Gå til innhold

[LØST] Spyware problemer, Vundo? ("hijack this" logg)


Anbefalte innlegg

Jeg har store problemer med spyware. Har greid å fjente det meste ved hjelp av Spyboy, ad-aware og anti-virus. Men det er noen rester igjen jeg har problemer med å fjerne. Etter det jeg har skjønt er det en trojan kalt Vundo. Har prøved diverse små programmer jeg har funnet som skal fjerne Vundo, men det ser ikke ut til å hjelpe.

 

Det mest merkbare problement jeg har er at jeg ikke kan åpne windows explorer(det vil si at jeg ikke kan åpne noen mapper). Også når jeg trykker på linker i google blir jeg ofte sendt til en helt annen side enn jeg vil, med reklame for fake anti-spyware progammer.

 

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:00:30, on 05.05.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\IPSSVC.EXE
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
C:\WINDOWS\system32\slClient.exe
C:\WINDOWS\system32\spss_lmd.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\System32\TPHDEXLG.EXE
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINDOWS\system32\TpScrLk.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\S1288\Local Settings\Temporary Internet Files\Content.IE5\W70FE2AM\FixVundo[1].exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://internetsearchservice.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://internetsearchservice.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://internetsearchservice.com
R3 - URLSearchHook: i-Nav IDN SearchHook - {CE000994-A58C-4441-8938-744CD72AB27F} - C:\Program Files\VeriSign\i-Nav\i-nav_4_2_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: i-Nav IDN Resolver - {CE000992-A58C-4441-8938-744CD72AB27F} - C:\Program Files\VeriSign\i-Nav\i-nav_4_2_0.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [TPKBDLED] C:\WINDOWS\system32\TpScrLk.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe" /startup
O4 - HKLM\..\Run: [ISUSPM] REM "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"
O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://c:\program files\adobe\acrobat 8.0\acrobat\acroiefavclient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://c:\program files\adobe\acrobat 8.0\acrobat\acroiefavclient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://c:\program files\adobe\acrobat 8.0\acrobat\acroiefavclient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://c:\program files\adobe\acrobat 8.0\acrobat\acroiefavclient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://c:\program files\adobe\acrobat 8.0\acrobat\acroiefavclient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://c:\program files\adobe\acrobat 8.0\acrobat\acroiefavclient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://c:\program files\adobe\acrobat 8.0\acrobat\acroiefavclient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: i-Nav Help - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra 'Tools' menuitem: i-Nav Help - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra button: (no name) - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\Program Files\VeriSign\i-Nav\i-nav_4_2_0.dll
O9 - Extra 'Tools' menuitem: i-Nav Options - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\Program Files\VeriSign\i-Nav\i-nav_4_2_0.dll
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\PkgMgr.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://site.ebrary.com/support/plugins/ebraryRdr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/control/en-US/activex/TmHcmsX.CAB
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://prerelease.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {B562BC94-9A3A-4760-AE48-0D52FD01B1B5} (VeriSign Software Update Service) - http://download.verisign-grs.com/plug-in/i-navinstall.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = valuta.nhh.no
O17 - HKLM\Software\..\Telephony: DomainName = valuta.nhh.no
O17 - HKLM\System\CCS\Services\Tcpip\..\{1053FCD7-1C85-41B5-9DCF-EEAC2F3C305E}: NameServer = 208.67.220.220,208.67.222.222 
O17 - HKLM\System\CCS\Services\Tcpip\..\{15591D2F-A540-4CC4-A39A-6B0298B484D7}: NameServer = 208.67.220.220,208.67.222.222 
O17 - HKLM\System\CCS\Services\Tcpip\..\{32B2E482-98AF-4602-BAD6-878C63C051FA}: NameServer = 208.67.220.220,208.67.222.222 
O17 - HKLM\System\CCS\Services\Tcpip\..\{F9FD814A-4BDB-41CC-A73C-EF2BF24971D8}: NameServer = 208.67.220.220,208.67.222.222 
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = valuta.nhh.no
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 
O17 - HKLM\System\CS1\Services\Tcpip\..\{1053FCD7-1C85-41B5-9DCF-EEAC2F3C305E}: NameServer = 208.67.220.220,208.67.222.222 
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = valuta.nhh.no
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 
O17 - HKLM\System\CS2\Services\Tcpip\..\{1053FCD7-1C85-41B5-9DCF-EEAC2F3C305E}: NameServer = 208.67.220.220,208.67.222.222 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O22 - SharedTaskScheduler: frowardness - {b0fdc513-46b9-46fc-8e70-d575ee546dae} - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ScriptLogic Service (SLClient) - ScriptLogic Software Corporation - C:\WINDOWS\system32\slClient.exe
O23 - Service: Spss License Manager (SpssLM) - Unknown owner - C:\WINDOWS\system32\spss_lmd.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe

--
End of file - 15519 bytes

Endret av Mrlarseirik
Lenke til kommentar
Videoannonse
Annonse

La oss rydde opp litt først. Hvis 017-linjene er noe du ikke kjenner til, så kan du forsåvidt fjerne dem:

 

 

Start hjt, velg "Do a system scan only", sett merke framfor følgende linjer og klikk Fix checked:

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll (file missing)

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll (file missing)

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll (file missing)

O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra button: i-Nav Help - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)

O9 - Extra 'Tools' menuitem: i-Nav Help - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)

O17 - HKLM\System\CCS\Services\Tcpip\..\{1053FCD7-1C85-41B5-9DCF-EEAC2F3C305E}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{15591D2F-A540-4CC4-A39A-6B0298B484D7}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{32B2E482-98AF-4602-BAD6-878C63C051FA}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\..\{F9FD814A-4BDB-41CC-A73C-EF2BF24971D8}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = valuta.nhh.no

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS1\Services\Tcpip\..\{1053FCD7-1C85-41B5-9DCF-EEAC2F3C305E}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = valuta.nhh.no

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CS2\Services\Tcpip\..\{1053FCD7-1C85-41B5-9DCF-EEAC2F3C305E}: NameServer = 208.67.220.220,208.67.222.222

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222

O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)

O22 - SharedTaskScheduler: frowardness - {b0fdc513-46b9-46fc-8e70-d575ee546dae} - (no file)

 

Hent Combofix, og legg det på skrivebordet

 

Kjør combofix.exe, og følg veiledningen.

Du må ikke klikke på vinduet mens programmet kjører.

 

Post loggfilen fra combofix (c:\combofix.txt)

(Ønsker også å se loggen fra SuperAntispyware - preferences->statistics/logs)

Endret av norbat
Lenke til kommentar

combofix

ComboFix 08-05-01.3 - S1288 2008-05-05 20:44:29.1 - NTFSx86
Running from: C:\Sync - do not delete or change\S1288\System\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active


[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUME~1\ALLUSE~1\APPLIC~1\salesmonitor
C:\WINDOWS\system32\cdfdcdaef_g.dll
C:\WINDOWS\system32\kdqqa.exe
C:\WINDOWS\system32\lsprst7.dll

.
(((((((((((((((((((((((((   Files Created from 2008-04-05 to 2008-05-05  )))))))))))))))))))))))))))))))
.

2008-05-05 20:38 . 2008-05-05 20:54	54,156	--ah-----	C:\WINDOWS\QTFont.qfn
2008-05-05 20:38 . 2008-05-05 20:38	1,409	--a------	C:\WINDOWS\QTFont.for
2008-05-05 17:11 . 2008-05-05 17:11	<DIR>	d--------	C:\Program Files\Enigma Software Group
2008-05-05 16:01 . 2008-05-05 16:01	<DIR>	d--------	C:\VundoFix Backups
2008-05-05 15:48 . 2008-05-05 15:48	<DIR>	d--------	C:\Program Files\Windows Defender
2008-05-05 15:48 . 2008-05-05 15:48	<DIR>	d--------	C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2008-05-05 15:47 . 2008-05-05 17:00	<DIR>	d--------	C:\Program Files\SUPERAntiSpyware
2008-05-05 15:47 . 2008-05-05 15:47	<DIR>	d--------	C:\Documents and Settings\S1288\Application Data\SUPERAntiSpyware.com
2008-05-05 15:47 . 2008-05-05 15:47	<DIR>	d--------	C:\DOCUME~1\S1288\APPLIC~1\SUPERAntiSpyware.com
2008-05-05 07:32 . 2008-05-05 07:32	<DIR>	d--------	C:\WINDOWS\report
2008-05-03 23:39 . 2008-05-03 23:39	23	--a------	C:\WINDOWS\system32\eebbaa_g.ocx
2008-05-03 23:12 . 2008-05-03 23:39	<DIR>	d--------	C:\Program Files\RegSupreme
2008-05-03 18:29 . 2007-11-27 22:51	35,216	--a------	C:\WINDOWS\system32\drivers\TMPassthru.sys
2008-05-03 18:28 . 2008-05-03 18:28	<DIR>	d--------	C:\Documents and Settings\S1288\Application Data\InstallShield
2008-05-03 18:28 . 2008-05-03 18:28	<DIR>	d--------	C:\DOCUME~1\S1288\APPLIC~1\InstallShield
2008-05-03 17:46 . 2008-05-03 17:46	<DIR>	d--------	C:\WINDOWS\system32\HouseCall 6.6
2008-05-03 17:46 . 2008-05-03 18:45	<DIR>	d--------	C:\Documents and Settings\S1288\Application Data\HouseCall 6.6
2008-05-03 17:46 . 2008-05-03 18:45	<DIR>	d--------	C:\DOCUME~1\S1288\APPLIC~1\HouseCall 6.6
2008-05-03 15:36 . 2008-05-03 15:34	691,545	--a------	C:\WINDOWS\unins000.exe
2008-05-03 15:36 . 2008-05-03 15:36	2,544	--a------	C:\WINDOWS\unins000.dat
2008-05-03 15:26 . 2008-05-03 15:26	<DIR>	d--------	C:\Program Files\CCleaner
2008-05-03 15:17 . 2008-05-05 16:23	<DIR>	d--------	C:\WINDOWS\system32\527631
2008-04-24 23:40 . 2008-05-03 15:35	<DIR>	d--------	C:\WINDOWS\system32\717305
2008-04-16 07:31 . 2008-04-16 07:31	<DIR>	d--------	C:\Program Files\Sonata
2008-04-16 07:31 . 2008-04-16 07:31	<DIR>	d--------	C:\Program Files\SAS
2008-04-16 07:31 . 2008-04-16 07:31	<DIR>	d--------	C:\Program Files\Clever Age
2008-04-16 07:31 . 2008-04-16 07:31	<DIR>	d--------	C:\DOCUME~1\ALLUSE~1\APPLIC~1\SafeNet Sentinel
2008-04-16 07:31 . 2008-04-16 07:36	76	--a------	C:\WINDOWS\null
2008-04-16 07:29 . 2008-04-16 07:29	<DIR>	d--------	C:\Program Files\SPSSInc
2008-04-16 07:29 . 2008-04-16 07:29	<DIR>	d--------	C:\Program Files\Common Files\SPSS
2008-04-16 07:29 . 2008-04-16 07:29	<DIR>	d--------	C:\Application Data
2008-04-16 07:24 . 2008-04-16 07:24	<DIR>	d--------	C:\Program Files\FileZilla
2008-04-16 07:15 . 2008-04-16 07:15	<DIR>	d--------	C:\data
2008-04-16 07:13 . 2008-04-16 07:13	<DIR>	d--------	C:\Program Files\XML Notepad 2007
2008-04-16 07:13 . 2008-04-16 07:13	<DIR>	d--------	C:\Program Files\VeriSign
2008-04-16 07:13 . 2008-04-16 07:13	<DIR>	d--------	C:\Program Files\Pinkode
2008-04-16 07:05 . 2008-04-16 07:05	<DIR>	d--------	C:\Program Files\FileMaker
2008-04-15 16:09 . 2007-08-08 12:54	<DIR>	d---s----	C:\Documents and Settings\s1288.VALUTA.000\UserData
2008-04-15 16:09 . 2008-04-15 16:09	<DIR>	d--------	C:\Documents and Settings\s1288.VALUTA.000
2008-04-15 16:09 . 2008-05-05 17:33	1,024	--ah-----	C:\Documents and Settings\s1288.VALUTA.000\ntuser.dat.LOG

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-05 13:47	---------	d-----w	C:\Program Files\Common Files\Wise Installation Wizard
2008-05-04 16:36	---------	d-----w	C:\Program Files\Trend Micro
2008-05-03 20:58	---------	d-----w	C:\Program Files\Mozilla Firefox 3 Beta 1
2008-05-03 19:08	---------	d-----w	C:\Program Files\EsetOnlineScanner
2008-05-03 16:29	---------	d--h--w	C:\Program Files\InstallShield Installation Information
2008-05-03 14:53	---------	d-----w	C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2008-05-03 13:43	---------	d-----w	C:\Program Files\Spybot - Search & Destroy
2008-05-03 13:25	---------	d-----w	C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2008-05-03 13:24	12,632	----a-w	C:\WINDOWS\system32\lsdelete.exe
2008-05-03 13:21	---------	d---a-w	C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2008-05-03 13:17	---------	d-----w	C:\Program Files\Opera
2008-04-16 05:31	---------	d-----w	C:\Program Files\MINITAB 14
2008-04-16 05:28	---------	d-----w	C:\Program Files\SPSS
2008-04-16 05:15	---------	d-----w	C:\Program Files\Stata10
2008-04-16 05:13	---------	d-----w	C:\Program Files\MSXML 4.0
2008-04-15 14:01	---------	d-----w	C:\Program Files\Allsync
2008-03-19 09:47	1,845,248	----a-w	C:\WINDOWS\system32\win32k.sys
2008-02-20 06:51	282,624	----a-w	C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32	45,568	----a-w	C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 08:59	659,456	----a-w	C:\WINDOWS\system32\wininet.dll
2008-02-11 07:39	253,952	----a-w	C:\WINDOWS\system32\OnlineScannerDLLA.dll
2008-02-11 07:39	237,568	----a-w	C:\WINDOWS\system32\OnlineScannerDLLW.dll
2008-02-08 11:53	110,592	----a-w	C:\WINDOWS\system32\OnlineScannerLang.dll
2008-02-05 06:48	77,824	----a-w	C:\WINDOWS\system32\OnlineScannerUninstaller.exe
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2004-08-04 14:00 143360]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [2005-03-15 17:55 335872]
"TPHOTKEY"="C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-05-10 15:03 94208]
"LPManager"="C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe" [2006-01-25 01:03 106496]
"TPKMAPHELPER"="C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" [2005-10-28 19:04 864256]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"PWRMGRTR"="C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2006-03-23 01:13 151552]
"BLOG"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2006-03-23 01:13 208896]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2005-05-06 14:06 716800]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2006-02-14 14:17 110592]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-02-14 14:16 512000]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2005-12-15 14:19 925696]
"TPKBDLED"="C:\WINDOWS\system32\TpScrLk.exe" [2002-10-08 22:28 40960]
"TP4EX"="tp4ex.exe" [2005-10-17 01:11 65536 C:\WINDOWS\system32\TP4EX.exe]
"ACWLIcon"="C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2006-04-17 12:59 98304]
"TpShocks"="TpShocks.exe" [2005-11-07 11:14 106496 C:\WINDOWS\system32\TpShocks.exe]
"PSQLLauncher"="C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe" [2006-04-25 19:03 31232]
"ISUSPM"="REM C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 16:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 04:22 267048]
"TMRUBottedTray"="C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe" [2007-12-19 00:18 288088]
"ACTray"="C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe" [2006-04-17 13:09 409600]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 23:24 620152]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
ACNotify.dll 2006-04-17 13:01 32768 C:\Program Files\ThinkPad\ConnectUtilities\ACNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
psqlpwd.dll 2006-04-25 19:20 40448 C:\WINDOWS\system32\psqlpwd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
notifyf2.dll 2005-07-05 23:45 28672 C:\WINDOWS\system32\notifyf2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
tphklock.dll 2005-11-30 20:16 24576 C:\WINDOWS\system32\tphklock.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\[u]0[/u]\[u]0[/u]]
"Script"=startup.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\[u]0[/u]]
"Script"=Startup.bat

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=

.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-05 20:54:06
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\ThinkPad\ConnectUtilities\AcSvcStub.dll
-> C:\Program Files\ThinkPad\ConnectUtilities\AcLocSettings.dll
-> C:\Program Files\ThinkPad\ConnectUtilities\ACHelper.dll
-> C:\WINDOWS\system32\tphklock.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ibmpmsvc.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\IPSSVC.EXE
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\OfficeScan Client\NTRtScan.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
C:\WINDOWS\system32\SLClient.exe
C:\WINDOWS\system32\spss_lmd.exe
C:\Program Files\Trend Micro\OfficeScan Client\TmListen.exe
C:\WINDOWS\system32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\TEMP\LP66C4.EXE
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\Program Files\Trend Micro\OfficeScan Client\PccNTUpd.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.exe
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-05-05 21:02:11 - machine was rebooted
ComboFix-quarantined-files.txt  2008-05-05 19:01:59

Pre-Run: 43,824,226,304 bytes free
Post-Run: 43,824,660,480 bytes free

200	--- E O F ---	2008-04-16 04:06:29

Lenke til kommentar

Åpne Notisblokk, kopier og lim inn det som står i fet skrift under. Lagre fila på skrivebordet som CFSCript

Dra fila over Combofix-iconet. Combofix vil starte igjen

File::

C:\WINDOWS\system32\eebbaa_g.ocx

 

Folder::

C:\VundoFix Backups

C:\WINDOWS\system32\527631

C:\WINDOWS\system32\717305

 

Du trenger ikke å poste loggen den lager.

Kunne du ha postet SAS-loggen som ble opprettet tidligere?

Fortell hvordan ting og tang fungerer.

Lenke til kommentar

Alt ser ut til å fungere perfekt nå. Ingen problemer med å åpne Windows Explorer eller andre mapper.

 

Jeg har kjørt SAS mange ganger, helt til den ikke fant mer.

 

Her er loggen fra første gangen er kjørte SAS.

 

 

 

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/05/2008 at 04:50 PM

Application Version : 4.0.1154

Core Rules Database Version : 3452
Trace Rules Database Version: 1444

Scan type	   : Complete Scan
Total Scan Time : 01:00:36

Memory items scanned	  : 537
Memory threats detected   : 1
Registry items scanned	: 5366
Registry threats detected : 92
File items scanned		: 6836
File threats detected	 : 819

Trojan.Vundo-Variant/F
C:\WINDOWS\SYSTEM32\CBXPOPHI.DLL
C:\WINDOWS\SYSTEM32\CBXPOPHI.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{19B9CD57-3043-442F-8DFF-F9924AF056BD}
HKCR\CLSID\{19B9CD57-3043-442F-8DFF-F9924AF056BD}
HKCR\CLSID\{19B9CD57-3043-442F-8DFF-F9924AF056BD}\InprocServer32
HKCR\CLSID\{19B9CD57-3043-442F-8DFF-F9924AF056BD}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{19B9CD57-3043-442F-8DFF-F9924AF056BD}
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\cbXpoPhi

Adware.Tracking Cookie
C:\Documents and Settings\S1288\Cookies\s1288@adtech[1].txt
C:\Documents and Settings\S1288\Cookies\s1288@adserver[1].txt
C:\Documents and Settings\S1288\Cookies\[email protected][2].txt
C:\Documents and Settings\S1288\Cookies\s1288@tribalfusion[1].txt
C:\Documents and Settings\S1288\Cookies\[email protected][1].txt
C:\Documents and Settings\S1288\Cookies\s1288@adultfriendfinder[1].txt
C:\Documents and Settings\S1288\Cookies\s1288@exoclick[2].txt
C:\Documents and Settings\S1288\Cookies\[email protected][2].txt
C:\Documents and Settings\S1288\Cookies\s1288@tacoda[2].txt
C:\Documents and Settings\S1288\Cookies\[email protected][2].txt
C:\Documents and Settings\S1288\Cookies\s1288@realmedia[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@indextools[10].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@accountpros[2].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][2].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][2].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[4].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[8].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[1].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[5].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[9].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@2o7[2].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][1].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][2].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][3].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][18].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][10].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][11].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][12].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][13].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][14].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][15].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][16].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][17].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][32].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][19].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][1].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][20].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][21].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][22].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][23].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][24].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][25].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][26].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][27].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][28].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][29].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][2].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][30].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][31].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][46].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][33].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][34].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][35].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][36].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][37].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][38].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][39].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][3].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][40].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][41].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][42].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][43].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][44].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][45].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][47].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][48].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][49].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][4].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][50].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][5].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][6].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][7].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][8].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][9].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[15].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[10].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[11].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[12].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[13].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[14].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[30].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[16].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[17].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[18].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[19].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[20].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[21].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[22].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[23].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[24].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[25].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[26].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[27].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[28].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[29].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[2].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[31].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[32].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[33].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[34].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[36].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[37].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[38].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[3].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[6].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@advertising[7].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@doubleclick[1].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][1].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][2].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][3].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][4].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][5].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][6].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][7].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][1].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[53].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@indextools[11].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@indextools[1].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@indextools[2].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@indextools[4].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@indextools[5].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@indextools[6].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@indextools[7].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@indextools[8].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@indextools[9].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@mediaplex[1].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][1].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][1].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@serving-sys[9].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@serving-sys[10].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@serving-sys[1].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@serving-sys[2].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@serving-sys[3].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@serving-sys[4].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@serving-sys[5].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@serving-sys[6].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@serving-sys[7].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@serving-sys[8].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][1].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][1].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][24].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][10].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][11].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][12].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][13].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][14].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][15].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][16].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][17].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][18].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][19].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][1].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][20].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][21].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][22].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][23].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][39].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][25].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][26].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][27].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][28].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][29].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][2].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][30].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][31].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][32].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][33].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][34].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][35].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][36].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][37].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][38].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][54].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][3].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][40].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][41].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][42].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][43].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][44].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][45].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][46].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][47].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][48].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][49].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][4].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][50].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][51].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][52].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][53].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[23].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][55].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][56].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][58].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][5].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][6].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][7].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][8].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][9].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][1].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[10].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[11].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[12].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[13].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[14].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[15].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[16].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[17].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[18].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[19].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[1].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[20].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[21].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[22].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[38].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[24].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[25].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[26].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[27].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[28].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[29].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[2].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[30].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[31].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[32].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[33].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[34].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[35].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[36].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[37].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[39].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[3].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[40].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[41].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[42].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[43].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[44].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[45].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[46].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[47].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[48].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[49].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[4].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[50].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[51].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[52].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[5].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[6].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[7].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[8].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\s1288@tradedoubler[9].txt
C:\Documents and Settings\s1288.VALUTA.000\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][10].txt
C:\profbackup\Cookies\[email protected][10].txt
C:\profbackup\Cookies\[email protected][14].txt
C:\profbackup\Cookies\[email protected][18].txt
C:\profbackup\Cookies\[email protected][20].txt
C:\profbackup\Cookies\[email protected][21].txt
C:\profbackup\Cookies\s1288@paycounter[2].txt
C:\profbackup\Cookies\[email protected][30].txt
C:\profbackup\Cookies\[email protected][31].txt
C:\profbackup\Cookies\s1288@tracker[1].txt
C:\profbackup\Cookies\[email protected][11].txt
C:\profbackup\Cookies\[email protected][15].txt
C:\profbackup\Cookies\[email protected][19].txt
C:\profbackup\Cookies\[email protected][40].txt
C:\profbackup\Cookies\[email protected][41].txt
C:\profbackup\Cookies\[email protected][50].txt
C:\profbackup\Cookies\[email protected][51].txt
C:\profbackup\Cookies\s1288@tracker[2].txt
C:\profbackup\Cookies\s1288@zedo[2].txt
C:\profbackup\Cookies\[email protected][12].txt
C:\profbackup\Cookies\[email protected][16].txt
C:\profbackup\Cookies\[email protected][60].txt
C:\profbackup\Cookies\[email protected][61].txt
C:\profbackup\Cookies\s1288@xiti[1].txt
C:\profbackup\Cookies\s1288@revenue[2].txt
C:\profbackup\Cookies\[email protected][4].txt
C:\profbackup\Cookies\s1288@zedo[1].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\s1288@tracker[3].txt
C:\profbackup\Cookies\[email protected][13].txt
C:\profbackup\Cookies\[email protected][17].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][10].txt
C:\profbackup\Cookies\[email protected][11].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][28].txt
C:\profbackup\Cookies\[email protected][27].txt
C:\profbackup\Cookies\[email protected][26].txt
C:\profbackup\Cookies\[email protected][25].txt
C:\profbackup\Cookies\[email protected][24].txt
C:\profbackup\Cookies\[email protected][23].txt
C:\profbackup\Cookies\[email protected][22].txt
C:\profbackup\Cookies\[email protected][29].txt
C:\profbackup\Cookies\[email protected][38].txt
C:\profbackup\Cookies\[email protected][37].txt
C:\profbackup\Cookies\[email protected][36].txt
C:\profbackup\Cookies\[email protected][35].txt
C:\profbackup\Cookies\[email protected][34].txt
C:\profbackup\Cookies\[email protected][33].txt
C:\profbackup\Cookies\[email protected][32].txt
C:\profbackup\Cookies\[email protected][39].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\s1288@atwola[2].txt
C:\profbackup\Cookies\s1288@atwola[1].txt
C:\profbackup\Cookies\[email protected][48].txt
C:\profbackup\Cookies\[email protected][47].txt
C:\profbackup\Cookies\[email protected][46].txt
C:\profbackup\Cookies\[email protected][45].txt
C:\profbackup\Cookies\[email protected][44].txt
C:\profbackup\Cookies\[email protected][43].txt
C:\profbackup\Cookies\[email protected][42].txt
C:\profbackup\Cookies\[email protected][49].txt
C:\profbackup\Cookies\[email protected][58].txt
C:\profbackup\Cookies\[email protected][57].txt
C:\profbackup\Cookies\[email protected][56].txt
C:\profbackup\Cookies\[email protected][55].txt
C:\profbackup\Cookies\[email protected][54].txt
C:\profbackup\Cookies\[email protected][53].txt
C:\profbackup\Cookies\[email protected][52].txt
C:\profbackup\Cookies\[email protected][59].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][4].txt
C:\profbackup\Cookies\[email protected][5].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][3].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][62].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\s1288@windowsmedia[1].txt
C:\profbackup\Cookies\s1288@windowsmedia[2].txt
C:\profbackup\Cookies\[email protected][18].txt
C:\profbackup\Cookies\[email protected][17].txt
C:\profbackup\Cookies\[email protected][16].txt
C:\profbackup\Cookies\[email protected][15].txt
C:\profbackup\Cookies\[email protected][14].txt
C:\profbackup\Cookies\[email protected][13].txt
C:\profbackup\Cookies\[email protected][12].txt
C:\profbackup\Cookies\[email protected][19].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\s1288@advertising[4].txt
C:\profbackup\Cookies\s1288@advertising[8].txt
C:\profbackup\Cookies\s1288@advertising[5].txt
C:\profbackup\Cookies\s1288@advertising[1].txt
C:\profbackup\Cookies\s1288@advertising[9].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][8].txt
C:\profbackup\Cookies\[email protected][9].txt
C:\profbackup\Cookies\[email protected][6].txt
C:\profbackup\Cookies\[email protected][7].txt
C:\profbackup\Cookies\s1288@247realmedia[1].txt
C:\profbackup\Cookies\s1288@247realmedia[2].txt
C:\profbackup\Cookies\s1288@2o7[1].txt
C:\profbackup\Cookies\s1288@2o7[2].txt
C:\profbackup\Cookies\s1288@2o7[3].txt
C:\profbackup\Cookies\s1288@2o7[4].txt
C:\profbackup\Cookies\s1288@2o7[5].txt
C:\profbackup\Cookies\s1288@2o7[6].txt
C:\profbackup\Cookies\s1288@2o7[7].txt
C:\profbackup\Cookies\s1288@2o7[8].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][4].txt
C:\profbackup\Cookies\[email protected][5].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][3].txt
C:\profbackup\Cookies\[email protected][4].txt
C:\profbackup\Cookies\[email protected][5].txt
C:\profbackup\Cookies\[email protected][6].txt
C:\profbackup\Cookies\[email protected][7].txt
C:\profbackup\Cookies\[email protected][8].txt
C:\profbackup\Cookies\[email protected][9].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][4].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][3].txt
C:\profbackup\Cookies\[email protected][4].txt
C:\profbackup\Cookies\[email protected][25].txt
C:\profbackup\Cookies\[email protected][11].txt
C:\profbackup\Cookies\[email protected][12].txt
C:\profbackup\Cookies\[email protected][13].txt
C:\profbackup\Cookies\[email protected][14].txt
C:\profbackup\Cookies\[email protected][15].txt
C:\profbackup\Cookies\[email protected][16].txt
C:\profbackup\Cookies\[email protected][17].txt
C:\profbackup\Cookies\[email protected][18].txt
C:\profbackup\Cookies\[email protected][19].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][20].txt
C:\profbackup\Cookies\[email protected][21].txt
C:\profbackup\Cookies\[email protected][22].txt
C:\profbackup\Cookies\[email protected][23].txt
C:\profbackup\Cookies\[email protected][24].txt
C:\profbackup\Cookies\[email protected][26].txt
C:\profbackup\Cookies\[email protected][27].txt
C:\profbackup\Cookies\[email protected][28].txt
C:\profbackup\Cookies\[email protected][29].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][30].txt
C:\profbackup\Cookies\[email protected][31].txt
C:\profbackup\Cookies\[email protected][32].txt
C:\profbackup\Cookies\[email protected][33].txt
C:\profbackup\Cookies\[email protected][34].txt
C:\profbackup\Cookies\[email protected][35].txt
C:\profbackup\Cookies\[email protected][36].txt
C:\profbackup\Cookies\[email protected][38].txt
C:\profbackup\Cookies\[email protected][3].txt
C:\profbackup\Cookies\[email protected][4].txt
C:\profbackup\Cookies\[email protected][5].txt
C:\profbackup\Cookies\[email protected][6].txt
C:\profbackup\Cookies\[email protected][7].txt
C:\profbackup\Cookies\[email protected][8].txt
C:\profbackup\Cookies\[email protected][9].txt
C:\profbackup\Cookies\[email protected][13].txt
C:\profbackup\Cookies\s1288@adrevolver[1].txt
C:\profbackup\Cookies\s1288@adrevolver[2].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][10].txt
C:\profbackup\Cookies\[email protected][11].txt
C:\profbackup\Cookies\[email protected][12].txt
C:\profbackup\Cookies\[email protected][26].txt
C:\profbackup\Cookies\[email protected][14].txt
C:\profbackup\Cookies\[email protected][15].txt
C:\profbackup\Cookies\[email protected][16].txt
C:\profbackup\Cookies\[email protected][17].txt
C:\profbackup\Cookies\[email protected][18].txt
C:\profbackup\Cookies\[email protected][19].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][20].txt
C:\profbackup\Cookies\[email protected][21].txt
C:\profbackup\Cookies\[email protected][22].txt
C:\profbackup\Cookies\[email protected][23].txt
C:\profbackup\Cookies\[email protected][24].txt
C:\profbackup\Cookies\[email protected][25].txt
C:\profbackup\Cookies\[email protected][39].txt
C:\profbackup\Cookies\[email protected][27].txt
C:\profbackup\Cookies\[email protected][28].txt
C:\profbackup\Cookies\[email protected][29].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][30].txt
C:\profbackup\Cookies\[email protected][31].txt
C:\profbackup\Cookies\[email protected][32].txt
C:\profbackup\Cookies\[email protected][33].txt
C:\profbackup\Cookies\[email protected][34].txt
C:\profbackup\Cookies\[email protected][35].txt
C:\profbackup\Cookies\[email protected][36].txt
C:\profbackup\Cookies\[email protected][37].txt
C:\profbackup\Cookies\[email protected][38].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][3].txt
C:\profbackup\Cookies\[email protected][40].txt
C:\profbackup\Cookies\[email protected][41].txt
C:\profbackup\Cookies\[email protected][42].txt
C:\profbackup\Cookies\[email protected][43].txt
C:\profbackup\Cookies\[email protected][44].txt
C:\profbackup\Cookies\[email protected][45].txt
C:\profbackup\Cookies\[email protected][47].txt
C:\profbackup\Cookies\[email protected][48].txt
C:\profbackup\Cookies\[email protected][49].txt
C:\profbackup\Cookies\[email protected][4].txt
C:\profbackup\Cookies\[email protected][50].txt
C:\profbackup\Cookies\[email protected][5].txt
C:\profbackup\Cookies\[email protected][6].txt
C:\profbackup\Cookies\[email protected][7].txt
C:\profbackup\Cookies\[email protected][8].txt
C:\profbackup\Cookies\[email protected][9].txt
C:\profbackup\Cookies\s1288@adultrevenueservice[1].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\s1288@adtech[10].txt
C:\profbackup\Cookies\s1288@adtech[11].txt
C:\profbackup\Cookies\s1288@adtech[12].txt
C:\profbackup\Cookies\s1288@adtech[13].txt
C:\profbackup\Cookies\s1288@adtech[14].txt
C:\profbackup\Cookies\s1288@adtech[15].txt
C:\profbackup\Cookies\s1288@adtech[16].txt
C:\profbackup\Cookies\s1288@adtech[17].txt
C:\profbackup\Cookies\s1288@adtech[18].txt
C:\profbackup\Cookies\s1288@adtech[19].txt
C:\profbackup\Cookies\s1288@adtech[1].txt
C:\profbackup\Cookies\s1288@adtech[20].txt
C:\profbackup\Cookies\s1288@adtech[2].txt
C:\profbackup\Cookies\s1288@adtech[3].txt
C:\profbackup\Cookies\s1288@adtech[4].txt
C:\profbackup\Cookies\s1288@adtech[5].txt
C:\profbackup\Cookies\s1288@adtech[6].txt
C:\profbackup\Cookies\s1288@adtech[7].txt
C:\profbackup\Cookies\s1288@adtech[8].txt
C:\profbackup\Cookies\s1288@adtech[9].txt
C:\profbackup\Cookies\s1288@adultfriendfinder[2].txt
C:\profbackup\Cookies\s1288@advertising[2].txt
C:\profbackup\Cookies\s1288@advertising[10].txt
C:\profbackup\Cookies\s1288@advertising[11].txt
C:\profbackup\Cookies\s1288@advertising[12].txt
C:\profbackup\Cookies\s1288@advertising[13].txt
C:\profbackup\Cookies\s1288@advertising[14].txt
C:\profbackup\Cookies\s1288@advertising[15].txt
C:\profbackup\Cookies\s1288@advertising[16].txt
C:\profbackup\Cookies\s1288@advertising[17].txt
C:\profbackup\Cookies\s1288@advertising[18].txt
C:\profbackup\Cookies\s1288@advertising[19].txt
C:\profbackup\Cookies\s1288@advertising[20].txt
C:\profbackup\Cookies\s1288@advertising[21].txt
C:\profbackup\Cookies\s1288@advertising[22].txt
C:\profbackup\Cookies\s1288@advertising[23].txt
C:\profbackup\Cookies\s1288@advertising[24].txt
C:\profbackup\Cookies\s1288@advertising[25].txt
C:\profbackup\Cookies\s1288@advertising[26].txt
C:\profbackup\Cookies\s1288@advertising[27].txt
C:\profbackup\Cookies\s1288@advertising[28].txt
C:\profbackup\Cookies\s1288@advertising[30].txt
C:\profbackup\Cookies\s1288@advertising[3].txt
C:\profbackup\Cookies\s1288@advertising[6].txt
C:\profbackup\Cookies\s1288@advertising[7].txt
C:\profbackup\Cookies\s1288@adviva[2].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][4].txt
C:\profbackup\Cookies\s1288@atdmt[1].txt
C:\profbackup\Cookies\s1288@atdmt[2].txt
C:\profbackup\Cookies\s1288@belnk[1].txt
C:\profbackup\Cookies\s1288@bfast[2].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\s1288@bluestreak[1].txt
C:\profbackup\Cookies\s1288@bluestreak[2].txt
C:\profbackup\Cookies\s1288@bluestreak[3].txt
C:\profbackup\Cookies\s1288@bluestreak[4].txt
C:\profbackup\Cookies\s1288@bluestreak[5].txt
C:\profbackup\Cookies\s1288@bluestreak[6].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected]
C:\profbackup\Cookies\s1288@clickability[1].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\s1288@doubleclick[1].txt
C:\profbackup\Cookies\s1288@discounthotels[1].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\s1288@doubleclick[10].txt
C:\profbackup\Cookies\s1288@doubleclick[11].txt
C:\profbackup\Cookies\s1288@doubleclick[12].txt
C:\profbackup\Cookies\s1288@doubleclick[13].txt
C:\profbackup\Cookies\s1288@doubleclick[14].txt
C:\profbackup\Cookies\s1288@doubleclick[15].txt
C:\profbackup\Cookies\s1288@doubleclick[16].txt
C:\profbackup\Cookies\s1288@doubleclick[17].txt
C:\profbackup\Cookies\s1288@doubleclick[18].txt
C:\profbackup\Cookies\s1288@doubleclick[19].txt
C:\profbackup\Cookies\[email protected][6].txt
C:\profbackup\Cookies\s1288@doubleclick[2].txt
C:\profbackup\Cookies\s1288@doubleclick[3].txt
C:\profbackup\Cookies\s1288@doubleclick[4].txt
C:\profbackup\Cookies\s1288@doubleclick[5].txt
C:\profbackup\Cookies\s1288@doubleclick[6].txt
C:\profbackup\Cookies\s1288@doubleclick[7].txt
C:\profbackup\Cookies\s1288@doubleclick[8].txt
C:\profbackup\Cookies\s1288@doubleclick[9].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][3].txt
C:\profbackup\Cookies\[email protected][4].txt
C:\profbackup\Cookies\[email protected][5].txt
C:\profbackup\Cookies\[email protected][7].txt
C:\profbackup\Cookies\[email protected][8].txt
C:\profbackup\Cookies\[email protected][9].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\s1288@emeraldinsight[1].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\s1288@fastclick[1].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\s1288@hitbox[2].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][3].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\s1288@hitbox[1].txt
C:\profbackup\Cookies\s1288@hitbox[4].txt
C:\profbackup\Cookies\s1288@hitbox[5].txt
C:\profbackup\Cookies\s1288@hitbox[6].txt
C:\profbackup\Cookies\s1288@hitbox[7].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][3].txt
C:\profbackup\Cookies\s1288@indexstats[2].txt
C:\profbackup\Cookies\s1288@indextools[1].txt
C:\profbackup\Cookies\s1288@indextools[2].txt
C:\profbackup\Cookies\s1288@indextools[3].txt
C:\profbackup\Cookies\s1288@indextools[4].txt
C:\profbackup\Cookies\s1288@indextools[5].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\s1288@insightfirst[2].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\s1288@linksynergy[1].txt
C:\profbackup\Cookies\s1288@mediaplex[12].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\s1288@mediaplex[10].txt
C:\profbackup\Cookies\s1288@mediaplex[11].txt
C:\profbackup\Cookies\s1288@mediaplex[26].txt
C:\profbackup\Cookies\s1288@mediaplex[13].txt
C:\profbackup\Cookies\s1288@mediaplex[14].txt
C:\profbackup\Cookies\s1288@mediaplex[15].txt
C:\profbackup\Cookies\s1288@mediaplex[16].txt
C:\profbackup\Cookies\s1288@mediaplex[17].txt
C:\profbackup\Cookies\s1288@mediaplex[18].txt
C:\profbackup\Cookies\s1288@mediaplex[19].txt
C:\profbackup\Cookies\s1288@mediaplex[1].txt
C:\profbackup\Cookies\s1288@mediaplex[20].txt
C:\profbackup\Cookies\s1288@mediaplex[21].txt
C:\profbackup\Cookies\s1288@mediaplex[22].txt
C:\profbackup\Cookies\s1288@mediaplex[23].txt
C:\profbackup\Cookies\s1288@mediaplex[24].txt
C:\profbackup\Cookies\s1288@mediaplex[25].txt
C:\profbackup\Cookies\s1288@mediaplex[27].txt
C:\profbackup\Cookies\s1288@mediaplex[28].txt
C:\profbackup\Cookies\s1288@mediaplex[29].txt
C:\profbackup\Cookies\s1288@mediaplex[2].txt
C:\profbackup\Cookies\s1288@mediaplex[30].txt
C:\profbackup\Cookies\s1288@mediaplex[31].txt
C:\profbackup\Cookies\s1288@mediaplex[32].txt
C:\profbackup\Cookies\s1288@mediaplex[33].txt
C:\profbackup\Cookies\s1288@mediaplex[34].txt
C:\profbackup\Cookies\s1288@mediaplex[35].txt
C:\profbackup\Cookies\s1288@mediaplex[36].txt
C:\profbackup\Cookies\s1288@mediaplex[37].txt
C:\profbackup\Cookies\s1288@mediaplex[3].txt
C:\profbackup\Cookies\s1288@mediaplex[4].txt
C:\profbackup\Cookies\s1288@mediaplex[5].txt
C:\profbackup\Cookies\s1288@mediaplex[6].txt
C:\profbackup\Cookies\s1288@mediaplex[7].txt
C:\profbackup\Cookies\s1288@mediaplex[8].txt
C:\profbackup\Cookies\s1288@mediaplex[9].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\s1288@overture[1].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][3].txt
C:\profbackup\Cookies\s1288@questionmarket[1].txt
C:\profbackup\Cookies\s1288@questionmarket[2].txt
C:\profbackup\Cookies\s1288@questionmarket[3].txt
C:\profbackup\Cookies\s1288@realmedia[2].txt
C:\profbackup\Cookies\s1288@revsci[2].txt
C:\profbackup\Cookies\s1288@roiservice[1].txt
C:\profbackup\Cookies\s1288@roiservice[2].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][6].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][3].txt
C:\profbackup\Cookies\[email protected][4].txt
C:\profbackup\Cookies\[email protected][5].txt
C:\profbackup\Cookies\[email protected][7].txt
C:\profbackup\Cookies\[email protected][8].txt
C:\profbackup\Cookies\[email protected][9].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][3].txt
C:\profbackup\Cookies\s1288@serving-sys[1].txt
C:\profbackup\Cookies\s1288@serving-sys[2].txt
C:\profbackup\Cookies\s1288@serving-sys[3].txt
C:\profbackup\Cookies\s1288@serving-sys[4].txt
C:\profbackup\Cookies\s1288@serving-sys[5].txt
C:\profbackup\Cookies\s1288@sexlist[2].txt
C:\profbackup\Cookies\s1288@sextracker[2].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\s1288@statcounter[1].txt
C:\profbackup\Cookies\s1288@statcounter[2].txt
C:\profbackup\Cookies\s1288@statcounter[3].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\s1288@superstats[1].txt
C:\profbackup\Cookies\s1288@superstats[2].txt
C:\profbackup\Cookies\s1288@superstats[3].txt
C:\profbackup\Cookies\s1288@superstats[4].txt
C:\profbackup\Cookies\s1288@superstats[5].txt
C:\profbackup\Cookies\s1288@tacoda[2].txt
C:\profbackup\Cookies\[email protected][22].txt
C:\profbackup\Cookies\[email protected][10].txt
C:\profbackup\Cookies\[email protected][11].txt
C:\profbackup\Cookies\[email protected][12].txt
C:\profbackup\Cookies\[email protected][13].txt
C:\profbackup\Cookies\[email protected][14].txt
C:\profbackup\Cookies\[email protected][15].txt
C:\profbackup\Cookies\[email protected][16].txt
C:\profbackup\Cookies\[email protected][17].txt
C:\profbackup\Cookies\[email protected][18].txt
C:\profbackup\Cookies\[email protected][19].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][20].txt
C:\profbackup\Cookies\[email protected][21].txt
C:\profbackup\Cookies\[email protected][36].txt
C:\profbackup\Cookies\[email protected][23].txt
C:\profbackup\Cookies\[email protected][24].txt
C:\profbackup\Cookies\[email protected][25].txt
C:\profbackup\Cookies\[email protected][26].txt
C:\profbackup\Cookies\[email protected][27].txt
C:\profbackup\Cookies\[email protected][28].txt
C:\profbackup\Cookies\[email protected][29].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][30].txt
C:\profbackup\Cookies\[email protected][31].txt
C:\profbackup\Cookies\[email protected][32].txt
C:\profbackup\Cookies\[email protected][33].txt
C:\profbackup\Cookies\[email protected][34].txt
C:\profbackup\Cookies\[email protected][35].txt
C:\profbackup\Cookies\[email protected][4].txt
C:\profbackup\Cookies\[email protected][37].txt
C:\profbackup\Cookies\[email protected][38].txt
C:\profbackup\Cookies\[email protected][39].txt
C:\profbackup\Cookies\[email protected][3].txt
C:\profbackup\Cookies\[email protected][40].txt
C:\profbackup\Cookies\[email protected][41].txt
C:\profbackup\Cookies\[email protected][42].txt
C:\profbackup\Cookies\[email protected][43].txt
C:\profbackup\Cookies\[email protected][44].txt
C:\profbackup\Cookies\[email protected][45].txt
C:\profbackup\Cookies\[email protected][46].txt
C:\profbackup\Cookies\[email protected][47].txt
C:\profbackup\Cookies\[email protected][48].txt
C:\profbackup\Cookies\[email protected][49].txt
C:\profbackup\Cookies\[email protected][63].txt
C:\profbackup\Cookies\[email protected][50].txt
C:\profbackup\Cookies\[email protected][51].txt
C:\profbackup\Cookies\[email protected][52].txt
C:\profbackup\Cookies\[email protected][53].txt
C:\profbackup\Cookies\[email protected][54].txt
C:\profbackup\Cookies\[email protected][55].txt
C:\profbackup\Cookies\[email protected][56].txt
C:\profbackup\Cookies\[email protected][57].txt
C:\profbackup\Cookies\[email protected][58].txt
C:\profbackup\Cookies\[email protected][59].txt
C:\profbackup\Cookies\[email protected][5].txt
C:\profbackup\Cookies\[email protected][60].txt
C:\profbackup\Cookies\[email protected][61].txt
C:\profbackup\Cookies\[email protected][62].txt
C:\profbackup\Cookies\[email protected][77].txt
C:\profbackup\Cookies\[email protected][64].txt
C:\profbackup\Cookies\[email protected][65].txt
C:\profbackup\Cookies\[email protected][66].txt
C:\profbackup\Cookies\[email protected][67].txt
C:\profbackup\Cookies\[email protected][68].txt
C:\profbackup\Cookies\[email protected][69].txt
C:\profbackup\Cookies\[email protected][6].txt
C:\profbackup\Cookies\[email protected][70].txt
C:\profbackup\Cookies\[email protected][71].txt
C:\profbackup\Cookies\[email protected][72].txt
C:\profbackup\Cookies\[email protected][73].txt
C:\profbackup\Cookies\[email protected][74].txt
C:\profbackup\Cookies\[email protected][75].txt
C:\profbackup\Cookies\[email protected][76].txt
C:\profbackup\Cookies\s1288@tradedoubler[10].txt
C:\profbackup\Cookies\[email protected][78].txt
C:\profbackup\Cookies\[email protected][79].txt
C:\profbackup\Cookies\[email protected][7].txt
C:\profbackup\Cookies\[email protected][80].txt
C:\profbackup\Cookies\[email protected][81].txt
C:\profbackup\Cookies\[email protected][82].txt
C:\profbackup\Cookies\[email protected][83].txt
C:\profbackup\Cookies\[email protected][84].txt
C:\profbackup\Cookies\[email protected][8].txt
C:\profbackup\Cookies\[email protected][9].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][4].txt
C:\profbackup\Cookies\s1288@tradedoubler[24].txt
C:\profbackup\Cookies\s1288@tradedoubler[11].txt
C:\profbackup\Cookies\s1288@tradedoubler[12].txt
C:\profbackup\Cookies\s1288@tradedoubler[13].txt
C:\profbackup\Cookies\s1288@tradedoubler[14].txt
C:\profbackup\Cookies\s1288@tradedoubler[15].txt
C:\profbackup\Cookies\s1288@tradedoubler[16].txt
C:\profbackup\Cookies\s1288@tradedoubler[17].txt
C:\profbackup\Cookies\s1288@tradedoubler[18].txt
C:\profbackup\Cookies\s1288@tradedoubler[19].txt
C:\profbackup\Cookies\s1288@tradedoubler[1].txt
C:\profbackup\Cookies\s1288@tradedoubler[20].txt
C:\profbackup\Cookies\s1288@tradedoubler[21].txt
C:\profbackup\Cookies\s1288@tradedoubler[22].txt
C:\profbackup\Cookies\s1288@tradedoubler[23].txt
C:\profbackup\Cookies\s1288@tradedoubler[25].txt
C:\profbackup\Cookies\s1288@tradedoubler[26].txt
C:\profbackup\Cookies\s1288@tradedoubler[27].txt
C:\profbackup\Cookies\s1288@tradedoubler[28].txt
C:\profbackup\Cookies\s1288@tradedoubler[2].txt
C:\profbackup\Cookies\s1288@tradedoubler[3].txt
C:\profbackup\Cookies\s1288@tradedoubler[4].txt
C:\profbackup\Cookies\s1288@tradedoubler[5].txt
C:\profbackup\Cookies\s1288@tradedoubler[6].txt
C:\profbackup\Cookies\s1288@tradedoubler[7].txt
C:\profbackup\Cookies\s1288@tradedoubler[8].txt
C:\profbackup\Cookies\s1288@tradedoubler[9].txt
C:\profbackup\Cookies\s1288@tribalfusion[1].txt
C:\profbackup\Cookies\s1288@valueclick[2].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][1].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][3].txt
C:\profbackup\Cookies\[email protected][4].txt
C:\profbackup\Cookies\[email protected][2].txt
C:\profbackup\Cookies\[email protected][1].txt

Rogue.VirusHeat
HKCR\TypeLib\{83B0CADC-EA64-4AC6-822A-3ECE95F44DA6}
HKCR\TypeLib\{83B0CADC-EA64-4AC6-822A-3ECE95F44DA6}\1.0
HKCR\TypeLib\{83B0CADC-EA64-4AC6-822A-3ECE95F44DA6}\1.0
HKCR\TypeLib\{83B0CADC-EA64-4AC6-822A-3ECE95F44DA6}\1.0\win32
HKCR\TypeLib\{83B0CADC-EA64-4AC6-822A-3ECE95F44DA6}\1.0\FLAGS
HKCR\TypeLib\{83B0CADC-EA64-4AC6-822A-3ECE95F44DA6}\1.0\HELPDIR
HKCR\Interface\{14E6D991-DB22-4661-981D-20C168D6847B}
HKCR\Interface\{14E6D991-DB22-4661-981D-20C168D6847B}\ProxyStubClsid
HKCR\Interface\{14E6D991-DB22-4661-981D-20C168D6847B}\ProxyStubClsid32
HKCR\Interface\{14E6D991-DB22-4661-981D-20C168D6847B}\TypeLib
HKCR\Interface\{14E6D991-DB22-4661-981D-20C168D6847B}\TypeLib#Version
HKCR\Interface\{2242513C-F5E9-41B3-BC89-4D9DAF487450}
HKCR\Interface\{2242513C-F5E9-41B3-BC89-4D9DAF487450}\ProxyStubClsid
HKCR\Interface\{2242513C-F5E9-41B3-BC89-4D9DAF487450}\ProxyStubClsid32
HKCR\Interface\{2242513C-F5E9-41B3-BC89-4D9DAF487450}\TypeLib
HKCR\Interface\{2242513C-F5E9-41B3-BC89-4D9DAF487450}\TypeLib#Version
HKCR\Interface\{3B489B37-FC1B-45C8-B1CE-78D9AEF5B336}
HKCR\Interface\{3B489B37-FC1B-45C8-B1CE-78D9AEF5B336}\ProxyStubClsid
HKCR\Interface\{3B489B37-FC1B-45C8-B1CE-78D9AEF5B336}\ProxyStubClsid32
HKCR\Interface\{3B489B37-FC1B-45C8-B1CE-78D9AEF5B336}\TypeLib
HKCR\Interface\{3B489B37-FC1B-45C8-B1CE-78D9AEF5B336}\TypeLib#Version
HKCR\Interface\{3D6A6E24-FDFF-418E-A93D-9FBDCBA377AF}
HKCR\Interface\{3D6A6E24-FDFF-418E-A93D-9FBDCBA377AF}\ProxyStubClsid
HKCR\Interface\{3D6A6E24-FDFF-418E-A93D-9FBDCBA377AF}\ProxyStubClsid32
HKCR\Interface\{3D6A6E24-FDFF-418E-A93D-9FBDCBA377AF}\TypeLib
HKCR\Interface\{3D6A6E24-FDFF-418E-A93D-9FBDCBA377AF}\TypeLib#Version
HKCR\Interface\{3E318E44-0C35-4292-AF91-18DD17795636}
HKCR\Interface\{3E318E44-0C35-4292-AF91-18DD17795636}\ProxyStubClsid
HKCR\Interface\{3E318E44-0C35-4292-AF91-18DD17795636}\ProxyStubClsid32
HKCR\Interface\{3E318E44-0C35-4292-AF91-18DD17795636}\TypeLib
HKCR\Interface\{3E318E44-0C35-4292-AF91-18DD17795636}\TypeLib#Version
HKCR\Interface\{495349A3-3A35-465F-88DF-6CCFC1348246}
HKCR\Interface\{495349A3-3A35-465F-88DF-6CCFC1348246}\ProxyStubClsid
HKCR\Interface\{495349A3-3A35-465F-88DF-6CCFC1348246}\ProxyStubClsid32
HKCR\Interface\{495349A3-3A35-465F-88DF-6CCFC1348246}\TypeLib
HKCR\Interface\{495349A3-3A35-465F-88DF-6CCFC1348246}\TypeLib#Version
HKCR\Interface\{575E8879-D6CF-4992-A7FE-651DA9277BCB}
HKCR\Interface\{575E8879-D6CF-4992-A7FE-651DA9277BCB}\ProxyStubClsid
HKCR\Interface\{575E8879-D6CF-4992-A7FE-651DA9277BCB}\ProxyStubClsid32
HKCR\Interface\{575E8879-D6CF-4992-A7FE-651DA9277BCB}\TypeLib
HKCR\Interface\{575E8879-D6CF-4992-A7FE-651DA9277BCB}\TypeLib#Version
HKCR\Interface\{76A15001-FF88-47EE-9E34-9F68E34246AF}
HKCR\Interface\{76A15001-FF88-47EE-9E34-9F68E34246AF}\ProxyStubClsid
HKCR\Interface\{76A15001-FF88-47EE-9E34-9F68E34246AF}\ProxyStubClsid32
HKCR\Interface\{76A15001-FF88-47EE-9E34-9F68E34246AF}\TypeLib
HKCR\Interface\{76A15001-FF88-47EE-9E34-9F68E34246AF}\TypeLib#Version
HKCR\Interface\{819A1C55-735F-4696-8727-3772EC87AD26}
HKCR\Interface\{819A1C55-735F-4696-8727-3772EC87AD26}\ProxyStubClsid
HKCR\Interface\{819A1C55-735F-4696-8727-3772EC87AD26}\ProxyStubClsid32
HKCR\Interface\{819A1C55-735F-4696-8727-3772EC87AD26}\TypeLib
HKCR\Interface\{819A1C55-735F-4696-8727-3772EC87AD26}\TypeLib#Version
HKCR\Interface\{8DC7E656-FFBC-4BA2-AF81-1C6C4FE04407}
HKCR\Interface\{8DC7E656-FFBC-4BA2-AF81-1C6C4FE04407}\ProxyStubClsid
HKCR\Interface\{8DC7E656-FFBC-4BA2-AF81-1C6C4FE04407}\ProxyStubClsid32
HKCR\Interface\{8DC7E656-FFBC-4BA2-AF81-1C6C4FE04407}\TypeLib
HKCR\Interface\{8DC7E656-FFBC-4BA2-AF81-1C6C4FE04407}\TypeLib#Version
HKCR\Interface\{A86BED71-2B56-4778-9C48-829A3D01C687}
HKCR\Interface\{A86BED71-2B56-4778-9C48-829A3D01C687}\ProxyStubClsid
HKCR\Interface\{A86BED71-2B56-4778-9C48-829A3D01C687}\ProxyStubClsid32
HKCR\Interface\{A86BED71-2B56-4778-9C48-829A3D01C687}\TypeLib
HKCR\Interface\{A86BED71-2B56-4778-9C48-829A3D01C687}\TypeLib#Version
HKCR\Interface\{AE119E11-CF86-43CB-91AA-1ACF2BBF9EC6}
HKCR\Interface\{AE119E11-CF86-43CB-91AA-1ACF2BBF9EC6}\ProxyStubClsid
HKCR\Interface\{AE119E11-CF86-43CB-91AA-1ACF2BBF9EC6}\ProxyStubClsid32
HKCR\Interface\{AE119E11-CF86-43CB-91AA-1ACF2BBF9EC6}\TypeLib
HKCR\Interface\{AE119E11-CF86-43CB-91AA-1ACF2BBF9EC6}\TypeLib#Version
HKCR\Interface\{B5A1CE7F-011D-4475-98DB-076AAF3B1D18}
HKCR\Interface\{B5A1CE7F-011D-4475-98DB-076AAF3B1D18}\ProxyStubClsid
HKCR\Interface\{B5A1CE7F-011D-4475-98DB-076AAF3B1D18}\ProxyStubClsid32
HKCR\Interface\{B5A1CE7F-011D-4475-98DB-076AAF3B1D18}\TypeLib
HKCR\Interface\{B5A1CE7F-011D-4475-98DB-076AAF3B1D18}\TypeLib#Version
HKCR\Interface\{B667F141-171C-4AC6-BD2B-8E0C646FB920}
HKCR\Interface\{B667F141-171C-4AC6-BD2B-8E0C646FB920}\ProxyStubClsid
HKCR\Interface\{B667F141-171C-4AC6-BD2B-8E0C646FB920}\ProxyStubClsid32
HKCR\Interface\{B667F141-171C-4AC6-BD2B-8E0C646FB920}\TypeLib
HKCR\Interface\{B667F141-171C-4AC6-BD2B-8E0C646FB920}\TypeLib#Version
HKCR\Interface\{DA4F8351-05EF-4956-B9AB-1093B732436F}
HKCR\Interface\{DA4F8351-05EF-4956-B9AB-1093B732436F}\ProxyStubClsid
HKCR\Interface\{DA4F8351-05EF-4956-B9AB-1093B732436F}\ProxyStubClsid32
HKCR\Interface\{DA4F8351-05EF-4956-B9AB-1093B732436F}\TypeLib
HKCR\Interface\{DA4F8351-05EF-4956-B9AB-1093B732436F}\TypeLib#Version
HKCR\Interface\{E1E4E46D-53B8-45DC-ABF0-3E7ADEF79012}
HKCR\Interface\{E1E4E46D-53B8-45DC-ABF0-3E7ADEF79012}\ProxyStubClsid
HKCR\Interface\{E1E4E46D-53B8-45DC-ABF0-3E7ADEF79012}\ProxyStubClsid32
HKCR\Interface\{E1E4E46D-53B8-45DC-ABF0-3E7ADEF79012}\TypeLib
HKCR\Interface\{E1E4E46D-53B8-45DC-ABF0-3E7ADEF79012}\TypeLib#Version

Rogue.WinPCDoctor
C:\Program Files\Common Files\WinPCDoctor
C:\Program Files\WinPCDoctor\swupd.log
C:\Program Files\WinPCDoctor

Lenke til kommentar

Fint.

 

Du kan da avlutte med å fjerne combofix ved å skrive combofix /u fra kjør-feltet (start->kjør).

Dette vil også nullstille systemgjenopprettingen slik at du ikke blir infisert ved en evt. systemgjenoppretting senere.

 

Surf trygt.

Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...