This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

pc running slow

42 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

can someone help me? my pc is running very slow, I have tried all spyware,ad- adware, and uitily clean-up progames. i have notist the slow down right after someone downloaded a mp3 file from one of those p2p network and my anti viruses and firewall were down. here is my hijackthis log



Logfile of HijackThis v1.99.1
Scan saved at 3:56:01 PM, on 1/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Ernie\My Documents\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?rs=1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?rs=1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1151356478299
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winsfg32 - C:\WINDOWS\SYSTEM32\winsfg32.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Hi dirtyyankand welcome to Tom Coyote forums

I am currently looking over your log. As I am an Undergraduate, everything that I post to you must be checked by an Admin or Moderator. Thus, there may be a tiny bit of a delay between posts, but it shouldn't be too long. I will post back shortly with a potential fix.

Thanks for your patience!

dan
Hi dirtyyank


You don't appear to be running an antivirus program

Before we go any further lets secure your computer to avoid any further risk of infection

There are many antivirus products out there
and at first
with there being so many different products it may look confusuing to you
some are free products and others are fully licienced products. It is up to you which you go for. For free antivirus product I would be looking at either Avast Home edition or AVG Free edition AntiVir Personal Edition
If you are going to be looking at fully licienced software then I would seriously consider either Nod32 or kaspersky Antivirus products
AVG Anti-Malware
all are excellent in their job of keeping viruses at bay.

_______________________

You may have the latest version of VX2. Download L2mfix from one of these two locations:

http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

Thanks dan
Thanks for looking at my log and helping me get started on fixing my slow a$$ pc, but i'm already runing a anti-virus ,anti-spyware and firewall program ZONE ALARM SECURITY

Logfile of HijackThis v1.99.1
Scan saved at 3:56:01 PM, on 1/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Ernie\My Documents\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?rs=1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?rs=1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1151356478299
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winsfg32 - C:\WINDOWS\SYSTEM32\winsfg32.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Hi dirtyyank
All your highlighted entries are refferance to your zone alarm firewall.
I'm not seeing an antivirus program running!
Is this the program you have Here
Can you check that your AntiVirus shows as running!
You may be able to right click the icon and get a ZA control center, or check that the Start, Control Panel, Security Center shows AntiVirus and Firewall both running.
Thanks dan
the anti virus is working. it was doing a virus scan as i was typing this ,(had to stop scaning for a min. pc don't multi tack very well)
here is the log from l2mfix L2MFIX find log 051206 These are the registry keys present ********************************************************************************** Winlogon/notify: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] "DLLName"="wlnotify.dll" "Logon"="SCardStartCertProp" "Logoff"="SCardStopCertProp" "Lock"="SCardSuspendCertProp" "Unlock"="SCardResumeCertProp" "Enabled"=dword:00000001 "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "StartShell"="SchedStartShell" "Logoff"="SchedEventLogOff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] "Logoff"="WLEventLogoff" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] "DLLName"="WlNotify.dll" "Lock"="SensLockEvent" "Logon"="SensLogonEvent" "Logoff"="SensLogoffEvent" "Safe"=dword:00000001 "MaxWait"=dword:00000258 "StartScreenSaver"="SensStartScreenSaverEvent" "StopScreenSaver"="SensStopScreenSaverEvent" "Startup"="SensStartupEvent" "Shutdown"="SensShutdownEvent" "StartShell"="SensStartShellEvent" "PostShell"="SensPostShellEvent" "Disconnect"="SensDisconnectEvent" "Reconnect"="SensReconnectEvent" "Unlock"="SensUnlockEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "Logoff"="TSEventLogoff" "Logon"="TSEventLogon" "PostShell"="TSEventPostShell" "Shutdown"="TSEventShutdown" "StartShell"="TSEventStartShell" "Startup"="TSEventStartup" "MaxWait"=dword:00000258 "Reconnect"="TSEventReconnect" "Disconnect"="TSEventDisconnect" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] "Logon"="WLEventLogon" "Logoff"="WLEventLogoff" "Startup"="WLEventStartup" "Shutdown"="WLEventShutdown" "StartScreenSaver"="WLEventStartScreenSaver" "StopScreenSaver"="WLEventStopScreenSaver" "Lock"="WLEventLock" "Unlock"="WLEventUnlock" "StartShell"="WLEventStartShell" "PostShell"="WLEventPostShell" "Disconnect"="WLEventDisconnect" "Reconnect"="WLEventReconnect" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000000 "SafeMode"=dword:00000001 "MaxWait"=dword:ffffffff "DllName"=hex(2):57,00,67,00,61,00,4c,00,6f,00,67,00,6f,00,6e,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Event"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings] "Data"=hex:01,00,00,00,d0,8c,9d,df,01,15,d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,\ 00,00,fe,87,ec,83,8a,01,95,4b,b5,7a,86,58,2a,ae,2e,5e,04,00,00,00,04,00,00,\ 00,53,00,00,00,03,66,00,00,a8,00,00,00,10,00,00,00,67,c7,3b,a4,eb,c7,c8,ad,\ 2e,89,aa,1c,7b,7d,01,2f,00,00,00,00,04,80,00,00,a0,00,00,00,10,00,00,00,8f,\ 64,33,61,4f,a0,13,76,50,0d,80,c8,52,4b,93,1f,08,06,00,00,cd,15,a4,d9,4d,72,\ 60,1e,3a,03,11,90,1e,cd,79,76,4e,02,f5,56,a2,40,64,7b,6f,81,81,20,b4,10,9b,\ 72,c5,4c,79,d2,07,54,f2,6f,da,36,a5,ea,8b,25,9e,ea,29,dd,25,38,a6,87,e2,d9,\ 71,49,b1,49,23,bc,24,ce,8f,a1,71,bb,39,a3,63,7a,4c,6e,ee,dd,4e,da,3d,ae,51,\ 5d,f5,22,60,55,00,39,76,4c,ea,96,88,65,96,b7,aa,8d,e7,4f,7e,c4,fe,bc,59,e3,\ a0,89,ef,6d,a6,4e,40,3f,7b,50,8c,62,83,0b,44,56,3d,1a,81,4b,55,da,35,40,a9,\ 64,18,fa,64,fc,22,06,44,d0,02,b5,de,f1,8d,f7,5b,8a,10,9c,16,d3,83,b5,bc,d9,\ d2,ec,f0,f8,b0,98,f9,21,17,69,62,99,26,5d,fc,f6,dd,c2,a5,ac,fb,14,74,ba,be,\ a5,9d,4c,01,16,76,e4,ff,b6,00,47,68,56,61,a3,93,74,75,30,a1,c1,c3,28,e1,b3,\ 44,33,84,74,07,ef,0d,b1,eb,75,cc,2a,35,90,61,dd,bf,f3,28,76,22,4e,76,3a,d1,\ 53,29,9a,9e,6b,2f,02,52,a8,2c,7b,13,6a,b0,55,31,99,94,80,c5,2e,fa,fb,71,de,\ 64,de,cc,8d,88,48,e0,48,ac,59,01,06,e1,9b,27,fb,ed,01,0b,41,d7,b1,24,78,a4,\ 10,56,bd,2d,72,1f,0f,c3,ac,82,0b,1d,a4,c7,8e,a6,33,c0,3a,d1,25,cf,86,c4,7d,\ 80,c6,31,18,de,6c,ae,ca,a1,0f,3a,94,dd,40,4d,d6,37,d5,20,3b,5f,c9,f6,0d,8d,\ 41,02,b0,6c,a5,87,ac,9c,b9,06,72,07,5f,74,95,8c,9f,53,b1,d4,b0,d7,3a,d5,c7,\ fc,05,45,9f,b0,38,d7,b6,4f,46,d2,cf,44,c3,96,cc,ad,f6,f8,6d,4a,52,f0,50,59,\ f8,02,d7,cd,9b,be,5f,ff,ba,80,a9,05,3a,11,9f,e5,ce,ab,b4,85,10,de,7d,d2,e2,\ a3,8e,da,fc,78,d7,74,07,c0,0c,90,9a,b9,b2,a2,67,6a,11,4e,6b,f3,64,4d,bb,e2,\ 92,32,cd,6e,9d,15,12,bb,28,1f,3e,65,bd,25,34,7f,90,33,2e,2e,39,be,71,4d,ca,\ 63,00,9e,4f,6c,1f,0a,8e,24,81,03,5e,1e,d1,47,33,98,71,29,f7,a5,38,66,de,78,\ 69,b4,6d,fa,54,f8,44,35,b5,cf,92,08,ba,d4,0e,6a,be,cb,d8,bb,8b,64,06,55,5e,\ 2e,c5,e0,60,48,13,6b,b5,bc,5f,cd,b3,9e,ca,1b,c8,fb,a1,05,14,8d,2f,50,83,13,\ e3,54,ec,e8,f1,2c,b3,0e,96,a5,96,0f,21,4b,ca,32,30,d0,ef,4f,43,d5,18,9a,ca,\ b1,96,25,2c,29,9c,82,02,f8,1f,82,52,12,36,7a,f7,5b,f4,39,10,20,06,af,93,bb,\ 56,78,ea,6f,a3,21,70,85,87,a0,a7,1f,e0,69,cf,fb,1b,38,3a,3f,a1,f9,00,fd,ce,\ b3,c2,0f,10,00,d4,7b,bc,e8,ce,53,22,8d,cb,23,4b,34,a7,a2,72,b9,bf,9c,57,12,\ b2,c9,4f,e8,57,99,76,04,22,6d,71,81,80,1f,38,a4,6f,d3,ff,19,d9,c3,61,58,4f,\ 6a,3f,5c,73,dc,59,d5,51,ae,a2,b2,5d,bc,be,0b,72,78,85,1b,b3,ce,f0,67,6e,26,\ bf,07,9c,ac,a1,e3,59,30,57,3c,98,e3,e0,2a,3c,e8,93,d7,b2,d2,cf,53,b2,90,cf,\ 4c,bd,b7,e5,88,02,80,08,d8,97,c7,67,bd,3b,4b,07,d8,49,70,31,c5,bd,43,16,d2,\ 03,6d,03,ce,fb,12,1d,a9,40,76,3f,ed,12,35,bd,30,8f,dd,db,7c,d0,e9,a2,be,8a,\ bd,cb,a9,a1,49,2e,dd,0d,a8,72,90,69,0c,b4,7b,c3,8c,b1,32,b0,73,c6,50,85,b4,\ 21,0f,ae,82,94,16,e4,45,e2,89,48,d3,60,55,21,15,d1,04,47,e2,48,97,60,e6,57,\ 5b,8e,77,a1,86,bc,ad,33,54,57,45,6e,26,0b,40,75,a2,b2,eb,d2,70,b0,4d,40,64,\ bb,7b,18,9b,bd,18,44,4a,c6,cf,c6,5e,d1,1a,8d,98,18,4d,10,10,89,ae,81,47,0e,\ c8,0d,23,29,39,3b,c3,02,ed,f0,6f,f8,64,08,13,38,44,18,12,c2,ba,71,c8,ee,ea,\ 97,91,89,93,22,57,a0,60,39,04,2c,c9,16,e1,b5,0d,ab,b1,5c,a8,07,1b,3b,65,6a,\ 06,95,74,5d,3b,00,b7,44,fb,6b,7f,bc,d2,f5,61,ef,20,c2,25,7c,4d,e7,21,a3,5a,\ 2a,9c,7f,27,52,b4,d0,ca,d1,bc,b8,b3,86,b2,2b,a6,20,48,e3,c7,82,f2,6d,c4,fa,\ ce,84,f9,6d,6e,2f,d1,d4,91,fe,27,d0,1b,ff,d8,5b,62,75,4c,85,c7,a8,ad,a9,12,\ 49,35,0b,ae,9a,84,0e,e5,81,5f,88,e8,15,80,53,46,7a,9a,67,73,08,ae,c9,6b,27,\ b4,33,04,17,ba,cb,81,c1,e9,c1,8a,14,7c,c9,90,2a,22,b3,f6,bf,e7,b5,70,b1,30,\ 05,ab,99,fd,fe,48,61,2c,84,17,f0,8c,ee,a3,cc,67,5c,ee,bd,9a,08,e4,35,9c,a4,\ 0c,82,c4,88,a3,95,73,d8,31,e8,cc,4d,42,af,80,3f,07,39,86,26,03,95,3e,d4,69,\ 6c,94,2a,62,07,47,30,aa,53,3b,e1,76,3e,51,d8,91,c9,7a,7c,09,08,80,a5,01,e1,\ c1,a2,77,3d,50,88,e0,b2,e2,cb,97,3f,10,34,4c,79,1e,2f,df,f6,ab,9d,9e,38,e4,\ d4,99,ab,df,cd,0f,f1,db,0c,3d,f9,0d,fe,a3,d8,d0,39,d7,09,cb,4c,96,7a,16,97,\ 8b,6b,18,eb,76,03,6e,a2,2d,d9,03,fa,34,12,29,9a,40,ee,8f,0f,4a,6f,ba,e0,28,\ a2,01,04,1e,78,a7,01,e1,77,cc,c3,5f,be,49,20,7c,3d,ff,a0,ed,42,fb,19,9c,46,\ 45,79,d9,6e,f9,f8,4c,6d,82,57,a3,7c,94,35,2c,ce,a8,a1,cb,1e,c9,60,b9,aa,8b,\ 1b,49,dd,51,07,81,93,2e,79,a4,d1,ca,ed,7e,d7,df,61,16,a5,71,99,2a,1d,ba,92,\ f8,85,e7,f6,c4,34,3e,da,1c,76,0e,5c,22,78,bf,09,f9,0b,5a,63,a6,01,7b,00,bf,\ 22,e7,24,82,0e,ed,c9,a4,36,9e,c0,75,38,3f,91,6d,cb,ee,27,23,24,5e,5c,6c,1b,\ 6f,31,74,2a,f1,ed,d3,39,bf,8f,da,88,12,38,6c,48,ec,b0,ff,9c,f2,7c,b9,8a,b1,\ d5,e7,f2,a6,f5,f0,cf,55,89,65,18,ac,0f,ed,da,92,e2,96,03,4f,ba,e5,bc,10,59,\ 90,87,2a,bb,5c,32,87,3f,2b,1b,2f,51,ab,5c,8d,e9,d7,e0,4b,44,32,a4,9d,2a,b4,\ 79,01,78,50,f6,29,05,50,1d,ad,0f,46,a0,bd,b0,79,fe,d6,f3,69,ca,40,c7,7e,81,\ af,ea,eb,bf,d5,45,68,3f,c9,f4,eb,74,71,92,99,5f,a4,d7,c4,50,a4,0a,43,2f,15,\ 80,41,34,4b,e1,98,22,d0,f1,1b,36,b8,5e,0d,c8,e8,2c,0c,1b,79,d0,0c,a0,2b,03,\ 19,69,1c,5f,56,18,f5,0a,4c,33,c9,17,c6,64,96,0c,e5,01,8c,bc,65,e6,70,31,97,\ 09,ab,17,72,77,4c,fb,79,4f,ff,75,5f,12,d7,32,24,e9,f6,e2,d8,c3,aa,a6,b0,58,\ fc,5f,5f,b8,07,d2,ab,6a,10,17,ef,76,4f,bc,02,d1,48,b8,27,f4,d3,7b,f9,95,71,\ 6f,bc,a3,cb,cf,d5,05,f2,71,a5,b2,a7,36,14,00,00,00,4c,2b,3b,30,4b,99,74,bf,\ 16,8b,72,9c,18,8c,23,72,ac,70,cf,d0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winsfg32] "Asynchronous"=dword:00000001 "DllName"="winsfg32.dll" "Impersonate"=dword:00000000 "Startup"="EvtStartup" "Shutdown"="EvtShutdown" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] "DLLName"="wlnotify.dll" "Logon"="RegisterTicketExpiredNotificationEvent" "Logoff"="UnregisterTicketExpiredNotificationEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 ********************************************************************************** useragent: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] ********************************************************************************** Shell Extension key: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved] "{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet" "{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management" "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page" "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page" "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing" "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension" "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension" "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension" "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension" "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page" "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page" "{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler" "{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension" "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects" "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management" "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management" "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression" "{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension" "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI" "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu" "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase" "{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext" "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts" "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile" "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page" "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing" "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension" "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension" "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension" "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections" "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections" "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras" "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras" "{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras" "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras" "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras" "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension" "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension" "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host" "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link" "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler" "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension" "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks" "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu" "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search" "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support" "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support" "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run…" "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet" "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail" "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts" "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools" "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler" "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler" "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler" "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler" "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler" "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor" "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar" "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status" "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder" "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2" "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy" "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand" "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="IE Search Band" "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band" "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search" "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search" "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility" "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address" "{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox" "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete" "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor" "{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List" "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List" "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible" "{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar" "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser" "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List" "{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List" "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container" "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu" "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp" "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar" "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite" "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist" "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings" "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band" "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service" "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer" "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture" "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut" "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service" "{FF393560-C2A7-11CF-BFF4-444553540000}"="History" "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files" "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files" "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook" "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen" "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook" "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC" "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC" "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet" "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space" "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band" "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service" "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service" "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder" "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck" "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr" "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder" "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler" "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent" "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent" "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent" "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent" "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent" "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler" "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager" "{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator" "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher" "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs" "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory" "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor" "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)" "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor" "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler" "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard" "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web" "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object" "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard" "{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts" "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler" "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target" "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview" "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext" "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control" "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control" "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control" "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control" "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control" "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI" "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object" "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find" "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find" "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI" "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs" "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook" "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target" "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties" "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu" "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options" "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder" "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler" "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell" "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%" "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler" "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer" "{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People…" "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Burn Audio CD Context Menu Handler" "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Play as Playlist Context Menu Handler" "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler" "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults" "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page" "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions" "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder" "{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band" "{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache" "{e82a2d71-5b2f-43a0-97b8-81be15854de8}"="ShellLink for Application References" "{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}"="Shell Icon Handler for Application References" "{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders" "{00020D75-0000-0000-C000-000000000046}"="Microsoft Office Outlook Desktop Icon Handler" "{0006F045-0000-0000-C000-000000000046}"="Microsoft Office Outlook Custom Icon Handler" "{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler" "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"="AVG7 Shell Extension" "{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}"="AVG7 Find Extension" "{07C45BB1-4A8C-4642-A1F5-237E7215FF66}"="IE Microsoft BrowserBand" "{1C1EDB47-CE22-4bbb-B608-77B48F83C823}"="IE Fade Task" "{205D7A97-F16D-4691-86EF-F3075DCCA57D}"="IE Menu Desk Bar" "{3028902F-6374-48b2-8DC6-9725E775B926}"="IE AutoComplete" "{43886CD5-6529-41c4-A707-7B3C92C05E68}"="IE Navigation Bar" "{44C76ECD-F7FA-411c-9929-1B77BA77F524}"="IE Menu Site" "{4B78D326-D922-44f9-AF2A-07805C2A3560}"="IE Menu Band" "{6038EF75-ABFC-4e59-AB6F-12D397F6568D}"="IE Microsoft History AutoComplete List" "{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE}"="IE Tracking Shell Menu" "{6CF48EF8-44CD-45d2-8832-A16EA016311B}"="IE IShellFolderBand" "{73CFD649-CD48-4fd8-A272-2070EA56526B}"="IE BandProxy" "{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8}"="IE MRU AutoComplete List" "{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E}"="IE RSS Feeder Folder" "{9D958C62-3954-4b44-8FAB-C4670C1DB4C2}"="IE Microsoft Shell Folder AutoComplete List" "{B31C5FAE-961F-415b-BAF0-E697A5178B94}"="IE Microsoft Multiple AutoComplete List Container" "{BC476F4C-D9D7-4100-8D4E-E043F6DEC409}"="Microsoft Browser Architecture" "{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}"="IE Shell Rebar BandSite" "{E6EE9AAC-F76B-4947-8260-A9F136138E11}"="IE Shell Band Site Menu" "{F2CF5485-4E02-4f68-819C-B92DE9277049}"="&Links" "{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E}"="IE Registry Tree Options Utility" "{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}"="IE User Assist" "{FDE7673D-2E19-4145-8376-BBD58C4BC7BA}"="IE Custom MRU AutoCompleted List" "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices" "{35786D3C-B075-49b9-88DD-029876E11C01}"="Portable Devices" "{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8}"="Portable Devices Menu" "{D9872D13-7651-4471-9EEE-F0A00218BEBB}"="Multiscan" "{3DE5DB7C-0EA5-4337-8A5C-D0AC6D154C1B}"="SFS_CONTEXT" ********************************************************************************** HKEY ROOT CLASSIDS: ********************************************************************************** Files Found are not all bad files: C:\WINDOWS\SYSTEM32\ admparse.dll Tue Nov 7 2006 3:26:44a A…. 71,680 70.00 K advpack.dll Tue Nov 7 2006 3:26:24a A…. 123,904 121.00 K extmgr.dll Tue Nov 7 2006 9:03:36p A…. 131,584 128.50 K ieakeng.dll Tue Nov 7 2006 3:26:56a A…. 152,064 148.50 K ieaksie.dll Tue Nov 7 2006 3:27:02a A…. 229,376 224.00 K ieakui.dll Tue Nov 7 2006 3:25:14a A…. 161,792 158.00 K iedkcs32.dll Tue Nov 7 2006 3:27:10a A…. 382,976 374.00 K ieframe.dll Tue Nov 7 2006 9:03:36p ….. 6,049,280 5.77 M iepeers.dll Tue Nov 7 2006 9:03:36p A…. 191,488 187.00 K iernonce.dll Tue Nov 7 2006 3:26:28a A…. 43,008 42.00 K iesetup.dll Tue Nov 7 2006 3:26:42a A…. 55,296 54.00 K ieui.dll Tue Nov 7 2006 9:03:36p ….. 180,736 176.50 K incine~1.dll Wed Dec 20 2006 5:48:02p A…. 1,212,416 1.16 M inetcomm.dll Wed Nov 8 2006 12:06:14a A…. 679,424 663.50 K inseng.dll Tue Nov 7 2006 3:26:24a A…. 92,672 90.50 K jsproxy.dll Tue Nov 7 2006 9:03:36p A…. 27,136 26.50 K msfeeds.dll Tue Nov 7 2006 9:03:36p ….. 458,752 448.00 K msfeed~1.dll Tue Nov 7 2006 9:03:36p ….. 50,688 49.50 K mshtml.dll Tue Nov 7 2006 9:03:36p A…. 3,577,856 3.41 M mshtmled.dll Tue Nov 7 2006 9:03:36p A…. 475,648 464.50 K msls31.dll Tue Nov 7 2006 9:03:36p A…. 156,160 152.50 K mstime.dll Tue Nov 7 2006 9:03:36p A…. 670,720 655.00 K urlmon.dll Tue Nov 7 2006 9:03:36p A…. 1,162,240 1.11 M vbscript.dll Tue Nov 7 2006 9:03:36p A…. 413,696 404.00 K vete.dll Thu Jan 18 2007 12:36:58p A…. 1,021,504 997.56 K webcheck.dll Tue Nov 7 2006 9:03:36p A…. 231,424 226.00 K wininet.dll Tue Nov 7 2006 9:03:36p A…. 818,688 799.50 K winsfg32.dll Thu Jan 18 2007 10:43:08a ….. 18,432 18.00 K 28 items found: 28 files, 0 directories. Total of file sizes: 18,840,640 bytes 17.96 M Locate .tmp files: No matches found. ********************************************************************************** Directory Listing of system files: Volume in drive C has no label. Volume Serial Number is 54DD-1AA9 Directory of C:\WINDOWS\System32 01/29/2007 11:27 AM dllcache 06/26/2006 04:10 PM Microsoft 0 File(s) 0 bytes 2 Dir(s) 13,954,965,504 bytes free
Hi dirtyyank

Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new Hijackthis log.

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!

Note : Once the PC has restarted if a log does not appear or the icons didn't disappear, run the "second.bat" located inside the L2mfix folder.

Please include L2me log and a new HJT log
in your next post
Thanks dan
L2mfix 032106
Creating Account.
The command completed successfully.

Adding Administrative privleges.
The command completed successfully.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX … successful

Running From:
C:\WINDOWS\system32

Killing Processes!

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 648 'smss.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'
Killing PID 1292 'winlogon.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 1520 'explorer.exe'
Killing PID 1520 'explorer.exe'
Killing PID 1520 'explorer.exe'
Killing PID 1520 'explorer.exe'
Killing PID 1520 'explorer.exe'
Killing PID 1520 'explorer.exe'
Killing PID 1520 'explorer.exe'
Killing PID 1520 'explorer.exe'
Killing PID 1520 'explorer.exe'
Killing PID 1520 'explorer.exe'
Killing PID 1520 'explorer.exe'
Killing PID 1520 'explorer.exe'
Killing PID 1520 'explorer.exe'
Killing PID 1520 'explorer.exe'
Killing PID 1520 'explorer.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Error, Cannot find a process with an image name of rundll32.exe
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators … successful

Scanning First Pass. Please Wait!

First Pass Completed

Second Pass Scanning

Second pass Completed!



Restoring Windows Update Certificates.:

The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
"Logon"="WLEventLogon"
"Logoff"="WLEventLogoff"
"Startup"="WLEventStartup"
"Shutdown"="WLEventShutdown"
"StartScreenSaver"="WLEventStartScreenSaver"
"StopScreenSaver"="WLEventStopScreenSaver"
"Lock"="WLEventLock"
"Unlock"="WLEventUnlock"
"StartShell"="WLEventStartShell"
"PostShell"="WLEventPostShell"
"Disconnect"="WLEventDisconnect"
"Reconnect"="WLEventReconnect"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000000
"SafeMode"=dword:00000001
"MaxWait"=dword:ffffffff
"DllName"=hex(2):57,00,67,00,61,00,4c,00,6f,00,67,00,6f,00,6e,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Event"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings]
"Data"=hex:01,00,00,00,d0,8c,9d,df,01,15,d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,\
00,00,fe,87,ec,83,8a,01,95,4b,b5,7a,86,58,2a,ae,2e,5e,04,00,00,00,04,00,00,\
00,53,00,00,00,03,66,00,00,a8,00,00,00,10,00,00,00,82,2b,b3,c0,32,dc,6a,5f,\
66,9a,a5,77,91,5b,87,7b,00,00,00,00,04,80,00,00,a0,00,00,00,10,00,00,00,b9,\
0f,48,cc,40,53,55,52,6a,b8,55,8f,2f,6a,66,33,08,06,00,00,7b,fe,0d,9f,38,26,\
72,6d,fa,91,93,3e,78,d5,51,87,88,1f,0b,cb,6e,1d,d7,f1,e4,d6,17,0c,84,3d,ba,\
4b,2f,4c,aa,a6,7f,0b,27,6c,74,6c,eb,7a,7e,60,fe,56,f9,73,62,d1,b7,af,2a,de,\
46,cd,2a,45,a6,50,3b,71,29,c1,61,7c,ff,31,68,3c,6a,f0,c2,c9,06,3c,0e,36,23,\
82,bc,da,0b,0c,b8,5d,d8,29,65,61,fd,ca,b5,eb,a3,23,99,17,24,56,85,c0,4a,4b,\
b7,06,36,e6,ef,d3,8f,75,b6,82,6a,f1,10,f0,70,6f,f4,6c,13,da,8d,53,b4,0e,d1,\
f1,2b,0b,9e,19,e2,28,49,66,64,1a,33,bf,0e,36,71,04,c9,d2,ac,db,7f,f8,e8,0d,\
94,0d,98,e7,06,ea,e5,f5,f7,cb,35,e7,0a,bf,f3,2e,e9,5c,59,a9,0f,32,b8,e5,6d,\
6f,44,09,ef,b7,c3,be,7c,65,76,28,81,e5,96,18,d8,eb,11,fb,a9,ec,cf,1c,75,44,\
03,d8,7e,b6,36,f4,1f,f4,39,67,15,da,29,cf,21,c0,ff,e4,c5,e1,f2,e7,14,7c,04,\
2c,84,25,b6,44,3a,5b,0a,1a,a9,61,da,22,64,53,ee,2a,f4,73,f3,38,b7,ba,db,86,\
a7,3b,a0,35,83,53,18,57,86,2c,26,e3,ad,ab,6b,4a,13,5d,f7,28,ee,af,17,65,47,\
b9,78,b7,a4,4e,23,b2,00,e7,26,a1,7c,82,93,40,22,47,d4,5f,e5,0d,90,95,9e,86,\
3f,00,8c,a8,80,87,2a,19,d5,a5,48,98,57,e1,ca,31,39,26,a6,7a,99,d0,39,4a,c2,\
48,35,08,e9,e8,be,59,60,43,67,42,e0,b6,43,5f,f0,05,7e,87,8f,21,b7,4a,5f,9a,\
bb,5c,03,35,f4,19,08,38,92,b3,05,8f,95,3c,b7,52,be,3a,2e,9d,9d,d8,72,de,b7,\
e0,81,8a,44,49,fc,70,c2,6d,bc,21,84,3a,05,40,22,56,08,b4,c1,d3,92,81,99,31,\
78,f3,14,77,7e,29,f8,ef,95,bc,62,4d,7c,d6,a4,b4,9c,30,8e,28,e8,7f,01,08,cc,\
af,61,9d,da,6a,4d,d8,28,28,c8,01,9b,84,52,9d,55,f1,7d,1e,90,0b,4d,14,42,d3,\
40,20,f6,41,13,2b,26,4c,5d,36,2d,18,c3,ec,4c,c9,1b,25,2f,76,ea,cb,19,3f,e7,\
29,38,29,a8,7a,02,04,e4,47,97,b5,8a,f3,ce,91,2b,7f,e6,4e,05,f1,84,57,a0,33,\
b7,ee,2b,20,bb,17,8a,0c,77,04,61,65,8a,71,9f,48,88,24,ea,08,59,37,80,f5,1e,\
6d,31,6a,42,7b,2b,03,86,7f,76,ff,bb,e9,2d,c2,18,e5,de,e9,d7,ec,21,a3,5a,fb,\
ec,b8,c7,4b,ab,44,80,23,4b,24,b2,2a,6f,a9,26,54,d9,f8,22,69,19,e1,e4,72,c6,\
16,d6,87,90,99,07,2a,80,30,c6,1b,95,59,c4,d3,01,97,68,de,ac,00,78,7e,0d,ab,\
28,fc,68,e7,b2,80,90,ba,b4,22,09,e5,bc,54,84,9a,67,60,6e,71,7f,6a,c7,ad,d2,\
e0,5c,30,a2,8d,f4,85,98,67,6d,18,a3,7a,e8,60,3d,6c,10,43,a7,57,67,71,f6,11,\
58,9a,f6,36,d5,dd,5b,10,24,83,b4,90,d9,9e,f6,79,fa,65,41,14,3d,6c,8e,0c,f8,\
62,a6,a1,5d,38,61,0b,80,ff,65,73,6b,2e,66,82,e0,d4,f2,38,02,35,b6,30,21,fe,\
c9,d7,84,0e,4d,de,0c,d5,cd,4a,18,6a,d6,05,49,02,7a,8f,9e,ec,59,4a,d8,c6,73,\
e1,bf,b8,d2,b2,85,e9,c8,b3,fa,92,3a,e0,a1,74,df,8a,fa,75,b9,af,18,ef,ab,bd,\
38,60,1f,1a,39,e2,40,8a,f4,69,49,6c,a8,a4,12,86,b5,ae,53,82,cb,0f,f1,2f,9a,\
c8,c8,d1,06,7c,0e,49,ca,cd,f2,7f,c5,c5,d2,0a,02,72,84,38,bf,c2,d0,25,a5,d9,\
c0,23,b7,fc,0c,bf,bc,21,48,7b,cd,9d,1a,3e,1c,53,51,22,53,ac,f0,dd,9a,b7,78,\
ab,90,64,a7,ff,5a,c3,30,32,c7,6b,0e,bb,1b,02,16,59,35,d7,2c,08,2f,02,6c,8a,\
5d,24,5f,94,8b,1d,51,1f,cb,91,09,d0,29,63,04,bf,72,9b,71,eb,d7,73,4e,b7,35,\
55,95,51,70,a3,2d,ec,6a,84,29,72,8d,e5,70,20,45,08,3e,cb,50,a0,00,e0,54,f1,\
df,b0,c9,15,b5,6b,df,e4,dd,6e,3e,67,eb,ac,1b,ee,cc,e9,d5,df,da,fa,e5,1d,5c,\
89,c0,f5,82,16,90,4c,98,9e,d2,6f,1a,df,09,dc,a3,a3,1d,ea,19,08,4b,c7,f4,59,\
76,74,79,e8,0c,95,70,4d,0c,8a,09,11,ad,27,ac,b3,a9,ca,71,aa,e8,dd,cb,1b,6d,\
85,13,65,27,cc,af,f5,a6,70,72,e2,83,1e,e1,ed,4e,25,f7,01,76,0f,dc,d0,04,9b,\
18,94,82,96,43,26,35,4b,b9,af,b5,2f,2c,02,4f,2a,a0,2b,7e,51,75,cd,cc,61,52,\
ca,75,3b,6a,10,ef,5a,9c,e0,16,6f,e2,a9,79,e8,e0,be,81,0b,53,9a,b0,e7,b2,3d,\
9f,c3,d6,2c,b2,3e,03,e8,7b,2d,7c,e7,47,da,86,d9,a1,50,08,f7,75,9d,66,7d,51,\
9e,7b,ce,3b,51,22,80,6d,7b,f5,52,19,87,a4,d7,f9,d6,47,af,c4,92,d3,57,c4,df,\
3e,a8,bc,9c,aa,ed,0a,56,14,c3,d8,10,14,50,ed,12,fd,2e,fa,9b,ef,c4,d4,0e,a7,\
5d,94,51,60,6a,c9,2b,36,c8,3c,bd,0d,eb,5c,18,5e,34,36,c5,d2,23,d7,05,bf,3e,\
d6,22,e2,34,78,e5,6c,de,36,a5,92,37,57,57,97,04,8b,67,b6,d8,8d,22,8a,e9,4e,\
e3,d4,58,e4,7b,12,5f,41,e1,5c,a9,72,68,35,1b,1c,10,66,bb,db,fa,2e,8f,cf,f5,\
db,4d,85,2b,a0,12,96,cd,ee,6d,1e,1b,bc,0d,be,cf,98,97,3f,06,73,c6,b3,80,19,\
57,3e,a8,72,5b,e4,42,b9,d8,ce,27,c7,45,48,cb,f6,66,40,4c,e1,dc,7e,27,18,77,\
a9,92,fb,0d,cb,42,a0,60,8e,07,94,df,bd,c2,6f,60,88,3a,df,16,6b,50,75,25,3b,\
7f,40,6b,ed,a3,b7,ab,50,cd,6c,15,00,0f,f5,1b,9e,c2,05,1e,20,17,7c,ee,2b,2d,\
ec,bf,b8,fa,16,b6,f2,8b,1a,b7,af,43,a8,3b,54,d1,a9,42,82,8b,43,83,d3,a2,73,\
ee,f6,52,74,4f,75,89,3b,78,85,c9,0c,ad,f3,5d,4a,23,ff,2a,6e,14,14,9f,e5,b5,\
b2,04,1c,75,38,0b,11,da,55,89,c4,f7,f3,ff,92,4b,2f,05,8b,15,0c,98,70,b0,ca,\
17,d3,12,ce,70,c3,3b,df,09,1a,cc,b0,5d,68,63,cb,3f,10,e2,76,6c,cc,47,3e,f4,\
94,00,a2,27,26,f5,a7,ea,5a,ce,f8,44,19,dc,48,a7,3d,d5,8d,60,c3,74,22,8e,47,\
47,ba,1d,3f,dd,1b,81,a8,2f,e0,f7,2c,8a,21,b9,28,1f,5d,4f,45,02,1a,f3,1b,0d,\
e0,40,97,05,b9,fc,f8,67,0a,a7,ba,f1,cf,b7,68,34,93,0c,66,29,98,9f,88,84,26,\
74,cc,42,ef,73,4c,11,bb,bf,75,53,6a,0e,7d,df,72,2a,e2,a6,fc,84,d5,3a,3b,06,\
ca,86,54,14,b5,f5,f5,05,df,57,e6,c8,23,fb,6f,65,24,9b,ed,bd,ed,6c,e4,89,91,\
22,9e,5f,8c,fb,97,da,5d,03,44,9d,f9,54,14,00,00,00,d9,66,15,a7,52,6e,e0,02,\
80,02,47,bf,8f,94,d7,68,ae,d1,36,5b

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winsfg32]
"Asynchronous"=dword:00000001
"DllName"="winsfg32.dll"
"Impersonate"=dword:00000000
"Startup"="EvtStartup"
"Shutdown"="EvtShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


The following are the files found:
****************************************************************************

Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************

****************************************************************************
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
zip warning: name not matched: dlls\*.*

zip error: Nothing to do! (backup.zip)
adding: backregs/notibac.reg (164 bytes security) (deflated 79%)
adding: backregs/shell.reg (164 bytes security) (deflated 73%)










Logfile of HijackThis v1.99.1
Scan saved at 2:47:12 PM, on 2/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Documents and Settings\Ernie\My Documents\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?rs=1
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?rs=1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1151356478299
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winsfg32 - C:\WINDOWS\SYSTEM32\winsfg32.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Hi dirtyyank

Download ATF Cleaner by Atribune and save it to your Desktop.
Do not use yet!

Ewido is now known as ( AVG Anti-Spyware.)

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
Dont use yet!
___________________

Copy/paste the following text into a new Notepad document. (You must use Notepad, NOT Wordpad). Make sure that you have NO blank lines at the beginning of the document before REGEDIT4, and ONE blank line at the end of the document as shown in the quoted text:

REGEDIT4

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winsfg32]


Save it to your desktop as Fixme.reg. Save it as follows…
File Type: "All Files" (not as a text document or it wont work).
Name: Fixme.reg

Locate Fixme.reg on your desktop and double-click it. When asked if you want to merge with the registry, click YES. Wait for the merged successfully prompt.
_____________

Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O20 - Winlogon Notify: winsfg32 - C:\WINDOWS\SYSTEM32\winsfg32.dll

WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit


We need to reveal system folders
  • Close all programs so that you are at your desktop.
  • Double-click on the My Computer icon.
  • Select the Tools menu and click Folder Options
  • After the new window appears select the View tab.
  • Place a checkmark in the checkbox labeled Display the contents of system folders
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types
  • Remove the checkmark from the checkbox labeled Hide protected operating system files
  • Press the Apply and then the ok button and shut down my computer
  • Now your computer is configured to show all hidden files.
  • For you and the tools to be able to see appropriate files we need to Show Hidden Files
Re-boot into safe mode

  • Next, please reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear use arrow up to highlight
  • Select the first option, to run Windows in Safe Mode hit enter.
  • For additional help in booting into Safe Mode, see the following site: HERE
Right click start, In the drop down menu click "Explore" Then navigate to each file\ folder in the left hand pane, which will reveal its content in the right hand pane, highlight file or folder right click and Delete, if present:

C:\WINDOWS\SYSTEM32\winsfg32.dll


Run ATF cleaner
  • Double click ATF-Cleaner.exe to run the program.
  • Check the following boxes:
    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Prefetch
    • Recycle Bin
    • Java Cache
  • The rest are optional - if you want to remove the lot, check Select All.
  • Now click Empty Selected.
  • When you get the Done Cleaning message, click OK.
  • If you use Firefox browser.
    • Click Firefox at the top and choose: Select All
    • If you would like to keep your saved passwords, please click No at the prompt.
    • Click the Empty Selected button.
  • If you use Opera browser.
    • Click Opera at the top and choose: Select All
    • If you would like to keep your saved passwords, please click No at the prompt.
    • Click the Empty Selected button.

Run AVG Anti-Spyware

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)

