\John\Application Data\Microsoft\Internet Explorer\Quick Launch\TOTALCMD.EXE
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [\\ANTARES\EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P40 "\\ANTARES\EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [Skype updater] skypeupd.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunServices: [Skype updater] skypeupd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O21 - SSODL: Sndeterr - {522B6EBE-6F2F-445C-BA36-002BFF99746C} - C:\WINDOWS\system32\ipvassys.dll
O21 - SSODL: Logofdoc - {DAF4EBA1-8B97-473E-A2FC-38E2CB2ED489} - C:\WINDOWS\system32\bromaman.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\VNC4\WinVNC4.exe" -service (file missing)
torrmundi

Well done, making progress

You have a couple of suspicious files I would like to check

Please upload these files to Jotti's Online Virus Scan

C:\WINDOWS\system32\ipvassys.dll
C:\WINDOWS\system32\bromaman.dllClick "Browse" at the top of the page
- Navigate to C:\WINDOWS\system32\ipvassys.dll
- Click "Open" and let the scan finish
- Copy/paste the results in your next reply. (The results will be posted at the bottom of the Jotti scan page)
Repeat the process for C:\WINDOWS\system32\bromaman.dll

If you are unable to do this from the infected PC let me know, transfering the files to another PC will not produce the required results

thanks bamajim
Bamajim, The files are somehow protected from reading. I had to launch a DOS shell to copy them to a thumbdrive, as Windows wouldn't allow a copy operation. Jotti's scanner couldn't read them where they were. Result for files in c:\windows\system32: ———————————– The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file Result for files copied to a thumbdrive: ———————————– File: bromaman.dll Status: INFECTED/MALWARE MD5 ddb1101c7787273aabe5f9022c9dc254 Packers detected: - Scanner results AntiVir Found Heuristic/Malware (probable variant) ArcaVir Found nothing Avast Found Win32:UrlBot-B AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing VirusBuster Found nothing VBA32 Found Backdoor.xBot.26 (probable variant) File: ipvassys.dll Status: POSSIBLY INFECTED/MALWARE (Note: this file was only flagged as malware by heuristic detection(s). This might be a false positive. Therefore, results of this scan will not be stored in the database) MD5 7d9973355a078cc66a53865e3c8c935e Packers detected: - Scanner results AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing Dr.Web Found BACKDOOR.Trojan (probable variant) F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing VirusBuster Found nothing VBA32 Found Backdoor.xBot.26 (probable variant)
torrmundi

Thank you very much, I thought so
1)Rerun Killbox
2) Select "Delete on Reboot", and then select "All files".
3) Copy the file names below to the clipboard by highlighting them and pressing Control-C:C:\WINDOWS\system32\ipvassys.dll
C:\WINDOWS\system32\bromaman.dll

4) Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
5) Click the red-and-white "Delete File" button.  Click "Yes" at the Delete on Reboot prompt.  Click "No" at the Pending Operations prompt.
Next Rerun Hijackthis (scan only) and place checks beside the following entriesO21 - SSODL: Sndeterr - {522B6EBE-6F2F-445C-BA36-002BFF99746C} - C:\WINDOWS\system32\ipvassys.dll
O21 - SSODL: Logofdoc - {DAF4EBA1-8B97-473E-A2FC-38E2CB2ED489} - C:\WINDOWS\system32\bromaman.dll

Close all ther open windows except Hijackthis and Select "Fix checked"

Close Hijackthis->>Reboot your PC->>Rerun Hijackthis and post a fresh log

thanks bamajim
Bamajim,

After doing tasks you outlined, I was able to run IE and browse with reasonable speed for the first time. I had AVG performing updates, as well. Then I ran Firefox and immediately the AVG update failed to connect, Firefox would not browse, and IE would not browse.

As a simple test, I also tried copying all the files in …\system32 over to a thumbdrive. None failed to copy.

I rebooted and tried IE and Firefox again. Both worked ok for about 3-4 minutes, then both stopped browsing. However IE's initial connection to www.emachines.com took about 30-40 seconds, unusually long for an otherwise unoccupied machine with a mostly unused cable connection.

