Jump to content


Photo

hijacker


  • Please log in to reply
21 replies to this topic

#1 mattybrig

mattybrig

    Member

  • Members
  • PipPip
  • 14 posts

Posted 24 June 2006 - 11:39 PM

my homepage has been hijacked and is stuck to sysnetsecurity.com. i have seen that some other people seem to have experienced the same problem but i was hoping for some personal help as there seem to be several solutions listed.

Here is my hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 23:33:52, on 24/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\No-IP\DUC20.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Warez P2P Client\warez.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\AdwareAlert\AdwareAlert.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Matthew\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Wanadoo - {4E7BD74F-2B8D-469E-A3F1-F068B59BBB2A} - C:\PROGRA~1\wanadoo1\wanadoo1.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Nothing - {686a161d-5bd1-4999-8832-6393f41e564c} - C:\WINDOWS\system32\hp100.tmp
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {E5DDD23C-8CAC-E243-6FFB-5F2186919F92} - C:\DOCUME~1\Ashley\APPLIC~1\STARTM~1\tray stop.exe (file missing)
O3 - Toolbar: Wanadoo - {4E7BD74F-2B8D-469E-A3F1-F068B59BBB2A} - C:\PROGRA~1\wanadoo1\wanadoo1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [EPSON Stylus C46 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P32 "EPSON Stylus C46 Series (Copy 1)" /O6 "USB001" /M "Stylus C46"
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [adwarealert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [SixthSend] C:\DOCUME~1\Matthew\APPLIC~1\SECOND~1\Copy mail.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [warez] "C:\Program Files\Warez P2P Client\warez.exe" -h
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Wanadoo Search - file://C:\Program Files\WANADOO1\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg...l_v1-0-3-30.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,26/mcgdmgr.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NoIPDUCService - Vitalwerks LLC - C:\Program Files\No-IP\DUC20.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\WinVNC.exe" -service (file missing)

Hope one of you genius' can help!

#2 Windjammers

Windjammers

    Member

  • Members
  • PipPip
  • 10 posts

Posted 25 June 2006 - 08:19 PM

I've been hijacked as well. I don't know how to get the log to post here. Can someone please tell me how to get rid of this hijacker?

#3 mattybrig

mattybrig

    Member

  • Members
  • PipPip
  • 14 posts

Posted 25 June 2006 - 10:44 PM

I've been hijacked as well. I don't know how to get the log to post here. Can someone please tell me how to get rid of this hijacker?


if you want to do the log you need to download a program called HijackThis. Its free!

i suggest you start a new topic to avoid confusion between my hijacker and yours when someone helps.

#4 mattybrig

mattybrig

    Member

  • Members
  • PipPip
  • 14 posts

Posted 25 June 2006 - 11:47 PM

Heres my Ad-Aware scan!


Ad-Aware SE Build 1.06r1
Logfile Created on:25 June 2006 22:57:14
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R112 15.06.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
MRU List(TAC index:0):30 total references
SpywareNo(TAC index:10):3 total references
Tracking Cookie(TAC index:3):208 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects


25-06-2006 22:57:14 - Scan started. (Full System Scan)

MRU List Object Recognized!
Location: : C:\Documents and Settings\Matthew\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office


MRU List Object Recognized!
Location: : C:\Documents and Settings\Matthew\recent
Description : list of recently opened documents


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d


MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X


MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X


MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\directinput\mostrecentapplication
Description : most recent application to use microsoft directinput


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\directinput\mostrecentapplication
Description : most recent application to use microsoft directinput


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\internet explorer
Description : last download directory used in microsoft internet explorer


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\internet explorer\typedurls
Description : list of recently entered addresses in microsoft internet explorer


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\mediaplayer\medialibraryui
Description : last selected node in the microsoft windows media player media library


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\mediaplayer\player\recentfilelist
Description : list of recently used files in microsoft windows media player


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\mediaplayer\preferences
Description : last playlist index loaded in microsoft windows media player


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\mediaplayer\preferences
Description : last playlist loaded in microsoft windows media player


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\office\11.0\common\general
Description : list of recently used symbols in microsoft office


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\office\11.0\common\open find\microsoft office powerpoint\settings\save as\file name mru
Description : list of recent documents saved by microsoft powerpoint


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\office\11.0\common\open find\microsoft office word\settings\open\file name mru
Description : list of recent documents opened by microsoft word


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\office\11.0\common\open find\microsoft office word\settings\save as\file name mru
Description : list of recent documents saved by microsoft word


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\office\11.0\powerpoint\recent file list
Description : list of recent files used by microsoft powerpoint


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\search assistant\acmru
Description : list of recent search terms used with the search assistant


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\windows\currentversion\applets\paint\recent file list
Description : list of files recently opened using microsoft paint


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\windows\currentversion\applets\regedit
Description : last key accessed using the microsoft registry editor


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\windows\currentversion\explorer\runmru
Description : mru list for items opened in start | run


MRU List Object Recognized!
Location: : .DEFAULT\software\microsoft\windows media\wmsdk\general
Description : windows media sdk


MRU List Object Recognized!
Location: : S-1-5-18\software\microsoft\windows media\wmsdk\general
Description : windows media sdk


MRU List Object Recognized!
Location: : S-1-5-21-1229272821-813497703-1708537768-1006\software\microsoft\windows media\wmsdk\general
Description : windows media sdk


Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 372
ThreadCreationTime : 25-06-2006 21:15:40
BasePriority : Normal


#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 608
ThreadCreationTime : 25-06-2006 21:15:43
BasePriority : Normal


#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 632
ThreadCreationTime : 25-06-2006 21:15:45
BasePriority : High


#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 684
ThreadCreationTime : 25-06-2006 21:15:47
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe

#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 696
ThreadCreationTime : 25-06-2006 21:15:47
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe

#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 852
ThreadCreationTime : 25-06-2006 21:15:50
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 912
ThreadCreationTime : 25-06-2006 21:15:51
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:8 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1008
ThreadCreationTime : 25-06-2006 21:15:51
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:9 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1076
ThreadCreationTime : 25-06-2006 21:15:51
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:10 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1148
ThreadCreationTime : 25-06-2006 21:15:52
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:11 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1400
ThreadCreationTime : 25-06-2006 21:15:59
BasePriority : Normal
FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
ProductVersion : 5.1.2600.2696
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe

#:12 [kodakccs.exe]
FilePath : C:\WINDOWS\system32\drivers\
ProcessID : 1540
ThreadCreationTime : 25-06-2006 21:16:08
BasePriority : Normal
FileVersion : 1.1.5100.4
ProductVersion : 4.4.0.0
ProductName : Kodak DC File System Driver (Win32)
CompanyName : Eastman Kodak Company
FileDescription : Kodak DC Ring 3 Conduit (Win32)
InternalName : KodakCCS.exe
LegalCopyright : Copyright © Eastman Kodak Co. 2000-2004
OriginalFilename : DcFsSvc.exe

#:13 [mcdetect.exe]
FilePath : c:\program files\mcafee.com\agent\
ProcessID : 1568
ThreadCreationTime : 25-06-2006 21:16:08
BasePriority : Normal
FileVersion : 6, 0, 0, 19
ProductVersion : 6, 0, 0, 0
ProductName : McAfee SecurityCenter
CompanyName : McAfee, Inc
FileDescription : McAfee WSC Integration Service
InternalName : McDetect
LegalCopyright : Copyright © 2005 McAfee, Inc.
OriginalFilename : McDetect.exe
Comments : McAfee WSC Integration Service

#:14 [mcshield.exe]
FilePath : c:\PROGRA~1\mcafee.com\vso\
ProcessID : 1620
ThreadCreationTime : 25-06-2006 21:16:09
BasePriority : High


#:15 [mctskshd.exe]
FilePath : c:\PROGRA~1\mcafee.com\agent\
ProcessID : 1696
ThreadCreationTime : 25-06-2006 21:16:10
BasePriority : Normal
FileVersion : 6, 0, 0, 13
ProductVersion : 6, 0, 0, 0
ProductName : McAfee SecurityCenter
CompanyName : McAfee, Inc
FileDescription : McAfee Task Scheduler
InternalName : McTskshd
LegalCopyright : Copyright © 2005 McAfee, Inc.
OriginalFilename : McTskshd.exe

#:16 [mdm.exe]
FilePath : C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\
ProcessID : 1780
ThreadCreationTime : 25-06-2006 21:16:11
BasePriority : Normal
FileVersion : 7.00.9466
ProductVersion : 7.00.9466
ProductName : Microsoft® Visual Studio .NET
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : mdm.exe

#:17 [duc20.exe]
FilePath : C:\Program Files\No-IP\
ProcessID : 1848
ThreadCreationTime : 25-06-2006 21:16:14
BasePriority : Normal
FileVersion : 2.2.1.0
ProductVersion : 2.2.1.0
ProductName : DUC v2.2.1.0
CompanyName : Vitalwerks LLC
FileDescription : No-IP.com DUC
LegalCopyright : Vitalwerks LLC & No-IP.com

#:18 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 208
ThreadCreationTime : 25-06-2006 21:16:20
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE

#:19 [slserv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 328
ThreadCreationTime : 25-06-2006 21:16:21
BasePriority : Normal


#:20 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 356
ThreadCreationTime : 25-06-2006 21:16:23
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:21 [wdfmgr.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 360
ThreadCreationTime : 25-06-2006 21:16:25
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: dnsrv(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe

#:22 [winvnc.exe]
FilePath : C:\Program Files\UltraVNC\
ProcessID : 588
ThreadCreationTime : 25-06-2006 21:16:28
BasePriority : Normal


#:23 [jusched.exe]
FilePath : C:\Program Files\Java\jre1.5.0_06\bin\
ProcessID : 148
ThreadCreationTime : 25-06-2006 21:16:57
BasePriority : Normal


#:24 [launchapplication.exe]
FilePath : C:\Program Files\Nokia\Nokia PC Suite 6\
ProcessID : 268
ThreadCreationTime : 25-06-2006 21:17:00
BasePriority : Normal


#:25 [alg.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 544
ThreadCreationTime : 25-06-2006 21:17:04
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe

#:26 [datalayer.exe]
FilePath : C:\Program Files\Common Files\PCSuite\DataLayer\
ProcessID : 1276
ThreadCreationTime : 25-06-2006 21:17:06
BasePriority : Normal
FileVersion : 6, 50, 101, 3
ProductVersion : 6, 0
ProductName : Nokia PC Suite
CompanyName : Nokia Mobile Phones Ltd.
FileDescription : DataLayer 2.0 Module
InternalName : DataLayer 2.0
LegalCopyright : Copyright © 2005. Nokia. All rights reserved.
OriginalFilename : DataLayer.exe

#:27 [qttask.exe]
FilePath : C:\Program Files\QuickTime\
ProcessID : 2104
ThreadCreationTime : 25-06-2006 21:17:15
BasePriority : Normal
FileVersion : 7.0.4
ProductVersion : QuickTime 7.0.4
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
FileDescription : QuickTime Task
InternalName : QuickTime Task
LegalCopyright : Copyright Apple Computer, Inc. 1989-2006
OriginalFilename : QTTask.exe

#:28 [servic~1.exe]
FilePath : C:\PROGRA~1\COMMON~1\PCSuite\Services\
ProcessID : 2152
ThreadCreationTime : 25-06-2006 21:17:19
BasePriority : Normal
FileVersion : 6, 50, 28, 2
ProductVersion : 6.0
ProductName : Nokia Connectivity Library
CompanyName : Nokia.
FileDescription : ServiceLayer Module
InternalName : ServiceLayer
LegalCopyright : Copyright © 2002-2005 Nokia. All Rights Reserved.
OriginalFilename : ServiceLayer.exe

#:29 [mcvsshld.exe]
FilePath : C:\Program Files\McAfee.com\VSO\
ProcessID : 2156
ThreadCreationTime : 25-06-2006 21:17:19
BasePriority : Normal
FileVersion : 10, 0, 0, 22
ProductVersion : 10, 0, 0, 0
ProductName : McAfee VirusScan
CompanyName : McAfee, Inc.
FileDescription : McAfee VirusScan ActiveShield Resource
InternalName : McVsShld
LegalCopyright : Copyright © 2005 McAfee, Inc. All Rights Reserved.
OriginalFilename : McVsShld.exe
Comments : McAfee VirusScan ActiveShield Resource

#:30 [oasclnt.exe]
FilePath : C:\Program Files\McAfee.com\VSO\
ProcessID : 2228
ThreadCreationTime : 25-06-2006 21:17:20
BasePriority : Normal
FileVersion : 10, 0, 0, 24
ProductVersion : 10, 0, 0, 0
ProductName : McAfee VirusScan
CompanyName : McAfee, Inc.
FileDescription : McAfee VirusScan OAS Client
InternalName : OasClnt
LegalCopyright : Copyright © 2005 McAfee, Inc. All Rights Reserved.
OriginalFilename : OasClnt.exe
Comments : McAfee VirusScan OAS Client

#:31 [mcagent.exe]
FilePath : C:\PROGRA~1\mcafee.com\agent\
ProcessID : 2260
ThreadCreationTime : 25-06-2006 21:17:24
BasePriority : Normal
FileVersion : 6, 0, 0, 16
ProductVersion : 6, 0, 0, 0
ProductName : McAfee SecurityCenter
CompanyName : McAfee, Inc
FileDescription : McAfee SecurityCenter Agent
InternalName : mcagent
LegalCopyright : Copyright © 2005 McAfee, Inc.
OriginalFilename : mcagent.exe

#:32 [ituneshelper.exe]
FilePath : C:\Program Files\iTunes\
ProcessID : 2292
ThreadCreationTime : 25-06-2006 21:17:29
BasePriority : Normal
FileVersion : 6.0.4.2
ProductVersion : 6.0.4.2
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iTunesHelper Module
InternalName : iTunesHelper
LegalCopyright : © 2003-2006 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iTunesHelper.exe

#:33 [mcvsescn.exe]
FilePath : c:\progra~1\mcafee.com\vso\
ProcessID : 2384
ThreadCreationTime : 25-06-2006 21:17:43
BasePriority : Normal
FileVersion : 10, 0, 0, 20
ProductVersion : 10, 0, 0, 0
ProductName : McAfee VirusScan
CompanyName : McAfee, Inc.
FileDescription : McAfee VirusScan E-mail Scan Module
InternalName : mcvsescn
LegalCopyright : Copyright © 2005 McAfee, Inc. All Rights Reserved.
OriginalFilename : mcvsescn.EXE
Comments : McAfee VirusScan E-mail Scan Module

#:34 [ipodservice.exe]
FilePath : C:\Program Files\iPod\bin\
ProcessID : 2444
ThreadCreationTime : 25-06-2006 21:17:51
BasePriority : Normal
FileVersion : 6.0.4.2
ProductVersion : 6.0.4.2
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iPodService Module
InternalName : iPodService
LegalCopyright : © 2003-2006 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iPodService.exe

#:35 [ctfmon.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 2476
ThreadCreationTime : 25-06-2006 21:17:52
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE

#:36 [msmsgs.exe]
FilePath : C:\Program Files\Messenger\
ProcessID : 2584
ThreadCreationTime : 25-06-2006 21:17:59
BasePriority : Normal
FileVersion : 4.7.3001
ProductVersion : Version 4.7.3001
ProductName : Messenger
CompanyName : Microsoft Corporation
FileDescription : Windows Messenger
InternalName : msmsgs
LegalCopyright : Copyright © Microsoft Corporation 2004
LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
OriginalFilename : msmsgs.exe

#:37 [warez.exe]
FilePath : C:\Program Files\Warez P2P Client\
ProcessID : 2740
ThreadCreationTime : 25-06-2006 21:18:19
BasePriority : Normal
FileVersion : 2.9.5.3040
ProductVersion : 1.0.0.0

#:38 [easyshare.exe]
FilePath : C:\Program Files\Kodak\Kodak EasyShare software\bin\
ProcessID : 2776
ThreadCreationTime : 25-06-2006 21:18:35
BasePriority : Normal
FileVersion : 5, 0, 4, 125
ProductVersion : 4, 0, 0, 130
ProductName : Kodak EasyShare software
CompanyName : Eastman Kodak Company
FileDescription : Kodak EasyShare software
InternalName : EasyShare
LegalCopyright : Copyright © Eastman Kodak Company 2002
LegalTrademarks : EasyShare
OriginalFilename : EasyShare.exe

#:39 [kodak software updater.exe]
FilePath : C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\
ProcessID : 2844
ThreadCreationTime : 25-06-2006 21:18:53
BasePriority : Normal


#:40 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ProcessID : 3000
ThreadCreationTime : 25-06-2006 21:19:23
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : IEXPLORE.EXE

#:41 [mcvsftsn.exe]
FilePath : c:\progra~1\mcafee.com\vso\
ProcessID : 3092
ThreadCreationTime : 25-06-2006 21:19:55
BasePriority : Normal
FileVersion : 10, 0, 0, 19
ProductVersion : 10, 0, 0, 0
ProductName : McAfee VirusScan
CompanyName : McAfee, Inc.
FileDescription : McAfee VirusScan Instant Messenger Scan Module
InternalName : mcvsftsn
LegalCopyright : Copyright © 2005 McAfee, Inc. All Rights Reserved.
OriginalFilename : mcvsftsn.EXE
Comments : McAfee VirusScan Instant Messenger Scan Module

#:42 [adwarealert.exe]
FilePath : C:\Program Files\AdwareAlert\
ProcessID : 3420
ThreadCreationTime : 25-06-2006 21:21:31
BasePriority : Normal
FileVersion : 3.6.4.0
ProductVersion : 3.6.4.0
ProductName : AdwareAlert
CompanyName : AdwareAlert Company
FileDescription : Advanced Spyware Cleaner
InternalName : AdwareAlert.exe
LegalCopyright : AdwareAlert ©. All rights reserved.
OriginalFilename : AdwareAlert.exe

#:43 [ad-aware.exe]
FilePath : C:\PROGRA~1\Lavasoft\AD-AWA~1\
ProcessID : 3696
ThreadCreationTime : 25-06-2006 21:53:45
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved

Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 30


Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 30


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 30


Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


Tracking Cookie Object Recognized!
Type : IECache Entry
Data : matthew@statcounter[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:4
Value : Cookie:matthew@statcounter.com/
Expires : 20-06-2011 20:07:38
LastSync : Hits:4
UseCount : 0
Hits : 4

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : matthew@sextracker[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
Value : Cookie:matthew@sextracker.com/
Expires : 23-06-2006 14:21:46
LastSync : Hits:2
UseCount : 0
Hits : 2

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : matthew@clickbank[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:matthew@clickbank.net/
Expires : 18-12-2006 19:54:24
LastSync : Hits:1
UseCount : 0
Hits : 1

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : matthew@hc2.humanclick[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:4
Value : Cookie:matthew@hc2.humanclick.com/
Expires : 21-06-2007 22:01:04
LastSync : Hits:4
UseCount : 0
Hits : 4

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : matthew@counter7.sextracker[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:matthew@counter7.sextracker.com/
Expires : 23-06-2006 07:21:46
LastSync : Hits:1
UseCount : 0
Hits : 1

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : matthew@fastclick[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:14
Value : Cookie:matthew@fastclick.net/
Expires : 24-06-2008 22:22:14
LastSync : Hits:14
UseCount : 0
Hits : 14

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : matthew@doubleclick[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:4
Value : Cookie:matthew@doubleclick.net/
Expires : 20-06-2009 22:01:04
LastSync : Hits:4
UseCount : 0
Hits : 4

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : matthew@ads.pointroll[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:9
Value : Cookie:matthew@ads.pointroll.com/
Expires : 01-01-2010 01:00:00
LastSync : Hits:9
UseCount : 0
Hits : 9

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : matthew@server.iad.liveperson[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
Value : Cookie:matthew@server.iad.liveperson.net/
Expires : 21-06-2007 20:07:44
LastSync : Hits:3
UseCount : 0
Hits : 3

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : matthew@advertising[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:matthew@advertising.com/
Expires : 21-06-2011 14:19:48
LastSync : Hits:1
UseCount : 0
Hits : 1

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : matthew@hitbox[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:74
Value : Cookie:matthew@hitbox.com/
Expires : 22-06-2007 14:39:50
LastSync : Hits:74
UseCount : 0
Hits : 74

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : matthew@atdmt[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
Value : Cookie:matthew@atdmt.com/
Expires : 24-06-2011 01:00:00
LastSync : Hits:2
UseCount : 0
Hits : 2

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : matthew@tribalfusion[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:matthew@tribalfusion.com/
Expires : 01-01-2038 01:00:00
LastSync : Hits:1
UseCount : 0
Hits : 1

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : matthew@mediaplex[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
Value : Cookie:matthew@mediaplex.com/
Expires : 22-06-2009 01:00:00
LastSync : Hits:2
UseCount : 0
Hits : 2

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : matthew@counter1.sextracker[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:matthew@counter1.sextracker.com/
Expires : 23-06-2006 07:21:46
LastSync : Hits:1
UseCount : 0
Hits : 1

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : matthew@ehg-interlifeform.hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:37
Value : Cookie:matthew@ehg-interlifeform.hitbox.com/
Expires : 22-06-2007 14:39:50
LastSync : Hits:37
UseCount : 0
Hits : 37

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : matthew@www.maximumcash[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:matthew@www.maximumcash.com/
Expires : 24-06-2006 14:27:04
LastSync : Hits:1
UseCount : 0
Hits : 1

Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 17
Objects found so far: 47



Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@0[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@0[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@247realmedia[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@247realmedia[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@adrevolver[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@adrevolver[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@ads.addynamix[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@ads.addynamix[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@ads.pointroll[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@ads.pointroll[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@ads.tripod.lycos[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@ads.tripod.lycos[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@adserver.akqa[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@adserver.akqa[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@adserver.primelocation[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@adserver.primelocation[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@adserver.tibaco[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@adserver.tibaco[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@adtech[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@adtech[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@advertising[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@advertising[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@adviva[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@adviva[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@apmebf[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@apmebf[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@as-eu.falkag[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@as-eu.falkag[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@as1.falkag[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@as1.falkag[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@atdmt[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@atdmt[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@bfast[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@bfast[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@bluestreak[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@bluestreak[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@bravenet[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@bravenet[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@bs.serving-sys[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@bs.serving-sys[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@casalemedia[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@casalemedia[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@centrport[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@centrport[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@cgi-bin[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@cgi-bin[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@cgi-bin[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@cgi-bin[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@cgi-bin[3].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@cgi-bin[3].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@cgi-bin[5].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@cgi-bin[5].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@data.coremetrics[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@data.coremetrics[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@doubleclick[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@doubleclick[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@edge.ru4[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@edge.ru4[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@ehg-adidas.hitbox[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@ehg-adidas.hitbox[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@ehg-adidasus.hitbox[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@ehg-adidasus.hitbox[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@ehg-baa.hitbox[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@ehg-baa.hitbox[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@ehg-bbc.hitbox[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@ehg-bbc.hitbox[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@ehg-evesham.hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@ehg-evesham.hitbox[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@ehg-iwantoneofthose.hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@ehg-iwantoneofthose.hitbox[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@ehg-littlewoods.hitbox[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@ehg-littlewoods.hitbox[2].txt

#5 mattybrig

mattybrig

    Member

  • Members
  • PipPip
  • 14 posts

Posted 25 June 2006 - 11:51 PM

Continued:

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@ehg-logantod.hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@ehg-logantod.hitbox[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@ehg-micron.hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@ehg-micron.hitbox[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@ehg-nokiafin.hitbox[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@ehg-nokiafin.hitbox[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@ehg-superwarehouse.hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@ehg-superwarehouse.hitbox[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@ehg-usoc.hitbox[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@ehg-usoc.hitbox[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@ehg-wmc.hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@ehg-wmc.hitbox[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@ehg-xxolympicwintergames.hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@ehg-xxolympicwintergames.hitbox[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@estat[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@estat[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@fastclick[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@fastclick[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@fortunecity[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@fortunecity[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@hc2.humanclick[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@hc2.humanclick[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@hitbox[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@hotlog[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@hotlog[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@landing.domainsponsor[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@landing.domainsponsor[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@list[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@list[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@mediaplex[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@mediaplex[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@overture[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@overture[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@pacificpoker[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@pacificpoker[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@pacificpoker[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@pacificpoker[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@perf.overture[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@perf.overture[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@pr.valueclick[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@pr.valueclick[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@qksrv[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@qksrv[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@qsrch[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@qsrch[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@questionmarket[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@questionmarket[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@search200[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@search200[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@seeq[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@seeq[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@sel.as-eu.falkag[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@sel.as-eu.falkag[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@servedby.netshelter[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@servedby.netshelter[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@server.iad.liveperson[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@server.iad.liveperson[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@stat.onestat[1].txt
TAC Rating : 3
Category : Data Miner
Comment : www.searchtraffic.com
Value : C:\Documents and Settings\Ashley\Cookies\ashley@stat.onestat[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@statcounter[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@statcounter[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@stats1.clicktracks[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@stats1.clicktracks[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@statse.webtrendslive[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@statse.webtrendslive[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@tradedoubler[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@tradedoubler[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@trafficmp[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@trafficmp[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@tribalfusion[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@tribalfusion[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@tripod[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@tripod[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@valueclick[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@valueclick[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@valueclick[3].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@valueclick[3].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@web4.realtracker[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@web4.realtracker[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@weborama[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@weborama[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@www.intelli-tracker[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@www.intelli-tracker[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@xml.bravenetmedianetwork[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@xml.bravenetmedianetwork[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ashley@z1.adserver[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ashley\Cookies\ashley@z1.adserver[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@247realmedia[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@247realmedia[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@2o7[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@2o7[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@7search[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@7search[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@adrevolver[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@adrevolver[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@adtech[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@adtech[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@advertising[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@advertising[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@adviva[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@adviva[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@apmebf[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@apmebf[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@as-eu.falkag[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@as-eu.falkag[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@as1.falkag[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@as1.falkag[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@atdmt[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@atdmt[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@bfast[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@bfast[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@bluestreak[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@bluestreak[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@bravenet[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@bravenet[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@bs.serving-sys[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@bs.serving-sys[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@casalemedia[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@casalemedia[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@cgi-bin[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@cgi-bin[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@counter.hitslink[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@counter.hitslink[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@doubleclick[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@doubleclick[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@ehg-ordnancesurvey.hitbox[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@ehg-ordnancesurvey.hitbox[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@estat[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@estat[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@fastclick[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@fastclick[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@hc2.humanclick[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@hc2.humanclick[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@hg1.hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@hg1.hitbox[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@hitbox[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@media.fastclick[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@media.fastclick[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@mediaplex[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@mediaplex[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@overture[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@overture[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@pacificpoker[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@pacificpoker[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@pacificpoker[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@pacificpoker[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@perf.overture[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@perf.overture[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@qksrv[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@qksrv[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@questionmarket[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@questionmarket[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@realmedia[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@realmedia[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@search200[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@search200[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@serving-sys[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@serving-sys[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@statcounter[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@statcounter[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@statse.webtrendslive[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@statse.webtrendslive[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@tradedoubler[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@tradedoubler[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@trafficmp[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@trafficmp[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@tribalfusion[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@tribalfusion[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@valueclick[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@valueclick[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@weborama[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@weborama[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@www.clickedyclick[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@www.clickedyclick[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@xml.bravenetmedianetwork[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@xml.bravenetmedianetwork[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : clive@z1.adserver[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Clive\Cookies\clive@z1.adserver[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@247realmedia[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@247realmedia[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@2o7[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@2o7[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@ads.pointroll[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@ads.pointroll[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@adtech[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@adtech[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@advertising[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@advertising[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@adviva[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@adviva[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@apmebf[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@apmebf[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@banner.casinoking[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@banner.casinoking[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@banner.casinolasvegas[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@banner.casinolasvegas[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@bannerfarm.ace.advertising[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@bannerfarm.ace.advertising[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@bfast[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@bfast[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@bluestreak[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@bluestreak[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@bravenet[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@bravenet[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@casinoking[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@casinoking[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@casinolasvegas[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@casinolasvegas[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@cgi-bin[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@cgi-bin[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@cgi-bin[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@cgi-bin[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@cgi-bin[3].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@cgi-bin[3].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@cgi-bin[4].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@cgi-bin[4].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@edge.ru4[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@edge.ru4[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@ehg-adidas.hitbox[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@ehg-adidas.hitbox[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@ehg-flextech.hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@ehg-flextech.hitbox[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@ehg-logantod.hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@ehg-logantod.hitbox[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@ehg-thompson.hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@ehg-thompson.hitbox[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@ehg-wmc.hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@ehg-wmc.hitbox[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@ehg-yooxspa.hitbox[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@ehg-yooxspa.hitbox[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@etype.adbureau[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@etype.adbureau[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@hitbox[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@hitbox[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@inet-traffic[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@inet-traffic[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@landing.domainsponsor[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@landing.domainsponsor[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@mediaplex[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@mediaplex[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@overture[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@overture[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@pacificpoker[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@pacificpoker[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@pacificpoker[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@pacificpoker[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@perf.overture[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@perf.overture[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@qksrv[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@qksrv[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@qsrch[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@qsrch[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@questionmarket[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@questionmarket[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@realmedia[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@realmedia[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@server.iad.liveperson[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@server.iad.liveperson[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@stat.onestat[1].txt
TAC Rating : 3
Category : Data Miner
Comment : www.searchtraffic.com
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@stat.onestat[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@statcounter[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@statcounter[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@stats1.clicktracks[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@stats1.clicktracks[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@statse.webtrendslive[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@statse.webtrendslive[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@tradedoubler[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@tradedoubler[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@trafficmp[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@trafficmp[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@umstreet.adbureau[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@umstreet.adbureau[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@valueclick[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@valueclick[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@valueclick[3].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@valueclick[3].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@web2.realtracker[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@web2.realtracker[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@web4.realtracker[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@web4.realtracker[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@weborama[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@weborama[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@z1.adserver[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Cookies\debbie brignull@z1.adserver[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@247realmedia[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Local Settings\Temp\Cookies\debbie brignull@247realmedia[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@advertising[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Local Settings\Temp\Cookies\debbie brignull@advertising[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@apmebf[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Local Settings\Temp\Cookies\debbie brignull@apmebf[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@etype.adbureau[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Local Settings\Temp\Cookies\debbie brignull@etype.adbureau[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@mediaplex[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Local Settings\Temp\Cookies\debbie brignull@mediaplex[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@overture[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Local Settings\Temp\Cookies\debbie brignull@overture[1].txt

#6 mattybrig

mattybrig

    Member

  • Members
  • PipPip
  • 14 posts

Posted 25 June 2006 - 11:52 PM

continued:

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@qksrv[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Local Settings\Temp\Cookies\debbie brignull@qksrv[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@realmedia[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Local Settings\Temp\Cookies\debbie brignull@realmedia[2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@statcounter[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Local Settings\Temp\Cookies\debbie brignull@statcounter[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@tradedoubler[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Local Settings\Temp\Cookies\debbie brignull@tradedoubler[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@trafficmp[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Local Settings\Temp\Cookies\debbie brignull@trafficmp[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : debbie brignull@tripod[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Debbie Brignull\Local Settings\Temp\Cookies\debbie brignull@tripod[1].txt

SpywareNo Object Recognized!
Type : File
Data : Install[1].exe
TAC Rating : 10
Category : Misc
Comment :
Object : C:\Documents and Settings\Matthew\Local Settings\Temporary Internet Files\Content.IE5\WXEN4HUN\



Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 239


Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entries scanned.
New critical objects:0
Objects found so far: 239




Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

SpywareNo Object Recognized!
Type : RegData
Data : 2
TAC Rating : 10
Category : Misc
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\desktop\general
Value : WallpaperStyle
Data : 2

SpywareNo Object Recognized!
Type : RegData
Data : 2
TAC Rating : 10
Category : Misc
Comment :
Rootkey : HKEY_CURRENT_USER
Object : control panel\desktop
Value : WallpaperStyle
Data : 2

Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 2
Objects found so far: 241

23:39:56 Scan Complete

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:42:42.315
Objects scanned:189840
Objects identified:211
Objects ignored:0
New critical objects:211

#7 LS CalamityJane

LS CalamityJane

    Former Lavasoft Staff

  • Members
  • PipPipPip
  • 8814 posts

Posted 26 June 2006 - 02:15 AM

Looks like you have a number of infections ...we'll start with this fix:

Adaware does not detect that variant yet. It is not a virus but a Hijacker of the "Smitfraud" family that displays a fake notice that you are infected to fool you into buying some fraudlent antispyware program. Here is a free tool that should remove it for you

1. Download SmitfraudFix (by S!Ri) to your Desktop (Win2k/WinXP only!).
http://siri.urz.free...mitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

How to extract (decompress) zipped or compressed files
http://www.lvsonline...tut/index.shtml

Note : process.exe is part of the SmitFraudFix tool and is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky, Panda) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.


2. Reboot into Safe Mode
You can usually do this by restarting your computer and continually tapping F8 until a menu appears. Highlight Safe Mode and hit enter.

How to start the computer in Safe mode
http://service1.syma...src=sec_doc_nam

3. Once in Safe mode, open the SmitfraudFix folder and double-click smitfraudfix.cmd

Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually.

4. Once back into normal mode, please scan with HijackThis to produce a log. Post that log into your topic along with the other requested logs named below.

Logs needed in your next post are:

rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed

Fresh HijackThis log
Please do NOT send Private Messages to Staff or helpers to request assistance! We do not give a personal support via PM The way to request help is to post a NEW TOPIC in the appropriate forum.

Look for the *New Topic* Button near the top right when viewing the forums.

Here in the forums, replies are posted to topics only. Thank you for your understanding and cooperation!
Plus and Pro Ad-Aware users (only) may use the Support Center for personal assistance:
Support Center


Microsoft MVP/Windows - Security 2003-2009

#8 mattybrig

mattybrig

    Member

  • Members
  • PipPip
  • 14 posts

Posted 26 June 2006 - 11:23 AM

My MSN homepage is back, yeah! Seems sorted. Well here are those logs you wanted.

Logfile of HijackThis v1.99.1
Scan saved at 11:12:14, on 26/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\No-IP\DUC20.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Warez P2P Client\warez.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Matthew\Desktop\HijackThis.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Wanadoo - {4E7BD74F-2B8D-469E-A3F1-F068B59BBB2A} - C:\PROGRA~1\wanadoo1\wanadoo1.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {E5DDD23C-8CAC-E243-6FFB-5F2186919F92} - C:\DOCUME~1\Ashley\APPLIC~1\STARTM~1\tray stop.exe (file missing)
O3 - Toolbar: Wanadoo - {4E7BD74F-2B8D-469E-A3F1-F068B59BBB2A} - C:\PROGRA~1\wanadoo1\wanadoo1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [EPSON Stylus C46 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P32 "EPSON Stylus C46 Series (Copy 1)" /O6 "USB001" /M "Stylus C46"
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [SixthSend] C:\DOCUME~1\Matthew\APPLIC~1\SECOND~1\Copy mail.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [warez] "C:\Program Files\Warez P2P Client\warez.exe" -h
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Wanadoo Search - file://C:\Program Files\WANADOO1\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg...l_v1-0-3-30.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,26/mcgdmgr.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NoIPDUCService - Vitalwerks LLC - C:\Program Files\No-IP\DUC20.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\WinVNC.exe" -service (file missing)

#9 mattybrig

mattybrig

    Member

  • Members
  • PipPip
  • 14 posts

Posted 26 June 2006 - 11:24 AM

SmitFraudFix v2.65

Scan done at 11:03:09.18, 26/06/2006
Run from C:\Documents and Settings\Matthew\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{6af69c4d-420a-4c95-b34f-e4635f84f53b}"="forevouched"

[HKEY_CLASSES_ROOT\CLSID\{6af69c4d-420a-4c95-b34f-e4635f84f53b}\InProcServer32]
@="C:\WINDOWS\system32\viwpzla.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{6af69c4d-420a-4c95-b34f-e4635f84f53b}\InProcServer32]
@="C:\WINDOWS\system32\viwpzla.dll"


»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri

C:\WINDOWS\system32\viwpzla.dll -> Missing File


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\system32\atmclk.exe Deleted
C:\WINDOWS\system32\dcomcfg.exe Deleted
C:\WINDOWS\system32\hp???.tmp Deleted
C:\WINDOWS\system32\ld????.tmp Deleted
C:\WINDOWS\system32\ot.ico Deleted
C:\WINDOWS\system32\regperf.exe Deleted
C:\WINDOWS\system32\stdole3.tlb Deleted
C:\WINDOWS\system32\1024\ Deleted
C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url Deleted
C:\DOCUME~1\Matthew\FAVORI~1\Antivirus Test Online.url Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

#10 LS CalamityJane

LS CalamityJane

    Former Lavasoft Staff

  • Members
  • PipPipPip
  • 8814 posts

Posted 26 June 2006 - 07:18 PM

Warez P2P comes bundled with spyware. See here for clean and infected p2p programs and get one that does not come bundled with adware/spyware pests.
http://www.spywarein...o/articles/p2p/

Next, you have a LOP infection that Adaware doesn't recognize so I need copies of the files
Go here to upload the files as attachments
http://www.thespykil...x.php?board=1.0
Just press new topic (Make the subject: For CalamityJane from mattybrig at LS ),
fill in a short message & then press the browse button and then navigate to & select these files on your computer, If there is more than 1 file then press the more attachments button for each extra file and browse and select etc and then when all the files are listed in the windows press Post to upload the files

Files to upload:

C:\DOCUMENTS AND SETTINGS\Ashley\APPLICATION DATA\STARTM... (all files in the folder that start with those letters) Folder name may contain spaces, for example: Start M....

And this one (different user)
C:\DOCUMENTS AND SETTINGS\Matthew\APPLICATION DATA\SECOND (all files in the folder that start with those letters)

(Do not post HJT logs there as they will not get dealt with)

You DO NOT need to be a member to upload, anybody can upload the files

You will not see the files that have been uploaded as they only show to the authorized users who can download them. I will be able to collect the files from there and get them submitted for detection.
.......................................
Next:
Download this free tool called: smitRem
http://noahdfear.gee.../click.php?id=1
and save the file to your desktop.
Double click on the file to extract it to it's own folder on the desktop.

Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.
The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log in your next reply
.................
Next, make a copy of the following instructions, as this next step will need to be done in Safe mode

1. Reboot into Safe Mode
You can usually do this by restarting your computer and continually tapping F8 until a menu appears. Highlight Safe Mode and hit enter.

How to start the computer in Safe mode
http://service1.syma...src=sec_doc_nam

2. Once in Safe mode, open HijackThis and checkmark the following entries in the list, then press the *fix checked* button

O2 - BHO: (no name) - {E5DDD23C-8CAC-E243-6FFB-5F2186919F92} - C:\DOCUME~1\Ashley\APPLIC~1\STARTM~1\tray stop.exe (file missing)

O4 - HKCU\..\Run: [SixthSend] C:\DOCUME~1\Matthew\APPLIC~1\SECOND~1\Copy mail.exe

3. Close HijackThis, stay in safe mode and delete these two folders:

C:\DOCUMENTS AND SETTINGS\Ashley\APPLICATION DATA\STARTM... (delete folder)

C:\DOCUMENTS AND SETTINGS\Matthew\APPLICATION DATA\SECOND (delete folder)

4. Reboot back into normal mode, and scan once more With Hijakcthis to make a log and post the fresh log back here in your next reply.

5. Logs needed in your next reply are:

smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed.

fresh HijackThis log
Please do NOT send Private Messages to Staff or helpers to request assistance! We do not give a personal support via PM The way to request help is to post a NEW TOPIC in the appropriate forum.

Look for the *New Topic* Button near the top right when viewing the forums.

Here in the forums, replies are posted to topics only. Thank you for your understanding and cooperation!
Plus and Pro Ad-Aware users (only) may use the Support Center for personal assistance:
Support Center


Microsoft MVP/Windows - Security 2003-2009

#11 mattybrig

mattybrig

    Member

  • Members
  • PipPip
  • 14 posts

Posted 26 June 2006 - 08:59 PM

i cannot locate the files when i browse. can you guide me!

#12 LS CalamityJane

LS CalamityJane

    Former Lavasoft Staff

  • Members
  • PipPipPip
  • 8814 posts

Posted 26 June 2006 - 10:45 PM

Make sure your PC is configured to show hidden files
How to Show Hidden Files
http://www.xtra.co.n...1916458,00.html

Click Start.

Open My Computer.

Select the Tools menu and click Folder Options.

Select the View Tab.

Under the Hidden files and folders heading select Show hidden files and folders.

Uncheck the Hide protected operating system files (recommended) option.

Click Yes to confirm.

Click OK.

...................
If still not found, let's try this tool to make sure the folder exists:

download this tool called Get Long paths

http://www.castlecop.../Long_Paths.zip

Unzip/extract the vbs file from the zip file (Long_Path.vbs) and save the contents to your desktop

If you have scriptblocking enabled please *allow* when asked if it popups up.

Doubleclick on Long_Path.vbs and a box will popup asking for the path short name. Copy and paste this into that box:

C:\DOCUME~1\Ashley\APPLIC~1\STARTM~1 and press *ok*

The searchbox will pop up again asking for a short name path. Copy and paste this into the box:

C:\DOCUME~1\Matthew\APPLIC~1\SECOND~1 and press *ok*

Now press the *Cancel* button. A text document will popup in Notepad. Copy these results back here please :wub:
Please do NOT send Private Messages to Staff or helpers to request assistance! We do not give a personal support via PM The way to request help is to post a NEW TOPIC in the appropriate forum.

Look for the *New Topic* Button near the top right when viewing the forums.

Here in the forums, replies are posted to topics only. Thank you for your understanding and cooperation!
Plus and Pro Ad-Aware users (only) may use the Support Center for personal assistance:
Support Center


Microsoft MVP/Windows - Security 2003-2009

#13 mattybrig

mattybrig

    Member

  • Members
  • PipPip
  • 14 posts

Posted 27 June 2006 - 09:27 AM

files uploaded but unsure if they are correct. See message with attachments!

#14 mattybrig

mattybrig

    Member

  • Members
  • PipPip
  • 14 posts

Posted 27 June 2006 - 10:07 AM

Logfile of HijackThis v1.99.1
Scan saved at 10:04:35, on 27/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\No-IP\DUC20.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\system32\wuauclt.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Matthew\Desktop\HijackThis.exe
C:\Program Files\Kodak\Kodak Utilities\kodnotif.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Wanadoo - {4E7BD74F-2B8D-469E-A3F1-F068B59BBB2A} - C:\PROGRA~1\wanadoo1\wanadoo1.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Wanadoo - {4E7BD74F-2B8D-469E-A3F1-F068B59BBB2A} - C:\PROGRA~1\wanadoo1\wanadoo1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [EPSON Stylus C46 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P32 "EPSON Stylus C46 Series (Copy 1)" /O6 "USB001" /M "Stylus C46"
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Wanadoo Search - file://C:\Program Files\WANADOO1\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg...l_v1-0-3-30.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,26/mcgdmgr.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NoIPDUCService - Vitalwerks LLC - C:\Program Files\No-IP\DUC20.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\WinVNC.exe" -service (file missing)

#15 mattybrig

mattybrig

    Member

  • Members
  • PipPip
  • 14 posts

Posted 27 June 2006 - 10:08 AM

smitRem © log file
version 3.0

by noahdfear


Microsoft Windows XP [Version 5.1.2600]
"IE"="6.0000"
The current date is: 27/06/2006
The current time is: 9:34:45.03

Running from
C:\Documents and Settings\Matthew\Desktop\smitRem

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pre-run SharedTask Export

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright© 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!


checking for WinHound.com key


WinHound.com key not present!


checking for drsmartload2 key


drsmartload2 key not present!

spyaxe uninstaller NOT present
Winhound uninstaller NOT present
SpywareStrike uninstaller NOT present
AlfaCleaner uninstaller NOT present
SpyFalcon uninstaller NOT present
SpywareQuake uninstaller NOT present
SpywareSheriff uninstaller NOT present

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Existing Pre-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~

Online Security Guide.url
Security Troubleshooting.url


~~~ Favorites ~~~



~~~ system32 folder ~~~

amcompat.tlb
nscompat.tlb


~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 344 'explorer.exe'
Killing PID 344 'explorer.exe'

Starting registry repairs

Registry repairs complete

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SharedTask Export after registry fix

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright© 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Deleting files

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Remaining Post-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~


~~~ Wininet.dll ~~~

CLEAN! :huh:

#16 LS CalamityJane

LS CalamityJane

    Former Lavasoft Staff

  • Members
  • PipPipPip
  • 8814 posts

Posted 27 June 2006 - 02:53 PM

That's a clean log :huh:

Some final cleanup and prevention recomendations follow.

Navigate to C:\Windows\Temp
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

Navigate to C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

Clean out your Temporary Internet files.
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.


Now that your PC is clean, make sure all programs are running properly and then you'll need to reset your restore point in Windows XP.......why?

One of the best features of Windows ME or XP is the System Restore option, however if a malware infects a computer with this operating system it can be backed up in the System Restore folder. Therefore, clearing the restore points is necessary after malware removal.

To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account.

(winXP)

1. Turn off System Restore.
Go to Start and right-click on *My Computer*.
Click Properties.
Click the System Restore tab.
Put a Checkmark in the box next to "Turn off System Restore".
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
Go to Start and right-click on *My Computer*.
Click Properties.
Click the System Restore tab.
Remove the checkmark next to "Turn off System Restore".
Click Apply, and then click OK.

How to Turn On and Turn Off System Restore in Windows XP
http://support.micro...kb;en-us;310405

Next, I highly recommend you get some extra protection to prevent future infections. Here are some things you can do and some free programs to help :huh:.
How do I prevent Browser Hijacks and Spyware?
http://www.dslreports.com/faq/13620

I'm happy to see you have SP2 installed. That will address numerous security issues in your Operating System and IE
Make sure that you keep your Operating System and IE updated with the latest Critical Security Updates from Microsoft...they usually come out once a month, on the 2nd Tuesday of each month. This is the first step in malware prevention, as many nasties now take advantage of new exploits and if not patched, you are vulnerable!
Windows Update
http://update.micros...icrosoftupdate/

And see this link for instructions on how to configure the enhanced security features in SP2:
http://www.microsoft...xp/iesecxp.mspx

I also highly recommend to get the free tool, Microsoft Baseline Security Analyzer (MBSA) from Microsoft to analyze your PC security for prevention purposes.

MBSA Version 2.0 will scan for common system misconfigurations on Windows 2000, Windows XP, and Windows Server 2003 systems. This program will identify the system security weaknesses in your browser and operating system and provides easy instructions to correct them. This includes any missing critical Windows security updates, system vulnerabilities and your IE Browser security settings. Get the download here:
Microsoft Baseline Security Analyzer
http://www.microsoft...s/mbsahome.mspx
Choose MBSAsetup-EN.msi = (English Version) or the language appropriate for you.

Also visit this Free Online Scanner for PC Health and Safety
http://safety.live.c...-US/default.htm
and Microsoft Security At Home
http://www.microsoft...ty/default.mspx
for tips to Protect your Pc, Protect yourself and Protect your Family.
Please do NOT send Private Messages to Staff or helpers to request assistance! We do not give a personal support via PM The way to request help is to post a NEW TOPIC in the appropriate forum.

Look for the *New Topic* Button near the top right when viewing the forums.

Here in the forums, replies are posted to topics only. Thank you for your understanding and cooperation!
Plus and Pro Ad-Aware users (only) may use the Support Center for personal assistance:
Support Center


Microsoft MVP/Windows - Security 2003-2009

#17 mattybrig

mattybrig

    Member

  • Members
  • PipPip
  • 14 posts

Posted 27 June 2006 - 09:20 PM

cannot delete a file under the location C:\Documents and Settings\matthew\Local Settings\Temp. The file is called IadHide5.dll. A message says that the file may be write-protected or in current use etc. is this a problem!

#18 LS CalamityJane

LS CalamityJane

    Former Lavasoft Staff

  • Members
  • PipPipPip
  • 8814 posts

Posted 27 June 2006 - 11:39 PM

No, not a problem. There are always a couple that windows creates that are in use.
Please do NOT send Private Messages to Staff or helpers to request assistance! We do not give a personal support via PM The way to request help is to post a NEW TOPIC in the appropriate forum.

Look for the *New Topic* Button near the top right when viewing the forums.

Here in the forums, replies are posted to topics only. Thank you for your understanding and cooperation!
Plus and Pro Ad-Aware users (only) may use the Support Center for personal assistance:
Support Center


Microsoft MVP/Windows - Security 2003-2009

#19 mattybrig

mattybrig

    Member

  • Members
  • PipPip
  • 14 posts

Posted 28 June 2006 - 06:47 PM

good good! everything seems to be workin pretty good so thanks for the help it is much appreciated. You truly are awesome and i know where to come with future problems.
Thanks and Bye :)

PS. a new folder called "backups" has appeared on my desktop. It contains these files:

"backup-20060627-095545-836" and "backup-20060627-095545-998"

Can i delete this folder!

#20 LS CalamityJane

LS CalamityJane

    Former Lavasoft Staff

  • Members
  • PipPipPip
  • 8814 posts

Posted 28 June 2006 - 10:27 PM

Those backups belong to HijackThis. You should make a new folder (Name it HijackThis) on the Hard-drive to hold the HijackThis.exe and those backups in case they are needed should something not function correctly or if you find you "fixed" something legitimate by accident. Extract the HijackThis.exe from it's zip file into the folder and put those backup files in there with it. After a couple of weeks if everything is still running ok, you can delete the backup files.
Please do NOT send Private Messages to Staff or helpers to request assistance! We do not give a personal support via PM The way to request help is to post a NEW TOPIC in the appropriate forum.

Look for the *New Topic* Button near the top right when viewing the forums.

Here in the forums, replies are posted to topics only. Thank you for your understanding and cooperation!
Plus and Pro Ad-Aware users (only) may use the Support Center for personal assistance:
Support Center


Microsoft MVP/Windows - Security 2003-2009




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users