      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.
________________

please do an online scan with Kaspersky Online Scanner

Click on Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Extended (If available otherwise Standard)
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Please include new HJT log, AVG Anti-Spyware log and kaspersky log
in your next post
Thanks dan
——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 4:13:30 PM 2/4/2007 + Scan result: C:\Documents and Settings\Ernie\My Documents\My Music\Setup.exe -> Downloader.Agent.auv : Cleaned with backup (quarantined). :mozilla.100:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.101:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.102:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.103:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.104:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.105:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.114:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.115:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.116:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.117:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.118:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.119:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.121:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.122:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.123:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.124:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.125:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.126:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.127:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.128:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.129:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.228:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.335:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.88:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.89:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.90:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.91:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.92:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.93:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.94:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.95:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.96:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.97:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.98:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.99:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.386:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.7search : Error during cleaning. :mozilla.387:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.7search : Error during cleaning. :mozilla.173:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Adbrite : Error during cleaning. :mozilla.309:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.310:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.311:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.688:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.92:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Adbrite : Error during cleaning. :mozilla.93:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Adbrite : Error during cleaning. :mozilla.94:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Adbrite : Error during cleaning. :mozilla.95:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Adbrite : Error during cleaning. :mozilla.96:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Adbrite : Error during cleaning. :mozilla.276:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Addynamix : Error during cleaning. :mozilla.348:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned. :mozilla.257:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Adrevolver : Error during cleaning. :mozilla.262:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Adrevolver : Error during cleaning. :mozilla.266:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Adrevolver : Error during cleaning. :mozilla.267:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Adrevolver : Error during cleaning. :mozilla.275:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Adrevolver : Error during cleaning. :mozilla.432:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.433:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.434:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.435:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.436:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.437:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.362:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Adtech : Error during cleaning. :mozilla.363:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Adtech : Error during cleaning. :mozilla.58:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.59:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.18:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.19:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.201:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Advertising : Error during cleaning. :mozilla.202:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Advertising : Error during cleaning. :mozilla.203:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Advertising : Error during cleaning. :mozilla.204:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Advertising : Error during cleaning. :mozilla.205:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Advertising : Error during cleaning. :mozilla.20:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.21:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.22:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.26:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.49:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Atdmt : Error during cleaning. :mozilla.265:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Bfast : Cleaned. :mozilla.53:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Bridgetrack : Error during cleaning. :mozilla.54:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Bridgetrack : Error during cleaning. :mozilla.55:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Bridgetrack : Error during cleaning. :mozilla.56:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Bridgetrack : Error during cleaning. :mozilla.144:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned. :mozilla.145:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.146:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.147:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.261:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Burstnet : Error during cleaning. :mozilla.264:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Burstnet : Error during cleaning. :mozilla.627:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.628:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.629:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.630:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.631:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.632:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.633:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.204:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned. :mozilla.57:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Com : Error during cleaning. :mozilla.58:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Com : Error during cleaning. :mozilla.77:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.78:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.381:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Coremetrics : Error during cleaning. :mozilla.544:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned. :mozilla.18:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{D50DB637-3A86-42C1-820B-D88F138A572F}\{70E6B05B-10B8-4E81-B43D-D673C97DC986}.txt/{70E6B05B-10B8-4E81-B43D-D673C97DC986}.txt -> TrackingCookie.Doubleclick : Error during cleaning. :mozilla.23:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.44:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Doubleclick : Error during cleaning. C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{61B5B806-D908-4B3C-BBCC-087DF8BA2307}.txt/{61B5B806-D908-4B3C-BBCC-087DF8BA2307}.txt -> TrackingCookie.Enhance : Cleaned. :mozilla.499:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.297:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.298:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.299:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.300:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.301:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.120:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.27:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Fastclick : Error during cleaning. :mozilla.28:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Fastclick : Error during cleaning. :mozilla.29:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Fastclick : Error during cleaning. :mozilla.30:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Fastclick : Error during cleaning. :mozilla.60:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.61:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.62:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.63:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.64:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{0D184C4E-790A-4BC9-A98B-0DBB199C4D28}.txt/{0D184C4E-790A-4BC9-A98B-0DBB199C4D28}.txt -> TrackingCookie.Goclick : Cleaned. :mozilla.111:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Googleadservices : Error during cleaning. :mozilla.155:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.158:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.248:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Googleadservices : Error during cleaning. :mozilla.400:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Googleadservices : Error during cleaning. :mozilla.403:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Googleadservices : Error during cleaning. :mozilla.50:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Googleadservices : Error during cleaning. :mozilla.703:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.72:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Googleadservices : Error during cleaning. :mozilla.11:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{D50DB637-3A86-42C1-820B-D88F138A572F}\{70E6B05B-10B8-4E81-B43D-D673C97DC986}.txt/{70E6B05B-10B8-4E81-B43D-D673C97DC986}.txt -> TrackingCookie.Hitbox : Error during cleaning. :mozilla.160:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Hitbox : Error during cleaning. :mozilla.330:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.391:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Hitbox : Error during cleaning. :mozilla.41:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.425:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.426:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.427:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.42:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.43:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.548:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.589:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.428:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned. :mozilla.68:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Hotlog : Error during cleaning. C:\Documents and Settings\Ernie\Cookies\ernie@linksynergy[2].txt -> TrackingCookie.Linksynergy : Cleaned. :mozilla.551:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.552:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.553:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.336:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Masterstats : Error during cleaning. :mozilla.24:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.25:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.66:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Mediaplex : Error during cleaning. :mozilla.67:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Mediaplex : Error during cleaning. :mozilla.211:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Myaffiliateprogram : Error during cleaning. :mozilla.524:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Onestat : Cleaned. :mozilla.525:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Onestat : Cleaned. :mozilla.130:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Overture : Error during cleaning. :mozilla.223:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Overture : Error during cleaning. :mozilla.289:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.290:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.71:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.72:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.73:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.74:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.75:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.191:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Pstats : Cleaned. :mozilla.106:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.107:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.108:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.64:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Questionmarket : Error during cleaning. :mozilla.65:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Questionmarket : Error during cleaning. :mozilla.263:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Realmedia : Error during cleaning. :mozilla.168:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.169:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.294:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Ru4 : Error during cleaning. :mozilla.295:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Ru4 : Error during cleaning. :mozilla.296:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Ru4 : Error during cleaning. :mozilla.297:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Ru4 : Error during cleaning. :mozilla.298:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Ru4 : Error during cleaning. C:\Documents and Settings\Ernie\Cookies\ernie@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.170:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.171:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.172:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.173:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.174:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.175:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.192:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Sitestat : Error during cleaning. :mozilla.357:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned. :mozilla.485:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.486:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.487:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.488:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.489:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.208:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Spylog : Cleaned. :mozilla.69:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Spylog : Error during cleaning. :mozilla.169:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Statcounter : Error during cleaning. :mozilla.170:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Statcounter : Error during cleaning. :mozilla.171:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Statcounter : Error during cleaning. :mozilla.172:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Statcounter : Error during cleaning. :mozilla.174:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Statcounter : Error during cleaning. :mozilla.215:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.216:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.217:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.218:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.219:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.220:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.221:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.222:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.223:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.224:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.225:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.226:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.227:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.228:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.229:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.230:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.231:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.232:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.233:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.234:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.235:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.236:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.237:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.363:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.364:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.365:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.490:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.85:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Tacoda : Error during cleaning. :mozilla.86:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Tacoda : Error during cleaning. :mozilla.87:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Tacoda : Error during cleaning. :mozilla.88:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Tacoda : Error during cleaning. :mozilla.91:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Tacoda : Error during cleaning. :mozilla.255:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Trafficmp : Error during cleaning. :mozilla.265:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Trafficmp : Error during cleaning. :mozilla.268:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Trafficmp : Error during cleaning. :mozilla.269:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Trafficmp : Error during cleaning. :mozilla.270:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Trafficmp : Error during cleaning. :mozilla.271:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Trafficmp : Error during cleaning. :mozilla.272:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Trafficmp : Error during cleaning. :mozilla.273:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Trafficmp : Error during cleaning. :mozilla.274:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Trafficmp : Error during cleaning. :mozilla.439:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.440:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.441:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.442:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.443:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.444:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.445:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.143:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Trafic : Cleaned. :mozilla.256:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Tribalfusion : Error during cleaning. :mozilla.650:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.83:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.578:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.580:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.581:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.582:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.583:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.584:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.258:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Valueclick : Error during cleaning. :mozilla.259:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Valueclick : Error during cleaning. :mozilla.546:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned. :mozilla.421:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned. C:\Documents and Settings\Ernie\Cookies\[removed][2].txt -> TrackingCookie.Webtrendslive : Cleaned. :mozilla.210:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Yadro : Cleaned. :mozilla.212:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Yadro : Cleaned. :mozilla.423:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Yadro : Error during cleaning. :mozilla.100:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Yieldmanager : Error during cleaning. :mozilla.101:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{1EBB195D-E650-49F1-90C2-8F715ABEAE0F}\{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt/{811113F4-345F-4132-BE8B-2A31562FAAE2}.txt -> TrackingCookie.Yieldmanager : Error during cleaning. :mozilla.126:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.127:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.128:C:\Documents and Settings\Ernie\Application Data\Mozilla\Firefox\Profiles\9zgmtq3o.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.19:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{D50DB637-3A86-42C1-820B-D88F138A572F}\{70E6B05B-10B8-4E81-B43D-D673C97DC986}.txt/{70E6B05B-10B8-4E81-B43D-D673C9
Logfile of HijackThis v1.99.1
Scan saved at 4:21:30 PM, on 2/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Ernie\My Documents\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?rs=1
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?rs=1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1151356478299
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winsfg32 - winsfg32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
KASPERSKY ONLINE SCANNER REPORT Sunday, February 04, 2007 8:53:59 AM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 3/02/2007 Kaspersky Anti-Virus database records: 249749 Scan Settings Scan using the following antivirus database standard Scan Archives true Scan Mail Bases true Scan Target My Computer A:\ C:\ D:\ Scan Statistics Total number of scanned objects 31381 Number of viruses found 3 Number of infected objects 3 / 0 Number of suspicious objects 0 Duration of the scan process 01:48:39 Infected Object Name Virus Name Last Action C:\Documents and Settings\Ernie\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Ernie\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Ernie\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Ernie\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Ernie\Local Settings\History\History.IE5\MSHist012007020320070204\index.dat Object is locked skipped C:\Documents and Settings\Ernie\Local Settings\Temp\ZLT0358e.TMP Object is locked skipped C:\Documents and Settings\Ernie\Local Settings\Temp\ZLT035ea.TMP Object is locked skipped C:\Documents and Settings\Ernie\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Ernie\My Documents\My Music\Setup.exe Infected: Trojan-Downloader.Win32.Agent.auv skipped C:\Documents and Settings\Ernie\ntuser.dat Object is locked skipped C:\Documents and Settings\Ernie\NTUSER.DAT.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\Internet Logs\FRANKENBEAST.ldb Object is locked skipped C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\1933424099 Infected: Trojan.Win32.Agent.qt skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped C:\WINDOWS\system32\vxga4me1.exe Infected: Trojan.Win32.Agent.acr skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI