Steviebone

Members
  • Content Count

    31
  • Joined

  • Last visited

Posts posted by Steviebone

  1. Ok Im mad now... lol, I set spyware detector to run again every few hours for a while... the trojan zapchast resurfaced in a restore point file... to my knowledge I have not rebooted since the last scan... so this bugger is re-asserting itself somehow... in fact the only thing run inbetween scans was dss...

    c:\system volume information\_restore{2201e7e1-07c6-42bd-9a3d-8ec03be3ea1a}\rp479\a0107864.dll#@#2DBB00F5E171FF1101C350516116DCBC

    next to last one added.... this sucker was added minutes before dss was run while I was gone (I was not home at the time).

    In all my years of computing I have never run across such a persistant SOB. HELP! :blink:

  2. ok I ran the scan... can I upload this file to u rather than post the results to the world? There's some sensitive data there...

    Steve

    ---- edit -----

    ok you have a private message with instructions how to find the log...

  3. thanks,,,

    I will do as u instructed... one update... I ran an indepth scan using Spyware Detector... it found the Zapchast trojan and a keylogger again. I'm getting bounce backs from mail I havent sent so I'm pretty sure theres another dam mailbot on here again.

    :angry2:

    Funny, avast and nod32 dont pick any of this stuff up! :angry:

    Will get back to u... shortly

    Thanks again!

  4. Hello again... thanks for your previous help... no more rootkits that I know of, however, I have discovered that since disinfection I am having problems with Windows Firewall. After each reboot, some important entries are lost and Remote Assistance is enabled again. I have always had Remote Assistance disabled. In fact, even in services I have all the Remote entries disabled. The services are not being re-enabled, but the Remote Assistance checkbox in Windows Firewall IS being reset each time I reboot as well as most of the other exceptions that had already been set are lost altogether. This seems very nefarious to me.

    I ran combofix again, no rootkits found.

    Below is a new hijack log:

    Logfile of HijackThis v1.99.1

    Scan saved at 6:31:12 PM, on 6/3/2007

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\XP\System32\smss.exe

    C:\XP\system32\winlogon.exe

    C:\XP\system32\services.exe

    C:\XP\system32\lsass.exe

    C:\XP\system32\svchost.exe

    C:\XP\System32\svchost.exe

    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

    C:\Program Files\Alwil Software\Avast4\ashServ.exe

    C:\XP\system32\spoolsv.exe

    C:\XP\Explorer.EXE

    C:\Program Files\Acronis\BackupServer\backupserver.exe

    C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe

    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

    C:\Program Files\Eset\nod32krn.exe

    C:\XP\system32\nvsvc32.exe

    C:\XP\System32\svchost.exe

    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

    C:\Program Files\Eset\nod32kui.exe

    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    C:\Program Files\PTSync\PTSync.exe

    C:\Program Files\Acronis\TrueImageEnterpriseServer\TRUEIM~3.EXE

    c:\program files\vvengine\vvengine.exe

    C:\Program Files\SpywareDetector\SDSystemTray.exe

    C:\Program Files\SpywareDetector\SDService.exe

    C:\Ascend\SCM\scm.exe

    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

    C:\Program Files\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.americansingles.com/

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\keyscramblerIE.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Acrobat7\Acrobat\AcroIEFavClient.dll

    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Acrobat7\Acrobat\AcroIEFavClient.dll

    O3 - Toolbar: Cooxie - {DC99E960-6594-45e3-9D5D-141D825B8096} - C:\Program Files\Cooxie Toolbar\PrvcBand.dll

    O4 - HKLM\..\Run: [sDAutoLiveupdate] C:\Program Files\SpywareDetector\LiveUpdateSD.exe -AUTO

    O4 - HKLM\..\Run: [systemTraySD] C:\Program Files\SpywareDetector\SDSystemTray.exe -AUTO

    O4 - HKLM\..\RunOnce: [speedStartup] C:\Program Files\Speed Startup\speedstartup.exe runonce

    O4 - HKCU\..\Run: [speedStartup] C:\Program Files\Speed Startup\speedstartup.exe bootup

    O8 - Extra context menu item: Add to &Teleport - D:\TeleportUltra\teleport.htm

    O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

    O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

    O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    O8 - Extra context menu item: Convert to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\MsOffice\OFFICE11\EXCEL.EXE/3000

    O8 - Extra context menu item: Open with Scansoft PDF Converter 3.0 - res://D:\OmniPage15\PDFConverter3\IEShellExt.dll /100

    O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll

    O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

    O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll

    O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll

    O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\keyscramblerIE.dll

    O9 - Extra 'Tools' menuitem: &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\keyscramblerIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MsOffice\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1145986548799

    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

    O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) -

    O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} (Java Plug-in 1.5.0_09) -

    O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} (Java Plug-in 1.5.0_10) -

    O17 - HKLM\System\CCS\Services\Tcpip\..\{90F742E6-14BD-42BD-B353-7487933899E6}: NameServer = 66.254.6.2,66.254.1.2

    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll

    O20 - Winlogon Notify: SDNotify - C:\Program Files\SpywareDetector\SDNotify.dll

    O20 - Winlogon Notify: WgaLogon - C:\XP\SYSTEM32\WgaLogon.dll

    O20 - Winlogon Notify: WRNotifier - C:\XP\SYSTEM32\WRLogonNTF.dll

    O23 - Service: Acronis Remote Agent (AcronisAgent) - Acronis - C:\Program Files\Common Files\Acronis\Agent\agent.exe

    O23 - Service: Acronis Backup Server Service (AcronisBackupServerService) - Acronis - C:\Program Files\Acronis\BackupServer\backupserver.exe

    O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe

    O23 - Service: Arcana Notification Agent (adnotify) - Unknown owner - C:\Program Files\Arcana Development\Notification Agent\ADNotify.exe

    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

    O23 - Service: Arcana Scheduler - Arcana Development - C:\Program Files\Arcana Development\Arcana Scheduler\adscheduler.exe

    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

    O23 - Service: Acronis Group Server (GroupServer) - Acronis - C:\Program Files\Acronis\GroupServer\GroupServer.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\XP\system32\drivers\KodakCCS.exe

    O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe

    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe

    O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)

    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\XP\system32\nvsvc32.exe

    O23 - Service: O&O Defrag - O&O Software GmbH - C:\XP\system32\oodag.exe

    O23 - Service: ProgramCheckerPro (sassvc) - Unknown owner - C:\Program Files\Zenturi\ProgramChecker\sassvc.exe

    O23 - Service: SDService - Max Secure Software - C:\Program Files\SpywareDetector\SDService.exe

    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

    PS: I noticed the Windows messenger crap was back... I thought I had that removed... Id like to get rid of that... perhaps that is the culprit... only messaging installed is yahoo

    PS2: http://www.myitforum.com/articles/15/view.asp?id=7033 shows how to remove W messenger

  5. couldnt find a way to restrcit the scan to c: so I let it run until most of c & d were done and the stopped it. It found three threats, all of which were identifiable by me:

    pskill - I use it to kill local process from a batch file before running games

    ipscan - I use it to scan my network for open ports

    lzx32 - quarantined by combofix (this was the culprit and is zipped up inside the combo quarantine folder)

    couple of comments, couple of questions

    first, I think I'll hold on to all the handy tools I have used during this process, don't see any need to to trash them... any reason I shouldn't run combofix once in a while? It seemed to find things nothing else did. Which brings me to my next question...

    I have installed now on this computer: Avast, Nod32, AVG, Spyware Detector, SpybotS&D, Spysweeper, KeyScrambler, KeyloggerHunter. Avast and Nod32 have always worked together. So far, no problems running Spyware Detector at the same time either. The others I keep unloaded and run a scheduled scan with each of them periodically. When running scans from the others I have to disable everything else first (something I dont like to do since it requires me disconnecting the machine from the Internet for the duration).

    I'm wondering why Nod32 and AVAST failed to pick up the rootkit even though in the case of AVAST I used a boot time scan. And, BTW... I could never find a way to to do a boot time scan with Nod32, making it next to useless IMO. Wish I could get my money back on that one.

    So in your opinion, what is the best virus scanner to leave active? I really like avasts script scanner and the fact that u can turn on verbose display of real-time scans. This allowed me to spot a yahoo mail virus once that was running undetected by everything. Funny, Avast displayed the running script in the verbose window but failed to identify it as a virus. Nevertheless, has it not been for this feature of Avast I would never have spotted it so easily excepot through careful inspection of syslogs.

    More importantly, in trying to understand how the infection got there in the first place... I am VERY careful NEVER to open any emails that I don't already know the origin of... even tho all the emails are scanned on inbound by at least three scanners... the ISP's, Nod32 and Avast. And I never browse the Internet at large and keep the IE settings pretty tight, following the server2003 model.

    I use a hardware firewall which is set to reject EVERYTHING that is not explicitly allowed. And I regularly scan my network ports to make sure no holes open up. Of course, the Windows firewall, which also next to useless IMO, was left active. Should I run a software firewall in addition to the hardware one?

    Recently, tho, I allowed someone to plug their laptop into my hub for a few minutes. Out of curiosity, I ran a virus check for them. Despite their assurances the system was clean, I found 42 viruses almost immediately (lol). I immediately disconnected the machine...

    I had assumed that since the laptop was NOT configured to address my workgroup or domain and had no log on name and passwords that it could NOT communicate with the other computers on the network all of whom have guest access removed, etc. I know that none of the computers were visible to the laptops explorer, etc. However, I must now assume that I am overlooking something... could it be port 80? Could the laptop have infected the only XP machine on the subnet by channeling thru port 80? Seems unlikely since that computer had at least two virus scanners running at the time... As far as I can tell, all the other machines on the subnet are clean (they are all running 2003 server tho). Could the rootkit have proliferated to a neighboring machine without workgroup access and logon credientials?

    My new rule: absolutely NO outside machines anywhere on my subnet even for a second.

    The only other thing I can think of is that the infection was coincidental and resulted from something I loaded on to the machine that the virus scanners failed to pick up... after all they didn't see it when combofix did. This is the only machine I surf and get email from. That is an intentional design. All of the other computers on the subnet are used for specific purposes and are configured, in most cases, for little or no access to the outside world.

    I know this is more security related dialogue, but any comments or suggestions?

    Steve

  6. kapersky on-line was slower than dog... 1% complete after 6 hours... fook that... donwloaded the latest kaspesky but it wouldnt install as long as I had avast installed... sorry I already paid for avast and I like the script monitoring feature...

  7. oops, forgot I had run avenger where I had already killed those files:

    Logfile of The Avenger version 1, by Swandog46

    Running from registry key:

    \Registry\Machine\System\CurrentControlSet\Services\fjobmayi

    *******************

    Script file located at: \??\C:\Program Files\kroancfe.txt

    Script file opened successfully.

    Script file read successfully

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    File C:\XP\system32\71430B71.exe deleted successfully.

    File C:\chdir.bat not found!

    Deletion of file C:\chdir.bat failed!

    Could not process line:

    C:\chdir.bat

    Status: 0xc0000034

    File C:\XP\system32\drivers\k^nymapg.sys deleted successfully.

    File C:\xqsjepbn.bat deleted successfully.

    File C:\XP\system32\IE_Backup.reg deleted successfully.

    File C:\XP\system32\Windows_Backup.reg deleted successfully.

    File C:\XP\system32\startupBackup.reg deleted successfully.

    File C:\XP\system\SysSD.dll deleted successfully.

    File C:\XP\system32\CloseAll.exe deleted successfully.

    File C:\XP\system32\CheckDll.dll deleted successfully.

    File C:\XP\iun6002ev.exe deleted successfully.

    Completed script processing.

    *******************

    Finished! Terminate.

  8. ok, will do...

    the newtasks I created... I was just trying to get the task scheduler to work... wanted to see if I deleted a task and recreated it... but no luck... i have those tasks backed up so I am prolly about to delete all of them... at present they keep trying to run but just generate 'could not start' messages...

    will work the java over next...

    get back to u later today...

    and as always, thanks

  9. lol, I just saw the vfp start thing in the registry report which u had me fix with the reg file... that should stop that bad boy from resurfacing, thanks. Can't believe I didnt think to scan the report for mentions of vfp... :wacko:

    --- On second look, Y is the CD drive and those files are only on the CD... so something else was running first...

  10. ************************* Rustock.b-fix v. 1.01 -- By ejvindh *************************

    Tue 05/22/2007 13:56:46.09

    No Rustock.b-rootkits found

    ******************************* End of Logfile ********************************

  11. ok, second combofix scan with all protective programs off did better (see below). Perhaps the combo was picking up on something in spydetector?

    Anyway it found no lzx32 this time... curious....

    As for the task manager thingy: 0x80090016: Keysey does not exist. I have googled the hell out of that one and tried every fix I could find including deletion of the RSA files, etc. There are no registry entries that MS talks about. I did find a few people complaining about this problem after applying updates.

    "Staypuffer" - 2007-05-22 9:58:48 Service Pack 2

    ComboFix 07-05.20.9.V - Running from: "J:\Spywaredetector\"

    ((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-22 ))))))))))))))))))))))))))))))))))

    2007-05-21 23:15 <DIR> d-------- C:\ProcessExplorer

    2007-05-21 09:17 5,632 --a------ C:\XP\system32\71430B71.exe

    2007-05-21 08:57 <DIR> d-------- C:\RkUnhooker

    2007-05-21 01:33 3,968 --a------ C:\XP\system32\drivers\AvgArCln.sys

    2007-05-21 01:20 <DIR> d-------- C:\avenger

    2007-05-21 00:59 16 --a------ C:\chdir.bat

    2007-05-20 17:30 <DIR> d-------- C:\DOCUME~1\NETWOR~1.NTA\APPLIC~1\Webroot

    2007-05-20 17:18 3,968 --a------ C:\XP\system32\drivers\AvgAsCln.sys

    2007-05-20 14:53 60,416 --a------ C:\XP\system32\drivers\k^nymapg.sys

    2007-05-20 14:53 1,075 --a------ C:\xqsjepbn.bat

    2007-05-20 14:04 49,152 --a------ C:\XP\nircmd.exe

    2007-05-20 06:42 2,922 --a------ C:\XP\system32\IE_Backup.reg

    2007-05-20 06:42 2,846,854 --a------ C:\XP\system32\Windows_Backup.reg

    2007-05-20 06:42 2,588 --a------ C:\XP\system32\startupBackup.reg

    2007-05-20 02:27 123 --a------ C:\XP\system\SysSD.dll

    2007-05-20 02:26 63,192 --a------ C:\XP\system32\CloseAll.exe

    2007-05-20 02:26 270,336 --a------ C:\XP\system32\CheckDll.dll

    2007-05-20 02:26 1,019,904 --a------ C:\XP\system32\VchReg.dll

    2007-05-20 02:25 <DIR> d-------- C:\Program Files\SpywareDetector

    2007-05-19 18:15 22,080 --a------ C:\XP\system32\drivers\sshrmd.sys

    2007-05-19 18:15 21,056 --a------ C:\XP\system32\drivers\sskbfd.sys

    2007-05-19 18:15 20,544 --a------ C:\XP\system32\drivers\SSFS0509.sys

    2007-05-19 18:15 144,960 --a------ C:\XP\system32\drivers\ssidrv.sys

    2007-05-19 18:15 <DIR> d-------- C:\DOCUME~1\LOCALS~1.NTA\APPLIC~1\Webroot

    2007-05-19 18:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.XP\APPLIC~1\Webroot

    2007-05-19 18:08 164 --a------ C:\install.dat

    2007-05-19 18:08 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Webroot

    2007-05-18 11:43 <DIR> d--h----- C:\XP\system32\GroupPolicy

    2007-05-17 22:04 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Texture Maker

    2007-05-17 22:03 <DIR> d-------- C:\Program Files\Texture Maker

    2007-05-17 17:39 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Google

    2007-05-15 13:43 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.XP\APPLIC~1\Spybot - Search & Destroy

    2007-05-08 01:29 <DIR> d-------- C:\Program Files\Network Chemistry

    2007-05-08 01:17 <DIR> d-------- C:\Program Files\WinPcap

    2007-05-08 01:17 <DIR> d-------- C:\Program Files\Nmap

    2007-04-26 18:37 298,496 --a------ C:\XP\uninst.exe

    (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

    2007-05-22 14:08:10 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\dvdcss

    2007-05-21 05:50:19 -------- d-----w C:\Program Files\Common Files\Merge Modules

    2007-05-17 22:39:02 -------- d-----w C:\Program Files\Google

    2007-05-16 04:57:49 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\WeatherBug

    2007-05-15 18:38:06 -------- d-----w C:\Program Files\MySpace

    2007-05-07 17:28:32 -------- d-----w C:\Program Files\EPSON Print CD

    2007-05-07 13:39:36 298,104 ----a-w C:\XP\system32\imon.dll

    2007-05-07 13:39:34 512,096 ----a-w C:\XP\system32\drivers\amon.sys

    2007-05-07 13:39:33 15,424 ----a-w C:\XP\system32\drivers\nod32drv.sys

    2007-05-03 05:49:55 -------- d-----w C:\Program Files\LeapFTP

    2007-04-30 15:46:10 745,600 ----a-w C:\XP\system32\aswBoot.exe

    2007-04-30 15:41:55 85,952 ----a-w C:\XP\system32\drivers\aswmon.sys

    2007-04-30 15:41:42 94,552 ----a-w C:\XP\system32\drivers\aswmon2.sys

    2007-04-30 15:39:41 23,416 ----a-w C:\XP\system32\drivers\aswRdr.sys

    2007-04-30 15:38:51 43,176 ----a-w C:\XP\system32\drivers\aswTdi.sys

    2007-04-30 15:37:23 26,888 ----a-w C:\XP\system32\drivers\aavmker4.sys

    2007-04-30 15:35:28 95,872 ----a-w C:\XP\system32\AVASTSS.scr

    2007-04-30 08:55:32 -------- d-----w C:\Program Files\ViceVersa Pro 2

    2007-04-26 23:09:43 -------- d-----w C:\Program Files\IsoBuster

    2007-04-25 08:04:12 88,952 ----a-w C:\XP\system32\packet.dll

    2007-04-25 08:04:12 68,480 ----a-w C:\XP\system32\wanpacket.dll

    2007-04-25 08:04:12 42,000 ----a-w C:\XP\system32\drivers\npf.sys

    2007-04-25 08:04:12 240,496 ----a-w C:\XP\system32\wpcap.dll

    2007-04-21 03:30:35 -------- d-----w C:\Program Files\Speed Startup

    2007-04-20 03:28:54 1,040,384 ----a-w C:\XP\system32\libeay32.dll

    2007-04-20 03:27:57 196,608 ----a-w C:\XP\system32\ssleay32.dll

    2007-04-16 06:45:33 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\MySpace

    2007-04-09 04:37:55 -------- d-----w C:\Program Files\SlySoft

    2007-04-09 03:42:45 29,392 ----a-w C:\XP\system32\drivers\secdrv.sys

    2007-04-08 22:59:29 -------- d-----w C:\Program Files\PowerISO

    2007-04-06 21:14:04 542 ----a-w C:\hrlist.scr

    2007-04-06 20:32:08 371 ----a-w C:\getbilldirs.scr

    2007-04-06 20:31:54 371 ----a-w C:\gethbdirs.scr

    2007-04-06 20:28:28 139 ----a-w C:\tryftp.scr

    2007-04-06 05:46:37 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\Zeon

    2007-04-06 05:02:00 -------- d-----w C:\Program Files\G-Lock Software

    2007-04-05 15:31:07 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\G-Lock Software

    2007-04-04 10:33:04 -------- d-----w C:\Program Files\Yahoo!

    2007-03-18 17:28:30 5,885 ----a-w C:\XP\mozver.dat

    2007-03-17 13:43:01 292,864 ----a-w C:\XP\system32\winsrv.dll

    2007-03-15 19:35:33 -------- d-----w C:\Program Files\Tracker

    2007-03-15 10:52:51 -------- d-----w C:\Program Files\Registry Watch

    2007-03-15 10:14:59 720,896 ----a-w C:\XP\iun6002ev.exe

    2007-03-15 04:18:10 -------- d-----w C:\Program Files\Salive

    2007-03-15 04:17:28 -------- d--h--r C:\DOCUME~1\STAYPU~1\APPLIC~1\yahoo!

    2007-03-08 15:36:28 577,536 ----a-w C:\XP\system32\user32.dll

    2007-03-08 15:36:28 40,960 ----a-w C:\XP\system32\mf3216.dll

    2007-03-08 15:36:28 281,600 ----a-w C:\XP\system32\gdi32.dll

    2007-03-08 13:47:48 1,843,584 ----a-w C:\XP\system32\win32k.sys

    2007-03-08 04:59:59 -------- d-----w C:\Program Files\DirPrn

    2007-03-07 09:16:28 -------- d-----w C:\Program Files\'Net Monitor

    2007-03-07 09:13:15 -------- d-----w C:\Program Files\PTZone

    2007-03-07 09:10:26 -------- d-----w C:\Program Files\WinWatch

    2007-03-07 09:10:21 249,856 ------w C:\XP\Setup1.exe

    2007-03-07 09:10:09 -------- d-----w C:\Program Files\LanMon

    2007-03-07 09:09:11 73,216 ------w C:\XP\ST6UNST.EXE

    2007-02-28 08:59:01 26,000 ----a-w C:\XP\system32\E3TL.DLL

    2007-02-05 20:17:02 185,344 ----a-w C:\XP\system32\upnphost.dll

    (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll [2006-11-09 16:21]

    {AE7CD045-E861-484f-8273-0445EE161910}=D:\Acrobat7\Acrobat\AcroIEFavClient.dll [2005-09-24 00:41]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "NvCplDaemon"="C:\XP\system32\NvCpl.dll" [2005-10-28 16:06]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "SpeedStartup"="C:\Program Files\Speed Startup\speedstartup.exe" [2006-12-14 17:12]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]

    "SpeedStartup"=C:\Program Files\Speed Startup\speedstartup.exe runonce

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

    "{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"="D:\Internet\eudora\EuShlExt.dll" [2005-11-14 16:15]

    "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 09:13]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SDNotify]

    C:\Program Files\SpywareDetector\SDNotify.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

    Authentication Packages msv1_0 relog_ap

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService]

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Y]

    AutoRun\command- Y:\vfpstart.exe IE5="vfpstart.hta" IELess="vfpstart.htm"

    Contents of the 'Scheduled Tasks' folder

    2007-05-22 12:48:24 C:\XP\tasks\New Task 2.job

    2007-05-22 10:54:10 C:\XP\tasks\New Task.job

    2007-05-22 10:50:00 C:\XP\tasks\_viceversapr2_task_Bashful2Booby.job

    2007-05-22 11:30:00 C:\XP\tasks\_viceversapr2_task_batch.job

    2007-05-22 15:00:00 C:\XP\tasks\_viceversapr2_task_Bills.job

    2007-03-26 09:40:18 C:\XP\tasks\_viceversapr2_task_documents_and_settings.job

    2007-05-22 11:10:00 C:\XP\tasks\_viceversapr2_task_Eudora.job

    2007-05-22 15:00:00 C:\XP\tasks\_viceversapr2_task_hits prg to Tweetie D.job

    2007-05-22 06:00:00 C:\XP\tasks\_viceversapr2_task_HITSSOURCES.job

    2007-05-22 14:00:00 C:\XP\tasks\_viceversapr2_task_HITSVEN.job

    2007-05-22 13:15:00 C:\XP\tasks\_viceversapr2_task_Idisk.job

    2007-05-22 13:00:00 C:\XP\tasks\_viceversapr2_task_Links.job

    2007-03-26 09:33:37 C:\XP\tasks\_viceversapr2_task_madden.job

    2007-05-22 09:59:49 C:\XP\tasks\_viceversapr2_task_newag.job

    2007-05-22 10:30:00 C:\XP\tasks\_viceversapr2_task_OHITS.job

    2007-05-22 11:34:00 C:\XP\tasks\_viceversapr2_task_personal.job

    2007-05-22 14:00:00 C:\XP\tasks\_viceversapr2_task_ServersAlive.job

    2007-05-22 12:00:53 C:\XP\tasks\_viceversapr2_task_Steviebone.job

    2007-03-26 11:38:02 C:\XP\tasks\_viceversapr2_task_Torrents.job

    2007-05-22 14:15:00 C:\XP\tasks\_viceversapr2_task_txdot.job

    2007-05-22 11:20:00 C:\XP\tasks\_viceversapr2_task_visaversaprofiles.job

    ********************************************************************

    catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net

    Rootkit scan 2007-05-22 10:06:49

    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully

    hidden files: 0

    ********************************************************************

    Completion time: 2007-05-22 10:08:30

    C:\ComboFix-quarantined-files.txt ... 2007-05-22 10:08

    C:\ComboFix2.txt ... 2007-05-22 09:39

    C:\ComboFix3.txt ... 2007-05-20 14:38

    --- E O F ---

    2006-04-26 00:31	  775	--a------	C:\Qoobox\Quarantine\C\DOCUME~1\STAYPU~1\Desktop\Internet Explorer.lnk.vir
    2006-05-05 03:30 300 --a------ C:\Qoobox\Quarantine\C\Program Files\INSTALL.LOG.vir
    2007-05-20 10:22 77725 --a------ C:\Qoobox\Quarantine\catchme2007-05-20_135445.26.zip
    2007-05-22 09:27 500 --a------ C:\Qoobox\Quarantine\catchme.log


    Folder PATH listing for volume PrimaryC
    Volume serial number is 747C-9F49
    C:\QOOBOX
    \---Quarantine
    | catchme.log
    | catchme2007-05-20_135445.26.zip
    |
    +---C
    | +---DOCUME~1
    | | \---STAYPU~1
    | | \---Desktop
    | | Internet Explorer.lnk.vir
    | |
    | \---Program Files
    | INSTALL.LOG.vir
    |
    \---Registry_backups

  12. oh and btw, fwiw, somewhere in this whole process my task scheduler got broke... always gives me an 0x80090016 error... tried all the published fixes for it to no avail :( the taskscheduler can no longer see or set credentials...

  13. well chit...

    I ran combofix, but I forgot to turn off all my protective programs first. Immediately upon execution spydetector popped up window that said "Rustock.b successfully removed". Then towards the end of the scan another popup saying Trojan.Agent removed. Then combo said disinfecting and rebooting. After reboot, the following log was generated:

    "Staypuffer" - 2007-05-22 9:18:29 Service Pack 2

    ComboFix 07-05.20.9.V - Running from: "J:\Spywaredetector\"

    Rootkit driver lzx32 is present. A rootkit scan is required

    ((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-22 ))))))))))))))))))))))))))))))))))

    2007-05-21 23:15 <DIR> d-------- C:\ProcessExplorer

    2007-05-21 09:17 5,632 --a------ C:\XP\system32\71430B71.exe

    2007-05-21 08:57 <DIR> d-------- C:\RkUnhooker

    2007-05-21 01:33 3,968 --a------ C:\XP\system32\drivers\AvgArCln.sys

    2007-05-21 01:20 <DIR> d-------- C:\avenger

    2007-05-21 00:59 16 --a------ C:\chdir.bat

    2007-05-20 17:30 <DIR> d-------- C:\DOCUME~1\NETWOR~1.NTA\APPLIC~1\Webroot

    2007-05-20 17:18 3,968 --a------ C:\XP\system32\drivers\AvgAsCln.sys

    2007-05-20 14:53 60,416 --a------ C:\XP\system32\drivers\k^nymapg.sys

    2007-05-20 14:53 1,075 --a------ C:\xqsjepbn.bat

    2007-05-20 14:04 49,152 --a------ C:\XP\nircmd.exe

    2007-05-20 06:42 2,922 --a------ C:\XP\system32\IE_Backup.reg

    2007-05-20 06:42 2,846,854 --a------ C:\XP\system32\Windows_Backup.reg

    2007-05-20 06:42 2,588 --a------ C:\XP\system32\startupBackup.reg

    2007-05-20 02:27 123 --a------ C:\XP\system\SysSD.dll

    2007-05-20 02:26 63,192 --a------ C:\XP\system32\CloseAll.exe

    2007-05-20 02:26 270,336 --a------ C:\XP\system32\CheckDll.dll

    2007-05-20 02:26 1,019,904 --a------ C:\XP\system32\VchReg.dll

    2007-05-20 02:25 <DIR> d-------- C:\Program Files\SpywareDetector

    2007-05-19 18:15 22,080 --a------ C:\XP\system32\drivers\sshrmd.sys

    2007-05-19 18:15 21,056 --a------ C:\XP\system32\drivers\sskbfd.sys

    2007-05-19 18:15 20,544 --a------ C:\XP\system32\drivers\SSFS0509.sys

    2007-05-19 18:15 144,960 --a------ C:\XP\system32\drivers\ssidrv.sys

    2007-05-19 18:15 <DIR> d-------- C:\DOCUME~1\LOCALS~1.NTA\APPLIC~1\Webroot

    2007-05-19 18:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.XP\APPLIC~1\Webroot

    2007-05-19 18:08 164 --a------ C:\install.dat

    2007-05-19 18:08 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Webroot

    2007-05-18 11:43 <DIR> d--h----- C:\XP\system32\GroupPolicy

    2007-05-17 22:04 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Texture Maker

    2007-05-17 22:03 <DIR> d-------- C:\Program Files\Texture Maker

    2007-05-17 17:39 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Google

    2007-05-15 13:43 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.XP\APPLIC~1\Spybot - Search & Destroy

    2007-05-08 01:29 <DIR> d-------- C:\Program Files\Network Chemistry

    2007-05-08 01:17 <DIR> d-------- C:\Program Files\WinPcap

    2007-05-08 01:17 <DIR> d-------- C:\Program Files\Nmap

    2007-04-26 18:37 298,496 --a------ C:\XP\uninst.exe

    (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

    2007-05-22 14:08:10 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\dvdcss

    2007-05-21 05:50:19 -------- d-----w C:\Program Files\Common Files\Merge Modules

    2007-05-17 22:39:02 -------- d-----w C:\Program Files\Google

    2007-05-16 04:57:49 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\WeatherBug

    2007-05-15 18:38:06 -------- d-----w C:\Program Files\MySpace

    2007-05-07 17:28:32 -------- d-----w C:\Program Files\EPSON Print CD

    2007-05-07 13:39:36 298,104 ----a-w C:\XP\system32\imon.dll

    2007-05-07 13:39:34 512,096 ----a-w C:\XP\system32\drivers\amon.sys

    2007-05-07 13:39:33 15,424 ----a-w C:\XP\system32\drivers\nod32drv.sys

    2007-05-03 05:49:55 -------- d-----w C:\Program Files\LeapFTP

    2007-04-30 15:46:10 745,600 ----a-w C:\XP\system32\aswBoot.exe

    2007-04-30 15:41:55 85,952 ----a-w C:\XP\system32\drivers\aswmon.sys

    2007-04-30 15:41:42 94,552 ----a-w C:\XP\system32\drivers\aswmon2.sys

    2007-04-30 15:39:41 23,416 ----a-w C:\XP\system32\drivers\aswRdr.sys

    2007-04-30 15:38:51 43,176 ----a-w C:\XP\system32\drivers\aswTdi.sys

    2007-04-30 15:37:23 26,888 ----a-w C:\XP\system32\drivers\aavmker4.sys

    2007-04-30 15:35:28 95,872 ----a-w C:\XP\system32\AVASTSS.scr

    2007-04-30 08:55:32 -------- d-----w C:\Program Files\ViceVersa Pro 2

    2007-04-26 23:09:43 -------- d-----w C:\Program Files\IsoBuster

    2007-04-25 08:04:12 88,952 ----a-w C:\XP\system32\packet.dll

    2007-04-25 08:04:12 68,480 ----a-w C:\XP\system32\wanpacket.dll

    2007-04-25 08:04:12 42,000 ----a-w C:\XP\system32\drivers\npf.sys

    2007-04-25 08:04:12 240,496 ----a-w C:\XP\system32\wpcap.dll

    2007-04-21 03:30:35 -------- d-----w C:\Program Files\Speed Startup

    2007-04-20 03:28:54 1,040,384 ----a-w C:\XP\system32\libeay32.dll

    2007-04-20 03:27:57 196,608 ----a-w C:\XP\system32\ssleay32.dll

    2007-04-16 06:45:33 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\MySpace

    2007-04-09 04:37:55 -------- d-----w C:\Program Files\SlySoft

    2007-04-09 03:42:45 29,392 ----a-w C:\XP\system32\drivers\secdrv.sys

    2007-04-08 22:59:29 -------- d-----w C:\Program Files\PowerISO

    2007-04-06 21:14:04 542 ----a-w C:\hrlist.scr

    2007-04-06 20:32:08 371 ----a-w C:\getbilldirs.scr

    2007-04-06 20:31:54 371 ----a-w C:\gethbdirs.scr

    2007-04-06 20:28:28 139 ----a-w C:\tryftp.scr

    2007-04-06 05:46:37 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\Zeon

    2007-04-06 05:02:00 -------- d-----w C:\Program Files\G-Lock Software

    2007-04-05 15:31:07 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\G-Lock Software

    2007-04-04 10:33:04 -------- d-----w C:\Program Files\Yahoo!

    2007-03-18 17:28:30 5,885 ----a-w C:\XP\mozver.dat

    2007-03-17 13:43:01 292,864 ----a-w C:\XP\system32\winsrv.dll

    2007-03-15 19:35:33 -------- d-----w C:\Program Files\Tracker

    2007-03-15 10:52:51 -------- d-----w C:\Program Files\Registry Watch

    2007-03-15 10:14:59 720,896 ----a-w C:\XP\iun6002ev.exe

    2007-03-15 04:18:10 -------- d-----w C:\Program Files\Salive

    2007-03-15 04:17:28 -------- d--h--r C:\DOCUME~1\STAYPU~1\APPLIC~1\yahoo!

    2007-03-08 15:36:28 577,536 ----a-w C:\XP\system32\user32.dll

    2007-03-08 15:36:28 40,960 ----a-w C:\XP\system32\mf3216.dll

    2007-03-08 15:36:28 281,600 ----a-w C:\XP\system32\gdi32.dll

    2007-03-08 13:47:48 1,843,584 ----a-w C:\XP\system32\win32k.sys

    2007-03-08 04:59:59 -------- d-----w C:\Program Files\DirPrn

    2007-03-07 09:16:28 -------- d-----w C:\Program Files\'Net Monitor

    2007-03-07 09:13:15 -------- d-----w C:\Program Files\PTZone

    2007-03-07 09:10:26 -------- d-----w C:\Program Files\WinWatch

    2007-03-07 09:10:21 249,856 ------w C:\XP\Setup1.exe

    2007-03-07 09:10:09 -------- d-----w C:\Program Files\LanMon

    2007-03-07 09:09:11 73,216 ------w C:\XP\ST6UNST.EXE

    2007-02-28 08:59:01 26,000 ----a-w C:\XP\system32\E3TL.DLL

    2007-02-05 20:17:02 185,344 ----a-w C:\XP\system32\upnphost.dll

    (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll [2006-11-09 16:21]

    {AE7CD045-E861-484f-8273-0445EE161910}=D:\Acrobat7\Acrobat\AcroIEFavClient.dll [2005-09-24 00:41]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "NvCplDaemon"="C:\XP\system32\NvCpl.dll" [2005-10-28 16:06]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "SpeedStartup"="C:\Program Files\Speed Startup\speedstartup.exe" [2006-12-14 17:12]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]

    "SpeedStartup"=C:\Program Files\Speed Startup\speedstartup.exe runonce

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

    "{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"="D:\Internet\eudora\EuShlExt.dll" [2005-11-14 16:15]

    "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 09:13]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SDNotify]

    C:\Program Files\SpywareDetector\SDNotify.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

    Authentication Packages msv1_0 relog_ap

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService]

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Y]

    AutoRun\command- Y:\vfpstart.exe IE5="vfpstart.hta" IELess="vfpstart.htm"

    Contents of the 'Scheduled Tasks' folder

    2007-05-22 12:48:24 C:\XP\tasks\New Task 2.job

    2007-05-22 10:54:10 C:\XP\tasks\New Task.job

    2007-05-22 10:50:00 C:\XP\tasks\_viceversapr2_task_Bashful2Booby.job

    2007-05-22 11:30:00 C:\XP\tasks\_viceversapr2_task_batch.job

    2007-05-22 13:30:00 C:\XP\tasks\_viceversapr2_task_Bills.job

    2007-03-26 09:40:18 C:\XP\tasks\_viceversapr2_task_documents_and_settings.job

    2007-05-22 11:10:00 C:\XP\tasks\_viceversapr2_task_Eudora.job

    2007-05-22 14:00:00 C:\XP\tasks\_viceversapr2_task_hits prg to Tweetie D.job

    2007-05-22 06:00:00 C:\XP\tasks\_viceversapr2_task_HITSSOURCES.job

    2007-05-22 14:00:00 C:\XP\tasks\_viceversapr2_task_HITSVEN.job

    2007-05-22 13:15:00 C:\XP\tasks\_viceversapr2_task_Idisk.job

    2007-05-22 13:00:00 C:\XP\tasks\_viceversapr2_task_Links.job

    2007-03-26 09:33:37 C:\XP\tasks\_viceversapr2_task_madden.job

    2007-05-22 09:59:49 C:\XP\tasks\_viceversapr2_task_newag.job

    2007-05-22 10:30:00 C:\XP\tasks\_viceversapr2_task_OHITS.job

    2007-05-22 11:34:00 C:\XP\tasks\_viceversapr2_task_personal.job

    2007-05-22 14:00:00 C:\XP\tasks\_viceversapr2_task_ServersAlive.job

    2007-05-22 12:00:53 C:\XP\tasks\_viceversapr2_task_Steviebone.job

    2007-03-26 11:38:02 C:\XP\tasks\_viceversapr2_task_Torrents.job

    2007-05-22 14:15:00 C:\XP\tasks\_viceversapr2_task_txdot.job

    2007-05-22 11:20:00 C:\XP\tasks\_viceversapr2_task_visaversaprofiles.job

    ********************************************************************

    catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net

    Rootkit scan 2007-05-22 09:31:21

    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully

    hidden files: 0

    ********************************************************************

    Completion time: 2007-05-22 9:39:30 - machine was rebooted

    C:\ComboFix-quarantined-files.txt ... 2007-05-22 09:39

    C:\ComboFix2.txt ... 2007-05-20 14:38

    C:\ComboFix3.txt ... 2007-05-20 14:04

    --- E O F ---

    here is the quarantine log:

    2006-04-26 00:31	  775	--a------	C:\Qoobox\Quarantine\C\DOCUME~1\STAYPU~1\Desktop\Internet Explorer.lnk.vir
    2006-05-05 03:30 300 --a------ C:\Qoobox\Quarantine\C\Program Files\INSTALL.LOG.vir
    2007-05-20 10:22 77725 --a------ C:\Qoobox\Quarantine\catchme2007-05-20_135445.26.zip
    2007-05-22 09:27 500 --a------ C:\Qoobox\Quarantine\catchme.log


    Folder PATH listing for volume PrimaryC
    Volume serial number is 747C-9F49
    C:\QOOBOX
    \---Quarantine
    | catchme.log
    | catchme2007-05-20_135445.26.zip
    |
    +---C
    | +---DOCUME~1
    | | \---STAYPU~1
    | | \---Desktop
    | | Internet Explorer.lnk.vir
    | |
    | \---Program Files
    | INSTALL.LOG.vir
    |
    \---Registry_backups

    I'm guessing I need to run another scan with the HIPS off?

  14. file uploaded... will post combofix log shortly...

    sysinternals yes... great replacement for task manager... still wondering why the USB interuupts were triggering with no disk access but then I think USB drives are polled... one reason why they stink...

    btw, u been plenty of help, thanks

    You been (at least) a half a step ahead of me the whole way....Process Explorer (the one from SysInternals ??) was my next recommendation to you.

    All of your scan look good w/ possibly one exception. I'd like you to upload one file or me to look at please.

    Please go here to upload a suspicious file for analysis.

    • Enter your username from this forum
    • Copy and paste the link to this thread
    • Browse for this filename: C:\XP\system32\DRIVERS\EXPORTIT.SYS
    • In the comments, please mention that I asked you to upload this file
    • Click on Send File

    The ONLY other references I find to it are a Kodak file and it's allways in a Kodak sub folder..Just like to look at it and make sure.

    Jst keep an eye on your resources (Doesn't really seem I need to tell YOU that tho ;) )

    If you would give one final (?) Combofix log and let me have a look at that file hopefully we can put an end to this..

    Sorry I wasn't timely enough to be of more assistance to you in this..but it seems you REALLY had it pretty well handled all along.

  15. ok I think I fugured it out... I downloaded a program called process explorer which is more detailed than task manager (of course everything Windows has built in sucks compared to third party alternatives!). This program broke the activity down much better. The spikes were coming from hardware interrupts. Hardware interrupts? Yep. It was all the USB drives. I disconnected the USB drives and wahla... the interrupt load went down as did the overall activity which now hovers between 0-4%... acceptable if not perfect.

    I'm hoping the system is now clean. Let me know if you see anything else in the logs that appears suspicous... I never liked USB drives anyway... :blink:

    I suppose there's still the small possibility that the rogue program resided on one of the drives and was running from there which was causing the interrupts.... :wacko:

  16. Backlight didn't find anything.

    BTW, I have 8 other machines in here including some servers. Even with apps running on them most of them idle at 0-2% only spiking when an app does something (such as a web hit). Even then the spike is small and non-repetitive.

    The activity here is repetitive and continuous... I'm pretty sure there's still a rogue process running somewhere....

  17. ok thanks for all ur help..

    a couple of notes, I finally let the installer go... whatever it did it did and has not come back the last few reboots

    the rootkit program runs the hidden file scan but crashes near the end every time... Ive checked the disk for errors but nada... at the point only one file is listed in the window... to the best of my knowledege no log is ever written for that function, the other three logs are copied below..

    As for resource useage, in safe mode of course the task manager looks right. I disabled ALL of the programs however for these tests, following the instructions in the page you referenced AND going to startup controller and disabling all of them... I then checked on reboot and none of the programs had loaded. Even still, with NONE of those programs loaded the activity remains... including constant memory allocation changes... again task manager only indicates system idle at 98-99% even though no applications are opne there doesnt appear to be anything else running.

    I will download backlight next and post the results.

    Here are the other logs:

    RkUnhooker report generator v0.6

    ==============================================

    Rootkit Unhooker kernel version: 3.31.150.420

    ==============================================

    Windows Major Version: 5

    Windows Minor Version: 1

    Windows Build Number: 2600

    ==============================================

    Process: System

    Process Id: 4

    EPROCESS Address: 0x82FCA490

    Process: C:\XP\system32\nvsvc32.exe

    Process Id: 288

    EPROCESS Address: 0x82487890

    Process: C:\XP\system32\smss.exe

    Process Id: 532

    EPROCESS Address: 0x82494020

    Process: C:\XP\system32\csrss.exe

    Process Id: 648

    EPROCESS Address: 0x8217A360

    Process: C:\XP\system32\winlogon.exe

    Process Id: 676

    EPROCESS Address: 0x822EEBC8

    Process: C:\XP\system32\services.exe

    Process Id: 720

    EPROCESS Address: 0x8213CC88

    Process: C:\Program Files\Acronis\TrueImageEnterpriseServer\TRUEIM~3.EXE

    Process Id: 724

    EPROCESS Address: 0x81E6ADA0

    Process: C:\XP\system32\lsass.exe

    Process Id: 732

    EPROCESS Address: 0x82169A18

    Process: C:\XP\system32\svchost.exe

    Process Id: 884

    EPROCESS Address: 0x82113460

    Process: C:\XP\system32\svchost.exe

    Process Id: 972

    EPROCESS Address: 0x820E1020

    Process: C:\XP\system32\svchost.exe

    Process Id: 1028

    EPROCESS Address: 0x820CE300

    Process: C:\Program Files\SpywareDetector\SDService.exe

    Process Id: 1076

    EPROCESS Address: 0x824D5AC8

    Process: C:\XP\system32\svchost.exe

    Process Id: 1088

    EPROCESS Address: 0x820DBB50

    Process: C:\XP\system32\svchost.exe

    Process Id: 1132

    EPROCESS Address: 0x82492980

    Process: C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

    Process Id: 1148

    EPROCESS Address: 0x820DC8E0

    Process: C:\Program Files\Alwil Software\Avast4\ashServ.exe

    Process Id: 1204

    EPROCESS Address: 0x820CB8E0

    Process: C:\XP\system32\spoolsv.exe

    Process Id: 1408

    EPROCESS Address: 0x82054B30

    Process: C:\Program Files\Common Files\Acronis\Agent\agent.exe

    Process Id: 1524

    EPROCESS Address: 0x8202BDA0

    Process: C:\Program Files\Acronis\BackupServer\backupserver.exe

    Process Id: 1540

    EPROCESS Address: 0x82017DA0

    Process: C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe

    Process Id: 1572

    EPROCESS Address: 0x82060350

    Process: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

    Process Id: 1608

    EPROCESS Address: 0x8208C020

    Process: C:\Program Files\PTSync\PTSync.exe

    Process Id: 1616

    EPROCESS Address: 0x81EAB020

    Process: C:\XP\system32\svchost.exe

    Process Id: 1620

    EPROCESS Address: 0x8204CDA0

    Process: C:\Program Files\Acronis\GroupServer\GroupServer.exe

    Process Id: 1704

    EPROCESS Address: 0x81FEE5B0

    Process: C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe

    Process Id: 1780

    EPROCESS Address: 0x81F9DDA0

    Process: C:\XP\system32\wdfmgr.exe

    Process Id: 1996

    EPROCESS Address: 0x81FE6890

    Process: C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

    Process Id: 2120

    EPROCESS Address: 0x821B0890

    Process: C:\XP\system32\taskmgr.exe

    Process Id: 2412

    EPROCESS Address: 0xFE03F608

    Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

    Process Id: 2436

    EPROCESS Address: 0x8214C930

    Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

    Process Id: 2468

    EPROCESS Address: 0x82E68020

    Process: C:\Program Files\Acronis\TrueImageEnterpriseServer\TIMOUN~1.EXE

    Process Id: 2484

    EPROCESS Address: 0xFDA9B890

    Process: C:\XP\system32\alg.exe

    Process Id: 2712

    EPROCESS Address: 0x81EC7890

    Process: C:\XP\system32\wuauclt.exe

    Process Id: 2888

    EPROCESS Address: 0x82E54020

    Process: C:\RkUnhooker\oAi7c8OoI7xio.exe

    Process Id: 3028

    EPROCESS Address: 0xFCFC95B0

    Process: C:\XP\explorer.exe

    Process Id: 3852

    EPROCESS Address: 0x81E27DA0

    ---------------------

    RkUnhooker report generator v0.6

    ==============================================

    Rootkit Unhooker kernel version: 3.31.150.420

    ==============================================

    Windows Major Version: 5

    Windows Minor Version: 1

    Windows Build Number: 2600

    ==============================================

    Driver:

    Address: 0xF853D000

    Size: 98304 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82F6F278

    Size: 3464 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82DC1B78

    Size: 1160 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82D49008

    Size: 4088 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82E775C8

    Size: 2616 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82985D68

    Size: 664 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82985C40

    Size: 960 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82985B18

    Size: 1256 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82C387B0

    Size: 2128 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82C38688

    Size: 2424 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82C38560

    Size: 2720 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82C38438

    Size: 3016 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82C38310

    Size: 3312 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82C381E8

    Size: 3608 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82C379A0

    Size: 1632 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82C37888

    Size: 1912 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82C37760

    Size: 2208 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82C37638

    Size: 2504 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82C37510

    Size: 2800 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82C373E8

    Size: 3096 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82C372C0

    Size: 3392 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x829AC810

    Size: 2032 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x829AC6E8

    Size: 2328 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x829AC5C0

    Size: 2624 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x829AC498

    Size: 2920 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x829AC370

    Size: 3216 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x829AC248

    Size: 3512 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x829ABDA0

    Size: 608 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82AE81A0

    Size: 3680 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x824D0820

    Size: 2016 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x824F52E8

    Size: 3352 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82B9EFA8

    Size: 88 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82B9EF30

    Size: 208 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x8245C750

    Size: 2224 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x820AEBD0

    Size: 1072 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x824D4370

    Size: 3216 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x829929E8

    Size: 1560 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82DB3430

    Size: 3024 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x82AF17E0

    Size: 2080 bytes

    Driver: ?_unknown_code_page_?

    Address: 0x8245E1A0

    Size: 3680 bytes

    Driver: a347bus.sys

    Address: 0xF862D000

    Size: 163840 bytes

    Driver: a347scsi.sys

    Address: 0xF8B80000

    Size: 8192 bytes

    Driver: C:\XP\System32\Drivers\Aavmker4.SYS

    Address: 0xF8A76000

    Size: 20480 bytes

    Driver: ACPI.sys

    Address: 0xF85FF000

    Size: 188416 bytes

    Driver: ACPI_HAL

    Address: 0x806EC000

    Size: 81280 bytes

    Driver: C:\XP\system32\drivers\aec.sys

    Address: 0xB92B8000

    Size: 143360 bytes

    Driver: C:\XP\system32\drivers\Afc.sys

    Address: 0xF8A5E000

    Size: 32768 bytes

    Driver: C:\XP\System32\drivers\afd.sys

    Address: 0xF67B8000

    Size: 139264 bytes

    Driver: C:\XP\System32\DRIVERS\amdk7.sys

    Address: 0xF8726000

    Size: 40960 bytes

    Driver: C:\XP\system32\drivers\amon.sys

    Address: 0xB9892000

    Size: 503808 bytes

    Driver: C:\XP\System32\Drivers\AnyDVD.sys

    Address: 0xF8786000

    Size: 36864 bytes

    Driver: C:\XP\System32\Drivers\Asapi.SYS

    Address: 0xF8936000

    Size: 32768 bytes

    Driver: C:\XP\System32\drivers\aspi32.sys

    Address: 0xF669E000

    Size: 20480 bytes

    Driver: C:\XP\System32\Drivers\aswMon2.SYS

    Address: 0xB9B92000

    Size: 90112 bytes

    Driver: C:\XP\System32\Drivers\aswRdr.SYS

    Address: 0xB9564000

    Size: 16384 bytes

    Driver: C:\XP\System32\Drivers\aswTdi.SYS

    Address: 0xF8886000

    Size: 36864 bytes

    Driver: C:\XP\System32\DRIVERS\audstub.sys

    Address: 0xF8CBB000

    Size: 4096 bytes

    Driver: C:\XP\System32\DRIVERS\AvgArCln.sys

    Address: 0xF8D0F000

    Size: 4096 bytes

    Driver: avgarkt.sys

    Address: 0xF8B7A000

    Size: 8192 bytes

    Driver: C:\XP\System32\DRIVERS\AvgAsCln.sys

    Address: 0xF8D19000

    Size: 4096 bytes

    Driver: C:\XP\System32\Drivers\Beep.SYS

    Address: 0xF8B9C000

    Size: 8192 bytes

    Driver: C:\XP\system32\BOOTVID.dll

    Address: 0xF8A86000

    Size: 12288 bytes

    Driver: C:\XP\System32\Drivers\Cdfs.SYS

    Address: 0xF7BC8000

    Size: 65536 bytes

    Driver: C:\XP\System32\DRIVERS\cdrom.sys

    Address: 0xF8796000

    Size: 53248 bytes

    Driver: C:\XP\System32\DRIVERS\CLASSPNP.SYS

    Address: 0xF86E6000

    Size: 53248 bytes

    Driver: C:\XP\system32\drivers\cmaudio.sys

    Address: 0xF7F05000

    Size: 380928 bytes

    Driver: C:\XP\system32\DRIVERS\ctoss2k.sys

    Address: 0xF7D17000

    Size: 196608 bytes

    Driver: C:\XP\system32\DRIVERS\ctsfm2k.sys

    Address: 0xF7C2D000

    Size: 155648 bytes

    Driver: C:\XP\system32\DRIVERS\DcCam.sys

    Address: 0xF8846000

    Size: 36864 bytes

    Driver: C:\XP\system32\drivers\dcfs2k.sys

    Address: 0xF6168000

    Size: 40960 bytes

    Driver: disk.sys

    Address: 0xF86D6000

    Size: 36864 bytes

    Driver: C:\XP\System32\drivers\dmboot.sys

    Address: 0xF7C53000

    Size: 802816 bytes

    Driver: dmio.sys

    Address: 0xF8555000

    Size: 155648 bytes

    Driver: dmload.sys

    Address: 0xF8B7E000

    Size: 8192 bytes

    Driver: C:\XP\system32\drivers\DMusic.sys

    Address: 0xB9648000

    Size: 53248 bytes

    Driver: C:\XP\system32\drivers\drmk.sys

    Address: 0xF8736000

    Size: 61440 bytes

    Driver: C:\XP\system32\drivers\drmkaud.sys

    Address: 0xF8D88000

    Size: 4096 bytes

    Driver: C:\XP\System32\Drivers\dump_atapi.sys

    Address: 0xF60C8000

    Size: 98304 bytes

    Driver: C:\XP\System32\Drivers\dump_WMILIB.SYS

    Address: 0xF8BC4000

    Size: 8192 bytes

    Driver: C:\XP\System32\drivers\Dxapi.sys

    Address: 0xF66F2000

    Size: 12288 bytes

    Driver: C:\XP\System32\drivers\dxg.sys

    Address: 0xBF000000

    Size: 73728 bytes

    Driver: C:\XP\System32\drivers\dxgthk.sys

    Address: 0xF8CD1000

    Size: 4096 bytes

    Driver: C:\XP\System32\DRIVERS\el90xbc5.sys

    Address: 0xF7C1C000

    Size: 69632 bytes

    Driver: C:\XP\System32\Drivers\ElbyCDFL.sys

    Address: 0xF8A56000

    Size: 28672 bytes

    Driver: C:\XP\System32\Drivers\ElbyCDIO.sys

    Address: 0xF8BC2000

    Size: 8192 bytes

    Driver: C:\XP\System32\Drivers\ElbyDelay.sys

    Address: 0xF8B84000

    Size: 8192 bytes

    Driver: C:\XP\system32\DRIVERS\EXPORTIT.SYS

    Address: 0xF6976000

    Size: 155648 bytes

    Driver: C:\XP\System32\DRIVERS\fdc.sys

    Address: 0xF8A36000

    Size: 28672 bytes

    Driver: C:\XP\System32\Drivers\Fips.SYS

    Address: 0xF88C6000

    Size: 36864 bytes

    Driver: C:\XP\System32\DRIVERS\flpydisk.sys

    Address: 0xF89A6000

    Size: 20480 bytes

    Driver: fltmgr.sys

    Address: 0xF8505000

    Size: 131072 bytes

    Driver: C:\XP\System32\Drivers\Fs_Rec.SYS

    Address: 0xF8B96000

    Size: 8192 bytes

    Driver: ftdisk.sys

    Address: 0xF857B000

    Size: 126976 bytes

    Driver: C:\XP\system32\DRIVERS\gameenum.sys

    Address: 0xF8365000

    Size: 12288 bytes

    Driver: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys

    Address: 0xF8D80000

    Size: 4096 bytes

    Driver: C:\XP\system32\hal.dll

    Address: 0x806EC000

    Size: 81280 bytes

    Driver: C:\XP\System32\Drivers\HIDCLASS.SYS

    Address: 0xF8866000

    Size: 36864 bytes

    Driver: C:\XP\system32\DRIVERS\HIDPARSE.SYS

    Address: 0xF89DE000

    Size: 28672 bytes

    Driver: hpt3xx.sys

    Address: 0xF86C6000

    Size: 45056 bytes

    Driver: C:\XP\System32\Drivers\HTTP.sys

    Address: 0xB9014000

    Size: 266240 bytes

    Driver: C:\XP\System32\DRIVERS\i8042prt.sys

    Address: 0xF8756000

    Size: 53248 bytes

    Driver: C:\XP\system32\DRIVERS\imapi.sys

    Address: 0xF8776000

    Size: 45056 bytes

    Driver: C:\XP\System32\DRIVERS\ipnat.sys

    Address: 0xF6802000

    Size: 135168 bytes

    Driver: C:\XP\System32\DRIVERS\ipsec.sys

    Address: 0xF687B000

    Size: 77824 bytes

    Driver: isapnp.sys

    Address: 0xF8676000

    Size: 36864 bytes

    Driver: C:\XP\system32\drivers\iviaspi.sys

    Address: 0xF8A6E000

    Size: 24576 bytes

    Driver: C:\XP\System32\DRIVERS\kbdclass.sys

    Address: 0xF8A4E000

    Size: 24576 bytes

    Driver: C:\XP\system32\KDCOM.DLL

    Address: 0xF8B76000

    Size: 8192 bytes

    Driver: C:\XP\system32\drivers\kmixer.sys

    Address: 0xB928D000

    Size: 176128 bytes

    Driver: C:\XP\system32\drivers\ks.sys

    Address: 0xF7EBE000

    Size: 143360 bytes

    Driver: KSecDD.sys

    Address: 0xF84DC000

    Size: 94208 bytes

    Driver: C:\XP\system32\DRIVERS\L8042Kbd.sys

    Address: 0xF8345000

    Size: 12288 bytes

    Driver: C:\XP\system32\DRIVERS\LHidKE.Sys

    Address: 0xF89AE000

    Size: 24576 bytes

    Driver: C:\XP\System32\Drivers\LHidUsbK.Sys

    Address: 0xF8856000

    Size: 36864 bytes

    Driver: C:\XP\system32\DRIVERS\LMouKE.Sys

    Address: 0xF7BD8000

    Size: 65536 bytes

    Driver: C:\XP\system32\DRIVERS\lv302af.sys

    Address: 0xF8BB0000

    Size: 8192 bytes

    Driver: C:\XP\system32\DRIVERS\LV302AV.SYS

    Address: 0xF63C3000

    Size: 913408 bytes

    Driver: C:\XP\system32\DRIVERS\lvsvf2.sys

    Address: 0xF61A8000

    Size: 2207744 bytes

    Driver: C:\XP\System32\Drivers\mnmdd.SYS

    Address: 0xF8BA0000

    Size: 8192 bytes

    Driver: C:\XP\System32\DRIVERS\mouclass.sys

    Address: 0xF8986000

    Size: 24576 bytes

    Driver: C:\XP\System32\DRIVERS\mouhid.sys

    Address: 0xF696A000

    Size: 12288 bytes

    Driver: MountMgr.sys

    Address: 0xF86A6000

    Size: 45056 bytes

    Driver: C:\XP\System32\DRIVERS\mrxdav.sys

    Address: 0xB99FD000

    Size: 184320 bytes

    Driver: C:\XP\System32\DRIVERS\mrxsmb.sys

    Address: 0xF66F6000

    Size: 454656 bytes

    Driver: C:\XP\System32\Drivers\Msfs.SYS

    Address: 0xF89F6000

    Size: 20480 bytes

    Driver: C:\XP\System32\DRIVERS\msgpc.sys

    Address: 0xF8876000

    Size: 36864 bytes

    Driver: C:\XP\System32\DRIVERS\mssmbios.sys

    Address: 0xF8309000

    Size: 16384 bytes

    Driver: Mup.sys

    Address: 0xF83BD000

    Size: 110592 bytes

    Driver: C:\XP\SYSTEM32\Drivers\NDIS.SYS

    Address: 0xF859A000

    Size: 184320 bytes

    Driver: C:\XP\System32\DRIVERS\ndistapi.sys

    Address: 0xF8325000

    Size: 12288 bytes

    Driver: C:\XP\System32\DRIVERS\ndiswan.sys

    Address: 0xF7B51000

    Size: 94208 bytes

    Driver: C:\XP\System32\Drivers\NDProxy.SYS

    Address: 0xF8826000

    Size: 40960 bytes

    Driver: C:\XP\System32\DRIVERS\netbios.sys

    Address: 0xF88A6000

    Size: 36864 bytes

    Driver: C:\XP\System32\DRIVERS\netbt.sys

    Address: 0xF67DA000

    Size: 163840 bytes

    Driver: C:\XP\system32\drivers\nod32drv.sys

    Address: 0xF8BAA000

    Size: 8192 bytes

    Driver: C:\XP\system32\drivers\npf.sys

    Address: 0xB97B8000

    Size: 36864 bytes

    Driver: C:\XP\System32\Drivers\Npfs.SYS

    Address: 0xF8A06000

    Size: 32768 bytes

    Driver: Ntfs.sys

    Address: 0xF844F000

    Size: 577536 bytes

    Driver: C:\XP\system32\ntoskrnl.exe

    Address: 0x804D7000

    Size: 2180352 bytes

    Driver: C:\XP\System32\Drivers\Null.SYS

    Address: 0xF8D0B000

    Size: 4096 bytes

    Driver: C:\XP\System32\nv4_disp.dll

    Address: 0xBF012000

    Size: 3928064 bytes

    Driver: C:\XP\System32\DRIVERS\nv4_mini.sys

    Address: 0xF7F9E000

    Size: 3534848 bytes

    Driver: C:\XP\system32\DRIVERS\nvcap.sys

    Address: 0xF6022000

    Size: 110592 bytes

    Driver: C:\XP\system32\DRIVERS\nvtunep.sys

    Address: 0xF66DA000

    Size: 16384 bytes

    Driver: C:\XP\system32\DRIVERS\nvtvsnd.sys

    Address: 0xF7B78000

    Size: 45056 bytes

    Driver: C:\XP\system32\DRIVERS\NVxbar.sys

    Address: 0xF66E2000

    Size: 12288 bytes

    Driver: C:\XP\system32\drivers\P17.sys

    Address: 0xF7D47000

    Size: 1392640 bytes

    Driver: C:\XP\System32\DRIVERS\parport.sys

    Address: 0xF7C08000

    Size: 81920 bytes

    Driver: PartMgr.sys

    Address: 0xF8906000

    Size: 20480 bytes

    Driver: C:\XP\System32\Drivers\ParVdm.SYS

    Address: 0xF8BA6000

    Size: 8192 bytes

    Driver: pci.sys

    Address: 0xF85EE000

    Size: 69632 bytes

    Driver: C:\XP\System32\DRIVERS\PCIIDEX.SYS

    Address: 0xF88FE000

    Size: 28672 bytes

    Driver: C:\XP\System32\Drivers\Pcouffin.sys

    Address: 0xF87E6000

    Size: 40960 bytes

    Driver: C:\XP\system32\drivers\pfc.sys

    Address: 0xF8335000

    Size: 12288 bytes

    Driver: PnpManager

    Address: 0x804D7000

    Size: 2180352 bytes

    Driver: C:\XP\system32\drivers\portcls.sys

    Address: 0xF7EE1000

    Size: 147456 bytes

    Driver: C:\XP\System32\DRIVERS\ptilink.sys

    Address: 0xF896E000

    Size: 20480 bytes

    Driver: PxHelp20.sys

    Address: 0xF890E000

    Size: 20480 bytes

    Driver: C:\XP\System32\DRIVERS\rasacd.sys

    Address: 0xF8329000

    Size: 12288 bytes

    Driver: C:\XP\System32\DRIVERS\rasl2tp.sys

    Address: 0xF87B6000

    Size: 53248 bytes

    Driver: C:\XP\System32\DRIVERS\raspppoe.sys

    Address: 0xF87C6000

    Size: 45056 bytes

    Driver: C:\XP\System32\DRIVERS\raspptp.sys

    Address: 0xF87D6000

    Size: 49152 bytes

    Driver: C:\XP\System32\DRIVERS\raspti.sys

    Address: 0xF897E000

    Size: 20480 bytes

    Driver: RAW

    Address: 0x804D7000

    Size: 2180352 bytes

    Driver: C:\XP\System32\DRIVERS\rdbss.sys

    Address: 0xF678D000

    Size: 176128 bytes

    Driver: C:\XP\System32\DRIVERS\RDPCDD.sys

    Address: 0xF8BA4000

    Size: 8192 bytes

    Driver: C:\XP\System32\DRIVERS\rdpdr.sys

    Address: 0xF7AF8000

    Size: 200704 bytes

    Driver: C:\XP\System32\DRIVERS\redbook.sys

    Address: 0xF87A6000

    Size: 61440 bytes

    Driver: C:\XP\System32\Drivers\rkhdrv31.SYS

    Address: 0xF8976000

    Size: 20480 bytes

    Driver: C:\XP\System32\Drivers\SCDEmu.SYS

    Address: 0xF8A3E000

    Size: 32768 bytes

    Driver: C:\XP\system32\DRIVERS\SCSIPORT.SYS

    Address: 0xF8525000

    Size: 98304 bytes

    Driver: C:\XP\System32\DRIVERS\secdrv.sys

    Address: 0xF8956000

    Size: 28672 bytes

    Driver: C:\XP\System32\DRIVERS\serenum.sys

    Address: 0xF834D000

    Size: 16384 bytes

    Driver: C:\XP\System32\DRIVERS\serial.sys

    Address: 0xF8746000

    Size: 65536 bytes

    Driver: snapman.sys

    Address: 0xF83D8000

    Size: 102400 bytes

    Driver: C:\XP\system32\drivers\splitter.sys

    Address: 0xF8BF4000

    Size: 8192 bytes

    Driver: sr.sys

    Address: 0xF84F3000

    Size: 73728 bytes

    Driver: C:\XP\System32\DRIVERS\srv.sys

    Address: 0xB97F0000

    Size: 335872 bytes

    Driver: SSFS0509.SYS

    Address: 0xF8696000

    Size: 36864 bytes

    Driver: SSHRMD.SYS

    Address: 0xF8686000

    Size: 36864 bytes

    Driver: SSIDRV.SYS

    Address: 0xF85C7000

    Size: 159744 bytes

    Driver: C:\XP\System32\Drivers\sskbfd.sys

    Address: 0xF8766000

    Size: 49152 bytes

    Driver: C:\XP\system32\DRIVERS\STREAM.SYS

    Address: 0xF88E6000

    Size: 49152 bytes

    Driver: C:\XP\System32\DRIVERS\swenum.sys

    Address: 0xF8B8C000

    Size: 8192 bytes

    Driver: C:\XP\system32\drivers\swmidi.sys

    Address: 0xB9AE2000

    Size: 57344 bytes

    Driver: C:\XP\system32\drivers\sysaudio.sys

    Address: 0xB9368000

    Size: 61440 bytes

    Driver: C:\XP\System32\DRIVERS\tcpip.sys

    Address: 0xF6823000

    Size: 360448 bytes

    Driver: C:\XP\SYSTEM32\Drivers\TDI.SYS

    Address: 0xF88F6000

    Size: 20480 bytes

    Driver: C:\XP\System32\DRIVERS\termdd.sys

    Address: 0xF87F6000

    Size: 40960 bytes

    Driver: C:\XP\system32\DRIVERS\tifsfilt.sys

    Address: 0xF899E000

    Size: 32768 bytes

    Driver: timntr.sys

    Address: 0xF83F1000

    Size: 385024 bytes

    Driver: C:\XP\System32\DRIVERS\update.sys

    Address: 0xF7AC4000

    Size: 212992 bytes

    Driver: C:\XP\system32\drivers\usbaudio.sys

    Address: 0xF7BE8000

    Size: 61440 bytes

    Driver: C:\XP\System32\DRIVERS\usbccgp.sys

    Address: 0xF89CE000

    Size: 32768 bytes

    Driver: C:\XP\System32\DRIVERS\USBD.SYS

    Address: 0xF8B90000

    Size: 8192 bytes

    Driver: C:\XP\system32\DRIVERS\usbehci.sys

    Address: 0xF8966000

    Size: 28672 bytes

    Driver: C:\XP\System32\DRIVERS\usbhub.sys

    Address: 0xF8816000

    Size: 61440 bytes

    Driver: C:\XP\System32\DRIVERS\usbohci.sys

    Address: 0xF895E000

    Size: 20480 bytes

    Driver: C:\XP\System32\DRIVERS\USBPORT.SYS

    Address: 0xF7E9B000

    Size: 143360 bytes

    Driver: C:\XP\System32\DRIVERS\usbprint.sys

    Address: 0xF8946000

    Size: 28672 bytes

    Driver: C:\XP\system32\DRIVERS\USBSTOR.SYS

    Address: 0xF8A26000

    Size: 28672 bytes

    Driver: C:\XP\System32\DRIVERS\usbuhci.sys

    Address: 0xF893E000

    Size: 20480 bytes

    Driver: D:\Virtual CD\VCdRom.sys

    Address: 0xF7B31000

    Size: 12288 bytes

    Driver: C:\XP\System32\drivers\vga.sys

    Address: 0xF89E6000

    Size: 24576 bytes

    Driver: viaagp.sys

    Address: 0xF86F6000

    Size: 45056 bytes

    Driver: viaide.sys

    Address: 0xF8B7C000

    Size: 8192 bytes

    Driver: C:\XP\System32\DRIVERS\VIDEOPRT.SYS

    Address: 0xF7F8A000

    Size: 81920 bytes

    Driver: VolSnap.sys

    Address: 0xF86B6000

    Size: 53248 bytes

    Driver: C:\XP\System32\DRIVERS\wanarp.sys

    Address: 0xF8896000

    Size: 36864 bytes

    Driver: C:\XP\System32\watchdog.sys

    Address: 0xF89D6000

    Size: 20480 bytes

    Driver: C:\XP\system32\drivers\wdmaud.sys

    Address: 0xB92DB000

    Size: 86016 bytes

    Driver: Win32k

    Address: 0xBF800000

    Size: 1847296 bytes

    Driver: C:\XP\System32\win32k.sys

    Address: 0xBF800000

    Size: 1847296 bytes

    Driver: C:\XP\system32\drivers\WmBEnum.sys

    Address: 0xF8301000

    Size: 12288 bytes

    Driver: C:\XP\System32\DRIVERS\WMILIB.SYS

    Address: 0xF8B78000

    Size: 8192 bytes

    Driver: WMIxWDM

    Address: 0x804D7000

    Size: 2180352 bytes

    Driver: C:\XP\system32\drivers\WmXlCore.sys

    Address: 0xF8806000

    Size: 45056 bytes

    Driver: C:\XP\System32\drivers\ws2ifsl.sys

    Address: 0xF7B3D000

    Size: 12288 bytes

    ----

    RkUnhooker report generator v0.6

    ==============================================

    Rootkit Unhooker kernel version: 3.31.150.420

    ==============================================

    Windows Major Version: 5

    Windows Minor Version: 1

    Windows Build Number: 2600

    ==============================================

    [2120]SpySweeper.exe-->kernel32.dll-->CreateThread, Type: Inline - PushRet at address 0x7C810651 hook handler located in [unknown_code_page]

    ntoskrnl.exe+0x0000B9A8, Type: Inline - RelativeCall at address 0x804E29A8 hook handler located in [unknown_code_page]

    tcpip.sys-->ndis.sys-->NdisRegisterProtocol, Type: IAT modification at address 0xF6861F60 hook handler located in [unknown_code_page]

    wanarp.sys-->ndis.sys-->NdisDeregisterProtocol, Type: IAT modification at address 0xF889BB1C hook handler located in [unknown_code_page]

    wanarp.sys-->ndis.sys-->NdisRegisterProtocol, Type: IAT modification at address 0xF889BB28 hook handler located in [unknown_code_page]

    As always, thanks a million for your assistance!

  18. below is the log u asked for:

    Rustock.b-ADS attached to the System32-folder:

    Attempting to remove ADS...

    Looking for Rustock.b-files in the System32-folder:

    ECHO is off.

    ******************* Post-run Status of system *******************

    Rustock.b-driver on the system:

    YOU NEED TO CONSULT MORE ADVANCED TOOLS!!

    The Gmer-rootkitscanner may be a good place to start.

    Gmer rootkit-scanner may be found here: http://www.gmer.net

    Rustock.b-ADS attached to the System32-folder:

    ECHO is off.

    You should either run the tool again or consult more advanced tools

    The Gmer-rootkitscanner may be a good place to start.

    Gmer rootkit-scanner may be found here: http://www.gmer.net

    Looking for Rustock.b-files in the System32-folder:

    ECHO is off.

    You should either run the tool again or consult more advanced tools

    Swandog46's Avenger or Gmer's-rootkitscanner may be a good place to start.

    Swandog46's Avenger may be found here: http://swandog46.geekstogo.com/avengernotes.htm

    Gmer rootkit-scanner may be found here: http://www.gmer.net

    ----------------

    I then ran gmer, the log is in an above post... I had no idea what to do with the information it presented.

    No matter what I did, whenever I rebooted, early in the log on process I got a Windows installer trying to re-install vIsual Foxpro 9, a program which was already on my computer and running fine. No matter how many times I clicked cancel, the installer would close and immediately reopen itself. I would have to click cancel at least 12-15 times (the installer would close and then restart each time) to make the window go away for good. I fear this may have been the vehicle used to infect the machine. I could find no registry entries anywhere that where telling it to run on startup. I have several starup monitors and none of them showed an entry for it either... very suspiscious IMO. I finally got tired of hovering over the mouse all the way thru each 5 minute boot and let it do its thing to see what would happen. I said it was preparing to instal VFP9, would gather a bunch of data and then finally close without ever installing anything near as I could tell.

    Subsequent scans did not turn up any rootkit, however, spydetector said that rustock backdoor had been successfully removed whenever I tried to run the rust checker. So I am now assuming from reading your post that I need to close all protection programs but my firewall while performing these checks.. this may invalidate much of previous information as I have avast pro, nod32, spybot S&D, spysweeper, spydetector and now avg all loaded on the system now. So before running combofix, etc, I should have all other protection programs disabled?

    Running the rust checker now just returns an error after reboot saying it can't find files.

    I DID run the avgantirootkit in depth scan last night and it found no rootkits. However, several of the protection programs were also running at the time...

    current status: tho I can see no outbound in the syslogs, task manager shows continuous memory useage and constant cpu useage from 2 up to 86% even tho no applications are open. Average is probably about 12%. However, on all my other computer systems when nothing is running tactual useage hovers near zero with NO spikes. Over night, my available memory has been reduced to almost zero as well. CLosing all the protection programs only freed a small portion oif the memory and had no effect on the task manager reported cpu activity. ALl of it always gets lumped under system idle even tho the computer doesnt seem to be doing anything.

    I noticed there didnt seem to be anyway to unload the nod32krn from task manager, it and its memory allocation seemed to hang around no matter how I closed the app. Sam thing with Spy Sweeper... even tho it has been unloaded using its own menu the app remains in the task manager list sucking up resources even tho it is not doing anything. BTW, Spy Sweper seems to be a huge resource hog. With all of its protections enabled CPU is at near 100% all the time even with no other applications open.

    Maybe Im obsessing too much over the CPU activity, but having anything spiking resources when u are running some applications, especially those with real time graphics (like games for example) are adverserly noticeably affected.

    (sigh)... I will now try your latest suggestion and then post the results in a while.

    Thanks for your help, I really appreciate it.

  19. I ran avg in safe mode, reran combofix, and for a brief period it looked as tho this might have done it... but alas... the windows installer for vfp9 persisted popping up continuously on every reboot until I let it run... here is the avg and another current hijack log:

    Logfile of HijackThis v1.99.1

    Scan saved at 1:24:51 AM, on 5/21/2007

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\XP\System32\smss.exe

    C:\XP\system32\winlogon.exe

    C:\XP\system32\services.exe

    C:\XP\system32\lsass.exe

    C:\XP\system32\svchost.exe

    C:\XP\System32\svchost.exe

    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

    C:\Program Files\Alwil Software\Avast4\ashServ.exe

    C:\XP\system32\spoolsv.exe

    C:\Program Files\Acronis\BackupServer\backupserver.exe

    C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe

    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

    C:\Program Files\Eset\nod32krn.exe

    C:\XP\system32\nvsvc32.exe

    C:\Program Files\SpywareDetector\SDService.exe

    C:\XP\System32\svchost.exe

    C:\XP\Explorer.EXE

    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

    C:\XP\system32\wuauclt.exe

    C:\Program Files\Eset\nod32kui.exe

    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

    C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe

    C:\Program Files\SpywareDetector\SDSystemTray.exe

    C:\Program Files\PTSync\PTSync.exe

    C:\Program Files\Acronis\TrueImageEnterpriseServer\TRUEIM~3.EXE

    C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe

    C:\Program Files\Acronis\TrueImageEnterpriseServer\TIMOUN~1.EXE

    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

    C:\Program Files\Webroot\Spy Sweeper\SSU.EXE

    C:\Program Files\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.americansingles.com/

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll

    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Acrobat7\Acrobat\AcroIEFavClient.dll

    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Acrobat7\Acrobat\AcroIEFavClient.dll

    O3 - Toolbar: Cooxie - {DC99E960-6594-45e3-9D5D-141D825B8096} - C:\Program Files\Cooxie Toolbar\PrvcBand.dll

    O4 - HKLM\..\Run: [spySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray

    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

    O4 - HKLM\..\RunOnce: [speedStartup] "C:\Program Files\Speed Startup\speedstartup.exe" runonce

    O4 - HKCU\..\Run: [speedStartup] "C:\Program Files\Speed Startup\speedstartup.exe" bootup

    O8 - Extra context menu item: Add to &Teleport - D:\TeleportUltra\teleport.htm

    O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

    O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

    O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    O8 - Extra context menu item: Convert to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\MsOffice\OFFICE11\EXCEL.EXE/3000

    O8 - Extra context menu item: Open with Scansoft PDF Converter 3.0 - res://D:\OmniPage15\PDFConverter3\IEShellExt.dll /100

    O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll

    O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll

    O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll

    O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MsOffice\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1145986548799

    O17 - HKLM\System\CCS\Services\Tcpip\..\{90F742E6-14BD-42BD-B353-7487933899E6}: NameServer = 66.254.6.2,66.254.1.2

    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll

    O20 - Winlogon Notify: SDNotify - C:\Program Files\SpywareDetector\SDNotify.dll

    O20 - Winlogon Notify: WgaLogon - C:\XP\SYSTEM32\WgaLogon.dll

    O20 - Winlogon Notify: WRNotifier - C:\XP\SYSTEM32\WRLogonNTF.dll

    O23 - Service: Acronis Remote Agent (AcronisAgent) - Acronis - C:\Program Files\Common Files\Acronis\Agent\agent.exe

    O23 - Service: Acronis Backup Server Service (AcronisBackupServerService) - Acronis - C:\Program Files\Acronis\BackupServer\backupserver.exe

    O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe

    O23 - Service: Arcana Notification Agent (adnotify) - Unknown owner - C:\Program Files\Arcana Development\Notification Agent\ADNotify.exe

    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

    O23 - Service: Arcana Scheduler - Arcana Development - C:\Program Files\Arcana Development\Arcana Scheduler\adscheduler.exe

    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

    O23 - Service: Acronis Group Server (GroupServer) - Acronis - C:\Program Files\Acronis\GroupServer\GroupServer.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\XP\system32\drivers\KodakCCS.exe

    O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe

    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe

    O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)

    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\XP\system32\nvsvc32.exe

    O23 - Service: O&O Defrag - O&O Software GmbH - C:\XP\system32\oodag.exe

    O23 - Service: ProgramCheckerPro (sassvc) - Unknown owner - C:\Program Files\Zenturi\ProgramChecker\sassvc.exe

    O23 - Service: SDService - Max Secure Software - C:\Program Files\SpywareDetector\SDService.exe

    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

    avg:

    ---------------------------------------------------------

    AVG Anti-Spyware - Scan Report

    ---------------------------------------------------------

    + Created at: 11:32:38 PM 5/20/2007

    + Scan result:

    F:\Audio Programs and Plugins\Holding\CyberlinkPower2go\CyberLink.Power2Go.Deluxe.v5.50.2614.Multilingual.Incl.Keymaker\keygen.exe -> Logger.Banker : Cleaned.

    F:\Audio Programs and Plugins\Holding\XPGenuine\Make Windows XP Genuine\3) Genuine.rar/Port_RockXP_v4.exe/RockXP4.exe -> Not-A-Virus.PSWTool.Win32.RAS.a : Cleaned.

    :mozilla.355:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.356:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.357:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.358:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.359:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.360:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.361:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.362:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.363:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.364:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.365:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.366:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.367:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.368:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.369:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.370:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.371:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.372:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.373:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.374:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.375:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.376:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.377:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.378:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.379:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.380:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.381:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.382:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.383:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.384:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.385:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.386:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.387:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.388:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.389:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.390:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.391:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.392:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.393:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.394:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.395:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.396:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.397:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.398:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.399:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.400:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.401:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.402:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.403:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.404:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.405:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.510:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.559:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.676:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.695:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.730:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.761:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.820:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.839:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.

    :mozilla.450:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.

    :mozilla.451:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.

    :mozilla.452:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.

    :mozilla.453:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.

    :mozilla.241:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.

    :mozilla.242:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.

    :mozilla.243:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.

    :mozilla.245:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.

    :mozilla.250:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.

    :mozilla.251:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.

    :mozilla.252:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.

    :mozilla.253:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.

    :mozilla.254:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.

    :mozilla.179:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.

    :mozilla.180:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.

    :mozilla.182:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.

    :mozilla.183:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.

    :mozilla.184:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.

    :mozilla.186:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.

    :mozilla.87:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.

    :mozilla.420:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.

    :mozilla.892:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.

    :mozilla.416:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.

    :mozilla.417:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.

    :mozilla.418:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.

    :mozilla.419:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.

    :mozilla.192:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.

    :mozilla.193:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.

    :mozilla.194:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.

    :mozilla.195:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.

    :mozilla.196:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.

    :mozilla.197:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.

    :mozilla.198:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.

    :mozilla.200:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.

    :mozilla.201:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.

    :mozilla.694:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Cnn : Cleaned.

    :mozilla.869:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Com : Cleaned.

    :mozilla.870:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Com : Cleaned.

    :mozilla.871:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Com : Cleaned.

    :mozilla.872:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Com : Cleaned.

    :mozilla.503:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.

    :mozilla.504:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.

    :mozilla.505:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.

    :mozilla.506:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.

    :mozilla.142:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.

    :mozilla.143:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.

    :mozilla.261:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.

    :mozilla.262:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.

    :mozilla.263:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.

    :mozilla.264:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.

    :mozilla.265:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.

    :mozilla.244:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.

    :mozilla.246:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.

    :mozilla.247:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.

    :mozilla.248:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.

    :mozilla.249:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.

    :mozilla.110:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.

    :mozilla.447:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.

    :mozilla.464:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.

    :mozilla.556:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.

    :mozilla.574:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.

    :mozilla.585:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.

    :mozilla.650:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.

    :mozilla.655:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.

    :mozilla.660:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.

    :mozilla.224:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.

    :mozilla.225:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.

    :mozilla.227:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.

    :mozilla.228:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.

    :mozilla.231:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.

    :mozilla.232:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.

    :mozilla.704:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.

    :mozilla.705:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.

    :mozilla.706:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.

    :mozilla.707:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.

    :mozilla.708:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.

    :mozilla.709:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.

    :mozilla.896:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.

    :mozilla.115:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.

    :mozilla.927:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.

    :mozilla.786:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.

    :mozilla.787:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.

    :mozilla.539:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.

    :mozilla.540:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.

    :mozilla.541:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.

    :mozilla.283:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.

    :mozilla.284:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.

    :mozilla.331:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Msn : Cleaned.

    :mozilla.332:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Msn : Cleaned.

    :mozilla.335:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Msn : Cleaned.

    :mozilla.7:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.

    :mozilla.8:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.

    :mozilla.9:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.

    :mozilla.931:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.

    :mozilla.932:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.

    :mozilla.727:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Overture : Cleaned.

    :mozilla.728:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Overture : Cleaned.

    :mozilla.729:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Overture : Cleaned.

    :mozilla.428:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.

    :mozilla.255:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.

    :mozilla.256:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.

    :mozilla.257:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.

    :mozilla.258:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.

    :mozilla.259:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.

    :mozilla.260:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.

    :mozilla.285:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.

    :mozilla.286:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.

    :mozilla.287:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.

    :mozilla.288:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.

    :mozilla.289:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.

    :mozilla.290:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.

    :mozilla.291:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.

    :mozilla.602:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.

    :mozilla.603:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.

    :mozilla.604:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.

    :mozilla.605:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.

    :mozilla.606:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.

    :mozilla.607:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.

    :mozilla.608:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.

    :mozilla.609:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.

    :mozilla.610:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.

    :mozilla.629:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.

    :mozilla.205:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.206:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.207:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.208:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.209:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.210:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.211:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.212:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.213:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.214:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.215:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.216:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.217:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.218:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.219:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.220:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.221:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.222:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.223:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.

    :mozilla.149:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.

    :mozilla.150:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.

    :mozilla.151:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.

    :mozilla.152:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.

    :mozilla.153:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.

    :mozilla.154:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.

    :mozilla.731:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.

    :mozilla.732:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.

    :mozilla.733:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.

    :mozilla.734:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.

    :mozilla.735:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.

    :mozilla.736:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.

    :mozilla.737:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.

    :mozilla.738:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.

    :mozilla.21:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.22:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.23:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.24:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.25:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.26:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.27:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.28:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.29:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.30:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.31:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.32:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.33:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.34:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.35:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.36:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.37:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.38:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.39:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.40:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.41:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.46:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.47:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.48:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.49:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.50:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.51:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.52:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.53:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.54:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.55:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.56:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.57:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.58:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.59:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.60:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.61:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.62:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.63:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.64:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.65:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.66:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.67:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.68:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.69:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.

    :mozilla.421:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.

    :mozilla.422:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.

    :mozilla.423:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.

    :mozilla.424:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.

    :mozilla.920:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Toplist : Cleaned.

    :mozilla.899:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.

    :mozilla.266:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.

    :mozilla.267:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.

    :mozilla.268:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.

    :mozilla.269:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.

    :mozilla.270:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.

    :mozilla.271:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.

    :mozilla.272:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.

    :mozilla.273:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.

    :mozilla.274:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.

    :mozilla.444:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafic : Cleaned.

    :mozilla.148:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.

    :mozilla.89:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.

    :mozilla.128:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.

    :mozilla.79:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.

    :mozilla.944:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.

    :mozilla.135:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.

    :mozilla.136:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.

    :mozilla.137:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.

    :mozilla.138:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.

    :mozilla.139:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.

    :mozilla.140:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.

    :mozilla.141:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.

    :mozilla.485:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.

    :mozilla.486:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.

    :mozilla.487:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.

    :mozilla.488:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.

    C:\Program Files\Teleport Ultra\scheduler.exe -> Trojan.Agent.iu : Cleaned.

    D:\TeleportUltra\scheduler.exe -> Trojan.Agent.iu : Cleaned.

    F:\Audio Programs and Plugins\Audio Programs\Vegas\SONY.Vegas.6.0c.FULL.Include.Keymaker-PDX.zip/KEYGEN/SONYkeygen.exe -> Trojan.Pakes.edg : Cleaned.

    F:\Audio Programs and Plugins\Audio Programs\Vegas\install\KEYGEN\SONYkeygen.exe -> Trojan.Pakes.edg : Cleaned.

    D:\Acronis Complete Suite\Acronis Complete\WinRAR.v3.51.WinALL.Cracked-CORE\cr-wr351.zip/crack.exe -> Trojan.Small : Cleaned.

    F:\Audio Programs and Plugins\Holding\SpiderWriter\Spider_Writer_v5-20-00610\Spider_Writer_v5[1].20.0610Patch.zip/crack.exe -> Trojan.Small : Cleaned.

    ::Report end