Windows Firewall: off
Norton: off
AVG: inactive
Firewalled NAT router: enabled

Thanks,
/torrmundi

Logfile of HijackThis v1.99.1
Scan saved at 8:55:03 PM, on 11/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\VNC4\WinVNC4.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\skypeupd.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Documents and Settings\John\Application Data\Microsoft\Internet Explorer\Quick Launch\TOTALCMD.EXE
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [\\ANTARES\EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P40 "\\ANTARES\EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [Skype updater] skypeupd.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunServices: [Skype updater] skypeupd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\VNC4\WinVNC4.exe" -service (file missing)
torrmundi

Download RIGHT-CLICK HERE and Save As (in IE it's "Save Target As") to download Silent Runners.
  • Save it to the desktop.
  • Run Silent Runner's by doubleclicking the "Silent Runners" icon on your desktop.
  • You will see a text file appear on the desktop - it's not done, let it run (it won't appear to be doing anything!)
  • Once you receive the prompt "All Done!", double-click the new text file on the desktop, copy that entire log, and paste it here.
*NOTE* If you receive any warning message about scripts, please choose to allow the script to run.

thanks bamajim
Bamajim,

Nothing happened when I double-clicked. I looked at the running processes and saw wscript.exe in the list, but having 0% cpu time. I rebooted and tried again, but with the test mode enabled in the script file. The Testing dialog showed up, then disappeared without me clicking OK. So I used MSCONFIG to disable all Services for Symantec, including scriptblocker, as well as AVG. I rebooted, tried again, same result. Finally, a dialog for Norton AV came up warning me about the script. I allowed it to continue and it produced a text file that was essentially empty.

Spent some time removing NAV (hate that program!). Then I had to install Windows Scripting. Finally, it ran ok.

"Silent Runners.vbs", revision 49, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
———————————

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"\\ANTARES\EPSON Stylus Photo R200 Series" = "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P40 "\\ANTARES\EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"" ["SEIKO EPSON CORPORATION"]
"VTTrayp" = "VTtrayp.exe" ["S3 Graphics Co., Ltd."]
"VTTimer" = "VTTimer.exe" ["S3 Graphics, Inc."]
"Symantec NetDriver Monitor" = "C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer" [file not found]
"SunKistEM" = "C:\Program Files\Digital Media Reader\shwiconem.exe" ["Alcor Micro, Corp."]
"SunJavaUpdateSched" = "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" ["Sun Microsystems, Inc."]
"SoundMan" = "SOUNDMAN.EXE" ["Realtek Semiconductor Corp."]
"RemoteControl" = ""C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"" ["Cyberlink Corp."]
"Reminder" = "%WINDIR%\Creator\Remind_XP.exe" ["SoftThinks"]
"Recguard" = "%WINDIR%\SMINST\RECGUARD.EXE" [empty string]
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
"iTunesHelper" = ""C:\Program Files\iTunes\iTunesHelper.exe"" ["Apple Computer, Inc."]
"ccApp" = ""C:\Program Files\Common Files\Symantec Shared\ccApp.exe"" [file not found]
"!AVG Anti-Spyware" = ""C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized" ["Anti-Malware Development a.s."]
"Skype updater" = "skypeupd.exe" [null data]
"TkBellExe" = ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot" ["RealNetworks, Inc."]
"C2K" = "C:\WINDOWS\Cyb2k.exe" [file not found]

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\ {++}
"Regsister WScript" = "wscript -regserver" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
-> {HKLM…CLSID} = "AcroIEHlprObj Class"
\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
-> {HKLM…CLSID} = "SSVHelper Class"
\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll" ["Sun Microsystems, Inc."]
{AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
-> {HKLM…CLSID} = "Google Toolbar Helper"
\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {HKLM…CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
"{7F67036B-66F1-411A-AD85-759FB9C5B0DB}" = "SampleView"
-> {HKLM…CLSID} = "SampleView"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ShellvRTF.dll" ["XSS"]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM…CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
"{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" = "OpenOffice.org Column Handler"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]
"{087B3AE3-E237-4467-B8DB-5A38AB959AC9}" = "OpenOffice.org Infotip Handler"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]
"{63542C48-9552-494A-84F7-73AA6A7C99C1}" = "OpenOffice.org Property Sheet Handler"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]
"{3B092F0C-7696-40E3-A80F-68D74DA84210}" = "OpenOffice.org Thumbnail Viewer"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes"
-> {HKLM…CLSID} = "iTunes"
\InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPlayer.dll" ["Apple Computer, Inc."]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {HKLM…CLSID} = "RealOne Player Context Menu Class"
\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
<> "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "AVG Anti-Spyware 7.5"
-> {HKLM…CLSID} = "CShellExecuteHookImpl Object"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" ["Anti-Malware Development a.s."]

HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
"WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
-> {HKLM…CLSID} = "WPDShServiceObj Class"
\InProcServer32\(Default) = "C:\WINDOWS\system32\WPDShServiceObj.dll" [MS]

HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\(Default) = "OpenOffice.org Column Handler"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
-> {HKLM…CLSID} = "PDF Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
-> {HKLM…CLSID} = "CContextScan Object"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."]
UltraEdit-32\(Default) = "{b5eedee0-c06e-11cf-8c56-444553540000}"
-> {HKLM…CLSID} = "UltraEdit-32"
\InProcServer32\(Default) = "C:\PROGRA~1\ULTRAE~1\ue32ctmn.dll" [empty string]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM…CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
-> {HKLM…CLSID} = "CContextScan Object"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM…CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM…CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


Group Policies {policy setting}:
——————————–

Note: detected settings may not have any effect.

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\

"DisableRegistryTools" = (REG_DWORD) hex:0x00000000
{Prevent access to registry editing tools}

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
—————————–

Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\WINDOWS\web\wallpaper\emachines.bmp"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "c:\windows\web\wallpaper\emachines.bmp"


Enabled Screen Saver:
———————

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\system32\logon.scr" [MS]


Startup items in "John" & "All Users" startup folders:
——————————————————

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"Adobe Reader Speed Launch" -> shortcut to: "C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"]
"BigFix" -> shortcut to: "C:\Program Files\BigFix\BigFix.exe /atstartup" ["BigFix Inc."]
"OpenOffice.org 2.0" -> shortcut to: "C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe" [null data]


Enabled Scheduled Tasks:
————————

"Norton AntiVirus - Scan my computer - Owner" -> launches: "C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe /task:"C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Tasks\mycomp.sca"" [file not found]


Winsock2 Service Provider DLLs:
——————————-

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
C:\WINDOWS\system32\lspcs.dll ["Solid Oak"], 01 - 05, 17
%SystemRoot%\system32\mswsock.dll [MS], 06 - 08, 11 - 16
%SystemRoot%\system32\rsvpsp.dll [MS], 09 - 10


Toolbars, Explorer Bars, Extensions:
————————————

Toolbars

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
-> {HKLM…CLSID} = "&Google"
\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)
-> {HKLM…CLSID} = "&Google"
\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

Explorer Bars

HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\
{FE54FA40-D68C-11D2-98FA-00C0F0318AFE}\(Default) = (no title provided)
-> {HKLM…CLSID} = "Real.com"
\InProcServer32\(Default) = "C:\WINDOWS\system32\Shdocvw.dll" [MS]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}"
-> {HKCU…CLSID} = "Java Plug-in"
\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll" ["Sun Microsystems, Inc."]
-> {HKLM…CLSID} = "Java Plug-in 1.5.0_06"
\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll" ["Sun Microsystems, Inc."]

{CD67F990-D8E9-11D2-98FE-00C0F0318AFE}\
"ButtonText" = "Real.com"

{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]


Miscellaneous IE Hijack Points
——————————

C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

Added lines (compared with English-language version):
[Strings]: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

Missing lines (compared with English-language version):
[Strings]: 1 line


Running Services (Display Name, Service Name, Path {Service DLL}):
——————————————————————

AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe" ["Anti-Malware Development a.s."]
HTTP SSL, HTTPFilter, "C:\WINDOWS\System32\svchost.exe -k HTTPFilter" {"C:\WINDOWS\System32\w3ssl.dll" [MS]}
iPodService, iPodService, "C:\Program Files\iPod\bin\iPodService.exe" ["Apple Computer, Inc."]
PrismXL, PrismXL, "C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS" ["New Boundary Technologies, Inc."]
VNC Server Version 4, WinVNC4, ""C:\Program Files\VNC4\WinVNC4.exe" -service" ["RealVNC Ltd."]


———-
<>: Suspicious data at a malware launch point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points, use the -supp parameter or answer "No" at the
first message box and "Yes" at the second message box.
———- (total run time: 38 seconds, including 10 seconds for message boxes)
torrmundi

Don't see anything there that would interfere with browsing. I'm not a Norton fan either

Here's a link for Norton removal tool

http://service1.symantec.com/SUPPORT/tsgen…005033108162039

See if that helps, if you still are having a browsing problem please reply

thanks bamajim

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI