0

Hi Guys

Its good to see that there is help out there for PC noobs like myself, so I hope you can help me out with some problems I have been experiencing.

A couple of weeks ago I started having new IE windows opening up with adverts displayed even though I use Firefox. I did some googling and discovered I had a trojan. I used VundoFix as instructed to clear it out.

The pop ups have stopped but now I get an error message on startup

C:\WINDOWS\system32\aejtnss.dll

I click OK and everything works.

The next thing I discovered was that if I click the start button and then the run in the list and type cmd I get the message:-

Another program is currently using this file.

And as I had no other progs running I guessed that, that wasn't right.

I use Zonealarm (free) as my firewall and my ISP provide my virus checker NTL netguard. I also run Adaware and Spybot regularly.

I followed your instructions about running AVG and HJT and here are my logs:-

Logfile of HijackThis v1.99.1
Scan saved at 17:02:25, on 25/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ntl\ntl Netguard\fws.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Apps\Powercinema\PCMService.exe
C:\Program Files\ntl\ntl Netguard\RPS.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\{F0889D5B-088C-2057-0720-05012306002c}\Update.exe
C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
C:\Program Files\Ipwindows\ipwins.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://format.packardbell.com/cgi-bin/redirect/?country=UK&range=AD&phase=6&key=SEARCH
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file://C:\APPS\IE\offline\uk.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\uk.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\ntl\ntl Netguard\pkR.dll
O2 - BHO: (no name) - {3DBAF53B-2576-4993-B270-411256569E8C} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\ntl\ntl Netguard\FBHR.dll
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: (no name) - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ntl Netguard] "C:\Program Files\ntl\ntl Netguard\RPS.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
O4 - HKLM\..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\aejetnss.dll",setvm
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - HKCU\..\Run: [Uniblue Registry Booster2] C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S
O4 - Global Startup: dllhost.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: Client IP-IPX - Unknown owner - ".exe (file missing)
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\ntl\ntl Netguard\fws.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 22:05:57 24/04/2007

+ Scan result:

HKU\S-1-5-21-2043878182-1645750751-2790001948-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4E7BD74F-2B8D-469E-A0E8-F479B685FA7D} -> Adware.2020Search : Cleaned with backup (quarantined).
C:\Program Files\Common Files\{30889D5B-088C-2057-0720-05012306002c}\Bar888.dll -> Adware.Lucky : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Local Settings\Temp\b122.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Local Settings\Temporary Internet Files\Content.IE5\HE35DYK6\122[1].net -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP253\A0076979.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP253\A0076981.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\VundoFix Backups\gebywxx.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\VundoFix Backups\jkkkhig.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Local Settings\Temp\b129.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Local Settings\Temporary Internet Files\Content.IE5\5VLLU79T\129[1].net -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP278\A0082742.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP278\A0082743.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP278\A0082744.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP278\A0082745.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\app.exe -> Downloader.Adload.jm : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\install.exe -> Downloader.Adload.jm : Cleaned with backup (quarantined).
C:\WINDOWS\system32\svchosts.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Local Settings\Temp\b104.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Local Settings\Temporary Internet Files\Content.IE5\3LG5KBAV\104[1].net -> Downloader.Small.buy : Cleaned with backup (quarantined).
:mozilla.165:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.6:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.102:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.105:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.106:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.107:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.108:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.10:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.11:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.12:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.12:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\8yo3dd1x.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.13:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.14:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.15:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.16:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.17:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.18:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.21:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.220:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.241:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.253:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.265:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.278:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.28:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.29:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.30:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.31:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.32:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.349:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.34:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.350:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.35:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.367:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.368:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.36:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.370:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.371:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.37:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.38:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.39:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.402:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.40:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.41:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.42:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.463:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.7:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.8:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.9:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Adam\Cookies\adam@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@divx.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@pinnaclesystems.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Nancy\Cookies\nancy@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.41:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.42:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.43:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.72:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.73:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.74:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Adam\Cookies\adam@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@www.adobe[1].txt -> TrackingCookie.Adobe : Cleaned.
:mozilla.37:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.38:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.10:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.11:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.12:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.14:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.15:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.16:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.14:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\8yo3dd1x.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.15:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\8yo3dd1x.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.188:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.189:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.54:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.55:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.25:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\8yo3dd1x.default\cookies.txt -> TrackingCookie.Adviva : Cleaned.
:mozilla.24:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\8yo3dd1x.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Adam\Cookies\adam@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.217:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.97:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.47:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.48:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.49:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.99:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Centrport : Cleaned.
:mozilla.135:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.136:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.105:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.121:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.232:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.106:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.107:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.108:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.109:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.16:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\8yo3dd1x.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.17:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\8yo3dd1x.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.18:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\8yo3dd1x.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.233:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.234:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.23:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\8yo3dd1x.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Adam\Cookies\adam@connextra[2].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@connextra[1].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Nancy\Cookies\nancy@connextra[1].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Adam\Cookies\adam@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Nancy\Cookies\nancy@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.13:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\8yo3dd1x.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.8:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Adam\Cookies\adam@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.124:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.125:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.126:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.127:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.128:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.129:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.130:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.131:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.132:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.156:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.157:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.250:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.251:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.252:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.253:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.254:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.255:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.256:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.257:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.258:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.177:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.178:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.46:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.47:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.58:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Adam\Cookies\adam@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Nancy\Cookies\nancy@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.72:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.74:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.76:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.183:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.184:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.301:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.302:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.550:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.596:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.597:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.598:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.599:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.600:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.601:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.602:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.603:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.604:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.95:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.207:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.
:mozilla.17:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.18:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.195:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.196:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.607:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Information : Cleaned.
:mozilla.198:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Intelli-direct : Cleaned.
:mozilla.222:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Intelli-direct : Cleaned.
:mozilla.601:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.602:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.603:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Live : Cleaned.
C:\Documents and Settings\Nancy\Cookies\nancy@search.live[2].txt -> TrackingCookie.Live : Cleaned.
:mozilla.480:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.481:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.482:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.525:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.526:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.527:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.528:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.529:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.530:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.531:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.532:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.533:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.534:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.535:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.536:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.609:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.610:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.611:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.466:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.22:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\8yo3dd1x.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.604:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.605:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.606:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\Adam\Cookies\adam@ie.search.msn[2].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.276:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Navrcholu : Cleaned.
:mozilla.363:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.376:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.542:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.543:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.262:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.268:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.399:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.565:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.651:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.685:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\Adam\Cookies\adam@www.paypal[2].txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.184:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.185:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.186:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.187:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.50:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.51:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.52:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.53:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.115:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.116:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.283:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.284:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.436:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Real : Cleaned.
:mozilla.437:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Real : Cleaned.
:mozilla.732:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Adam\Cookies\adam@guide.real[1].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Adam\Cookies\adam@realguide.real[1].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Adam\Cookies\adam@uk.real[1].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@uk.real[1].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Nancy\Cookies\nancy@guide.real[1].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Nancy\Cookies\nancy@music.guide.real[2].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Nancy\Cookies\nancy@realguide.real[1].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Nancy\Cookies\nancy@uk.real[1].txt -> TrackingCookie.Real : Cleaned.
:mozilla.297:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.438:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.439:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.440:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.442:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.304:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.305:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.306:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.307:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.308:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.309:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.310:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.311:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.443:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.444:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.445:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.446:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.447:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.447:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.448:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.449:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.450:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.451:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.573:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.147:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.216:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.343:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.344:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.345:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.346:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.347:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.464:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.465:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.466:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.467:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.468:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.96:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.548:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.549:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.628:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.363:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Skype : Cleaned.
:mozilla.364:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Skype : Cleaned.
:mozilla.524:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Skype : Cleaned.
:mozilla.538:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Skype : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@skype[1].txt -> TrackingCookie.Skype : Cleaned.
:mozilla.576:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.577:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.578:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.359:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.360:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.361:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.362:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.48:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.44:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.45:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.616:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Statistik-gallup : Cleaned.
:mozilla.370:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.371:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.372:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.479:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.480:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.375:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Toplist : Cleaned.
:mozilla.395:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Toplist : Cleaned.
:mozilla.87:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.88:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.89:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.377:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Trafic : Cleaned.
:mozilla.378:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.61:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.276:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.277:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.399:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.442:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.443:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.526:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.21:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\d2rfxbqz.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.587:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@m.webtrends[2].txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.96:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.424:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.553:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.554:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.435:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.436:C:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\mekg5ebw.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.562:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.563:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.564:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.565:C:\Documents and Settings\Nancy\Application Data\Mozilla\Firefox\Profiles\751tbdgd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0076359.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0076643.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0076817.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\Program Files\Ipwindows\UnInstall.exe -> Trojan.Rond : Cleaned with backup (quarantined).
C:\WINDOWS\system32\unsvchosts.exe -> Trojan.Small.mf : Cleaned with backup (quarantined).


::Report end

I hope you can help.

Thanks Easy

3
Contributors
9
Replies
10
Views
10 Years
Discussion Span
Last Post by gerbil
0

Uninstall pgm IpWindows.
C:\Program Files\Ipwindows\ipwins.exe -delete this file and the folder.
==Either: go Control panel > folder options OR: in an explorer window > tools>folder options;
-then view tab, press Show hidden files and folders, Apply and Ok.
===To restart your computer in Safe Mode:- press F8 several times while POST is running and before IDE detection completes.
- On the Windows Advanced Options Menu, select Safe Mode with Command Prompt and press Enter.
- When the Boot Menu appears again, select Microsoft Windows XP and press Enter.
- Log in by using the Administrator account and password. NOTE: The password is blank by default unless you set a password.
==Start hijackthis, do a Scan Only, and place checkmarks against all of the following, and press Fix Checked:

O2 - BHO: (no name) - {3DBAF53B-2576-4993-B270-411256569E8C} - (no file)
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - (no file)
O3 - Toolbar: (no name) - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\aejetnss.dll",setvm
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - Global Startup: dllhost.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O23 - Service: Client IP-IPX - Unknown owner - ".exe (file missing)

-Now press Config button, Misc Tools tab and then Delete a File on Reboot; in the window which opens paste into the text box the following pathname, press Open and then Yes...

C:\WINDOWS\system32\aejetnss.dll

Finally, locate this file and delete it:
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe

Restart in normal windows mode, make a fresh HT log, post it along with your comments.
Empty AVG's quarantine bin. Delete Vundofix's backups folder, C:\VundoFix Backups\
Btw, b4 you run scans like AVG it is wise to run a cleaner such as CCleaner:

===Get CCleaner from http://www.ccleaner.com/ - and put it in a new folder. You should aim to keep this one for general use. I set it from the install checkboxes to only open from the recycle bin. It's neater that way.
Now run Ccleaner from the recycle bin rclick menu using its default settings [if you set up CCleaner as i suggested, rclicking the bin icon should give you the Open CCleaner option...]. Select the Cleaner icon and the Windows tab; press Run Cleaner. Next select the Applications tab and Run Cleaner again.
[For future quick temp file cleaning select the options you wish to use. Note that CCleaner is also a free registry cleaner. Explore all its options, but skip the prefetch folder cleaning option. That one is a furphy, much loved on some websites, but cleaning it is unnecessary because windows automatically dumps old unused entries anyway, they can do no harm, and further, if there is no prefetch entry for an app you wish to load then your sys will just be a lil bit slower loading it. And an entry will then be generated anyway.]

0

Ok,

1) I couldn't uninstall IpWindows or delete C:\Program Files\Ipwindows\ipwins.exe

I got the message Cannot delete ipwins.dll: Access is denied. Make sure disk is not full or write preotected and that the file is not currently in use.

2) In the safe mode
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
Did not show up so I couldn't fix it in HT.

3) Finally The following file was not located so I couldn't delete it.
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup - contained the microsoft office flag.

My latest HT log is -

Logfile of HijackThis v1.99.1
Scan saved at 20:42:45, on 26/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ntl\ntl Netguard\fws.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Apps\Powercinema\PCMService.exe
C:\Program Files\ntl\ntl Netguard\RPS.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\{F0889D5B-088C-2057-0720-05012306002c}\Update.exe
C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
C:\Program Files\Ipwindows\ipwins.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://format.packardbell.com/cgi-bin/redirect/?country=UK&range=AD&phase=6&key=SEARCH
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file://C:\APPS\IE\offline\uk.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\uk.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\ntl\ntl Netguard\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\ntl\ntl Netguard\FBHR.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ntl Netguard] "C:\Program Files\ntl\ntl Netguard\RPS.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
O4 - HKLM\..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - HKCU\..\Run: [Uniblue Registry Booster2] C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\ntl\ntl Netguard\fws.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

0

Ripper... a guinea pig at last.. :)
Please get Unlocker from here: http://ccollomb.free.fr/unlocker/
Install it, uncheck the update option during installation if you wish; navigate to ipwins.exe [C:\Program Files\Ipwindows\ipwins.exe] and rclick it - a small window should open -select Delete and Ok. Please tell me if it works... and if so, delete the whole folder.
Do not worry about dll.host - its Global startup entry was fixed successfully.
You mentioned ipwins.dll -was this correct, or did you mean ipwins.exe?

0

I'm not sure I liked being a guinea pig (gulp)

But I did as you asked.

Once the Unlocker window came up I highlighted the two processes and hit the kill process button.

They disapeared and then I was able to delete the folder.

It deffo said
"Cannot delete ipwins.dll: Access is denied. Make sure disk is not full or write preotected and that the file is not currently in use."

New HT log-

Logfile of HijackThis v1.99.1
Scan saved at 14:20:37, on 27/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ntl\ntl Netguard\fws.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Apps\Powercinema\PCMService.exe
C:\Program Files\ntl\ntl Netguard\RPS.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\{F0889D5B-088C-2057-0720-05012306002c}\Update.exe
C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\WINDOWS\explorer.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://format.packardbell.com/cgi-bin/redirect/?country=UK&range=AD&phase=6&key=SEARCH
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file://C:\APPS\IE\offline\uk.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\uk.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\ntl\ntl Netguard\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\ntl\ntl Netguard\FBHR.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ntl Netguard] "C:\Program Files\ntl\ntl Netguard\RPS.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
O4 - HKLM\..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - HKCU\..\Run: [Uniblue Registry Booster2] C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\ntl\ntl Netguard\fws.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

0

Ha. Garn. Would i hurt your sys? I had played with Unlocker, liked its capabilities, but didn't have any tough files to delete. Which is nice, I guess.
So, just a couple of things to fix: the startup entry for Ipwins, and one I missed from before.
Fix these:
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe

Is everything okay now? No popups, and cmd.exe is free?

There is one entry in the log that bothers me : C:\Program Files\Common Files\{F0889D5B-088C-2057-0720-05012306002c}\Update.exe
- I have no idea where that could have come from, you may know or can find from its properties, but I can see no harm in renaming its extension to .xbak [the x is to remind you that it is a .exe, should some valid pgm protest.

0

Does he have sonic buring studio installed?

I have a similar referance to update.exe, its this installshield updater for it i think.

0

Right all instructions followed and completed.

No pop ups and cmd.exe is free.

I looked at the properties of the log that bothered you and although I do have Sonic, I've had it since the beginning of this PC's life and the properties of the update.exe said it was created a couple of weeks ago.
When all my probs started.

So I tried to delete it and I got the access denied message. So I again used the Unlocker pgm and it couldn't unlock it so I chose to delete it on reboot.

Thank you very much for your clear instructions, excellent follow up and great detective skills.
As I said when I added to your reputation more of a Bloodhound than a Gerbil :)

Thanks again TOP JOB!!!!!!!!!!!!!!!!!!!!!!

0

Nice, Easy, glad you're happy.. If the ppl who generated that guid, have made such a rare bird of an application that i can't find it out there, then James, imo there is a great chance it is dodgy. But it could well have been sonic's work; I spose it could be their way of encoding his machine info for their updater? I dunno; it would be fixable by reinstallation of their sware if it came to that..

This topic has been dead for over six months. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.