Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 09-25-2006, 04:17 PM   #1 (permalink)
Registered User
 
Join Date: Sep 2006
Posts: 7
OS: winxp


Going crazy, need help

Hey guys,
I have a feeling that I have something on my computer that is slowing it down and allowing others to access my computer. I have been racking my brain and cant find anything. Here is my Hijackthis file, any help would be greatly appreciated.


Logfile of HijackThis v1.99.1
Scan saved at 3:00:19 PM, on 9/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Common Files\AOL\1158002726\ee\AOLSoftware.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~2\NORTON~2\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\SECURI~2\NSCSRVCE.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Winamp\Winamp.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Roxio\Easy CD Creator 6\Easy CD Creator\creatorc.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\Documents and Settings\Casey Crowell\My Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/mor...on/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com.../fix_homepage/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: IeCaptureBho Object - {7c1ce531-09e9-4fc5-9803-1c2956615786} - (no file)
O2 - BHO: Norton Personal Firewall 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: (no name) - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - (no file)
O3 - Toolbar: Norton Personal Firewall 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1158002726\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WindowEnhancer] "C:\Program Files\winex\v2\winex.EXE" /U
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [Spyware Nuker Installer] C:\Documents and Settings\Casey Crowell\My Documents\SpywareNukerInstaller.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [ConMgr.exe] "C:\Program Files\EarthLink 5.0\ConMgr.exe"
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {0585238B-9CA6-4CCB-A9B2-FE4BA495E880} (AXWebMon Control) - http://www.smilecam.com/home/ezwebca...ebMonProj1.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://us.creative.com/support/downl...19/CTSUEng.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/085a4e9cec26591...zip/RdxIE2.cab
O16 - DPF: {5763F8E8-0DD7-4A0F-ADB0-9F64C8F2C349} (Pixami/Snapfish Upload UI Control) - http://www.snapfish.com/SnapfishUploader.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://216.120.80.145/activex/AxisCamControl.cab
O16 - DPF: {A8739816-022C-11D6-A85D-00C04F9AEAFB} (Web Camera Server Control) - http://216.120.80.148/wg_webeye.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/def...ploader_v5.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://us.creative.com/support/downl...2119/CTPID.cab
O16 - DPF: {FDDCE9FF-1FC6-413C-80B1-37B101FDA1D4} - http://download.buddylinks.net/ShellInstaller.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~2\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
greenh is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 09-26-2006, 09:30 PM   #2 (permalink)
Registered User
 
Join Date: Sep 2006
Posts: 7
OS: winxp


bump!
greenh is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 09-27-2006, 08:34 PM   #3 (permalink)
Security Team (ret.)
 
Pancake's Avatar
 
Join Date: Nov 2003
Location: Victoria.Australia
Posts: 7,404
OS: XP Pro SP3


Hi....

We need to stop TeaTimer from running as changes to the log may not be saved.Right click Spybot's TeaTimer System Tray Icon(the lock symbol is just part of the icon and does not mean it is locked preventing using it) > click Exit Spybot-S&D Resident.


Uninstall Spyware Nuker using the Add/Remove Programs utility


Step 1: Download and install Ewido Anti-Spyware v4.0
1. After download, double click on the file to launch the install process.
2. Choose a language, click "OK" and then click "Next".
3. Read the "License Agreement" and click "I Agree".
4. Accept default installation path: C:\Program Files\ewido anti-spyware 4.0, click "Next", then click "Install".
5. After setup completes, click "Finish" to start the program automatically or launch ewido by double-clicking its icon on your desktop or in the system tray.
6. The main "Status" menu will appear. Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'.
7. Then right click on ewdio in the system tray and uncheck "Start with Windows".
8. Go to Start > Run and type: services.msc
  • Press "OK".
  • Click the "Extended tab" and scroll down the list to find ewido anti-spyware 4.0 guard.
  • When you find the guard service, double-click on it.
  • In the Properties Window > General Tab that opens, click the "Stop" button.
  • From the drop-down menu next to "Startup Type", click on "Manual".
  • Now click "Apply", then "OK" and close the Services window.
9. Select the "Update" button and click "Start update". If you are having problems with the updater, manually update with the Ewido Full database installer from here. Exit Ewido when done - DO NOT perform a scan yet.

Step 2: Reboot your computer in SAFE MODE" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup [but before the Windows icon appears] press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Step 3: Scan with Ewido as follows:
1. Launch Ewido, click on the "Scanner" button and choose the "Settings" tab.
  • Under "How to act?", click on "Recommended actions" and choose "Quarantine" to set default action for detected malware.
  • Under "How to Scan?" check all (default).
  • Under "Possibly unwanted software" check all (default).
  • Under "What to Scan?" make sure "Scan every file" is selected (default).
  • Under "Reports" select "Automatically generate report after every scan and UNcheck "Only if threats were found".
2. Click the "Scan" tab to return to scanning options.
3. Click "Complete System Scan" to start.
4. When the scan has finished you will be presented with a list of infected objects found. Click "Apply all actions" to place the files in Quarantine.

IMPORTANT! Do not save the report before you have clicked the Apply all actions button. If you do, the log that is created will indicate "No action taken", making it more difficult to interpret the report. So be sure you save it only AFTER clicking the "Apply all actions" button?

5. Click on "Save Report" to view all completed scans. Click on the most recent scan you just performed and select "Save report as" - the default file name will be in date/time format as follows: Report-Scan-20060620-142816.txt. Save to your desktop. A copy of each report will also be saved in C:\Program Files\ewido anti-spyware 4.0\Reports\
6. Exit Ewido when done and submit the log report in your next response. .






Have "Hijack This" fix all the following items in the list below by placing a check in the appropriate boxes.Confirm that you have only the listed ones checked, then press <Fix checked> and Close HJT.

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
O4 - HKLM\..\Run: [WindowEnhancer] "C:\Program Files\winex\v2\winex.EXE" /U
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [Spyware Nuker Installer] C:\Documents and Settings\Casey Crowell\My Documents\SpywareNukerInstaller.exe
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/085a4e9cec26591...zip/RdxIE2.cab
O16 - DPF: {FDDCE9FF-1FC6-413C-80B1-37B101FDA1D4} - http://download.buddylinks.net/ShellInstaller.cab

Open Windows Explorer and delete the following red folder/s if still present.

C:\Program Files\ winex
C:\Program Files\Common Files\ CMEII
C:\Program Files\ Date Manager
C:\Program Files\Common Files\ GMT
C:\Program Files\ PrecisionTime



Please download ATF Cleaner by Atribune
http://www.atribune.org/public-beta/ATF-Cleaner.exe
Save it to your Desktop.

Double-click ATF-Cleaner.exe to run the program.
Click Select All found at the bottom of the list.
Click the Empty Selected button.
Click Exit on the Main menu to close the program.

Reboot an post a new HJT log
__________________
Eddy

Last edited by Pancake; 09-27-2006 at 08:37 PM.
Pancake is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 10-07-2006, 05:26 PM   #4 (permalink)
Registered User
 
Join Date: Sep 2006
Posts: 7
OS: winxp


---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 4:02:45 PM 10/7/2006

+ Scan result:



C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined).
C:\WINDOWS\NDNuninstall4_80.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\S-1-5-21-480437244-2693076698-917563655-1006\Software\DNS -> Adware.Shorty : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Cleaned with backup (quarantined).
C:\Documents and Settings\Casey Crowell\.jpi_cache\jar\1.0\archive.jar-487b52a0-598a1454.zip/Beyond.class -> Dropper.Beyond.g : Cleaned with backup (quarantined).
C:\Documents and Settings\Casey Crowell\.jpi_cache\jar\1.0\archive.jar-487b52a0-598a1454.zip/BlackBox.class -> Dropper.Beyond.g : Cleaned with backup (quarantined).
C:\Documents and Settings\Casey Crowell\.jpi_cache\jar\1.0\ar3.jar-5157872c-2efd1d23.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup (quarantined).
C:\Documents and Settings\Casey Crowell\.jpi_cache\jar\1.0\ar3.jar-58581c27-4ccaf97a.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup (quarantined).
C:\Documents and Settings\Casey Crowell\.jpi_cache\jar\1.0\ar3.jar-5ef20017-47ed25e1.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup (quarantined).
C:\Documents and Settings\Casey Crowell\.jpi_cache\jar\1.0\ar3.jar-6198e311-4f3cc325.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup (quarantined).
C:\Documents and Settings\Casey Crowell\.jpi_cache\jar\1.0\ar3.jar-6afd3e27-4641938a.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup (quarantined).
C:\Documents and Settings\Casey Crowell\.jpi_cache\jar\1.0\ar3.jar-7765947f-223082c0.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup (quarantined).
C:\Documents and Settings\Casey Crowell\.jpi_cache\jar\1.0\archive.jar-49e9e171-4d58aeda.zip/Dummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup (quarantined).
C:\Documents and Settings\Casey Crowell\.jpi_cache\jar\1.0\loaderadv101.jar-77bf84d4-2160c61b.zip/Dummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup (quarantined).
C:\Documents and Settings\Casey Crowell\.jpi_cache\jar\1.0\loaderadv500.jar-3add8624-335dd313.zip/Dummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup (quarantined).
C:\install.htm -> Not-A-Virus.Exploit.DialogArg : Cleaned with backup (quarantined).
C:\Documents and Settings\Casey Crowell\.jpi_cache\jar\1.0\archive.jar-1803745e-452cb2ab.zip/A.class -> Not-A-Virus.Exploit.Java.Bytverify : Cleaned with backup (quarantined).
C:\Documents and Settings\Casey Crowell\.jpi_cache\jar\1.0\archive.jar-4926543b-39ac81e6.zip/A.class -> Not-A-Virus.Exploit.Java.Bytverify : Cleaned with backup (quarantined).
:mozilla.19:C:\RECYCLER\NPROTECT\00000414.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\00000415.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.23:C:\RECYCLER\NPROTECT\00000418.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.26:C:\RECYCLER\NPROTECT\00000420.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.30:C:\RECYCLER\NPROTECT\00000421.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.30:C:\RECYCLER\NPROTECT\00000422.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.30:C:\RECYCLER\NPROTECT\00000423.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.30:C:\RECYCLER\NPROTECT\00000424.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.32:C:\RECYCLER\NPROTECT\00000425.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.32:C:\RECYCLER\NPROTECT\00000426.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.32:C:\RECYCLER\NPROTECT\00000427.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.32:C:\RECYCLER\NPROTECT\00000428.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\RECYCLER\NPROTECT\00000429.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\RECYCLER\NPROTECT\00000430.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\RECYCLER\NPROTECT\00000431.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\RECYCLER\NPROTECT\00000432.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\RECYCLER\NPROTECT\00000433.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\RECYCLER\NPROTECT\00000434.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\RECYCLER\NPROTECT\00000435.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\RECYCLER\NPROTECT\00000436.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\RECYCLER\NPROTECT\00000437.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\RECYCLER\NPROTECT\00000439.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\RECYCLER\NPROTECT\00000440.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\RECYCLER\NPROTECT\00000441.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\RECYCLER\NPROTECT\00000639.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\RECYCLER\NPROTECT\00000648.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.37:C:\RECYCLER\NPROTECT\00000442.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.37:C:\RECYCLER\NPROTECT\00000444.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.37:C:\RECYCLER\NPROTECT\00000447.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.37:C:\RECYCLER\NPROTECT\00000638.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.38:C:\RECYCLER\NPROTECT\00000649.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.38:C:\RECYCLER\NPROTECT\00000654.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.38:C:\RECYCLER\NPROTECT\00000655.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.40:C:\RECYCLER\NPROTECT\00000656.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.40:C:\RECYCLER\NPROTECT\00000657.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.40:C:\RECYCLER\NPROTECT\00000659.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.42:C:\RECYCLER\NPROTECT\00000660.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.42:C:\RECYCLER\NPROTECT\00000661.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.42:C:\RECYCLER\NPROTECT\00000662.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.42:C:\RECYCLER\NPROTECT\00000713.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.44:C:\RECYCLER\NPROTECT\00000784.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.45:C:\RECYCLER\NPROTECT\00000788.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.55:C:\RECYCLER\NPROTECT\00000789.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.55:C:\RECYCLER\NPROTECT\00000855.MOZ -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@ad-flow[1].txt -> TrackingCookie.Ad-flow : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@t1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@z1.adserver[2].txt -> TrackingCookie.Adserver : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@servedby.advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.10:C:\RECYCLER\NPROTECT\00001485.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.10:C:\RECYCLER\NPROTECT\00001507.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00001259.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.15:C:\RECYCLER\NPROTECT\00001511.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\00001502.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\00001503.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\00001504.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\00001514.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\00001505.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\00001547.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\00001486.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\00001487.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\00001488.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\00001491.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\00001497.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\00001498.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\00001499.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\00001551.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\00001552.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.9:C:\RECYCLER\NPROTECT\00001254.MOZ -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@bestoffersnetworks[2].txt -> TrackingCookie.Bestoffersnetworks : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@bfast[2].txt -> TrackingCookie.Bfast : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@centrport[1].txt -> TrackingCookie.Centrport : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@cz3.clickzs[1].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@cz4.clickzs[1].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@cz6.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@cz7.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@cliks[2].txt -> TrackingCookie.Cliks : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00002276.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00002277.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00002278.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00002279.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00002280.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00002281.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00002282.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00002284.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.16:C:\Documents and Settings\Casey Crowell\Application Data\Mozilla\Firefox\Profiles\rf14mi4j.Default User\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\00001251.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\00002285.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\00002288.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\00002302.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\00002340.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\00001502.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\00001503.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\00001504.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\00001505.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.22:C:\RECYCLER\NPROTECT\00001254.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.23:C:\RECYCLER\NPROTECT\00001486.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.23:C:\RECYCLER\NPROTECT\00001487.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.23:C:\RECYCLER\NPROTECT\00001488.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.23:C:\RECYCLER\NPROTECT\00001491.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.23:C:\RECYCLER\NPROTECT\00001497.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.23:C:\RECYCLER\NPROTECT\00001498.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.23:C:\RECYCLER\NPROTECT\00001499.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.25:C:\RECYCLER\NPROTECT\00001259.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.25:C:\RECYCLER\NPROTECT\00001485.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.25:C:\RECYCLER\NPROTECT\00001507.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.26:C:\RECYCLER\NPROTECT\00001511.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.26:C:\RECYCLER\NPROTECT\00001514.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.26:C:\RECYCLER\NPROTECT\00001547.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.26:C:\RECYCLER\NPROTECT\00001551.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.26:C:\RECYCLER\NPROTECT\00001552.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.6:C:\RECYCLER\NPROTECT\00001250.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.6:C:\RECYCLER\NPROTECT\00002273.MOZ -> TrackingCookie.Com : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.10:C:\RECYCLER\NPROTECT\00000421.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.11:C:\RECYCLER\NPROTECT\00000424.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.11:C:\RECYCLER\NPROTECT\00000434.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.11:C:\RECYCLER\NPROTECT\00000435.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.11:C:\RECYCLER\NPROTECT\00000437.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.11:C:\RECYCLER\NPROTECT\00000439.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.12:C:\RECYCLER\NPROTECT\00000424.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.12:C:\RECYCLER\NPROTECT\00000434.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.12:C:\RECYCLER\NPROTECT\00000435.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.12:C:\RECYCLER\NPROTECT\00000436.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.12:C:\RECYCLER\NPROTECT\00000437.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.12:C:\RECYCLER\NPROTECT\00000439.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.12:C:\RECYCLER\NPROTECT\00000440.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.12:C:\RECYCLER\NPROTECT\00000441.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000422.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000423.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000424.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000425.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000426.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000427.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000428.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000429.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000430.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000431.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000432.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000433.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000434.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000435.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000436.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000437.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000439.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000440.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00000441.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00000425.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00000426.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00000427.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00000428.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00000434.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00000435.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00000436.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00000437.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00000439.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00000440.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00000441.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.15:C:\RECYCLER\NPROTECT\00000425.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.15:C:\RECYCLER\NPROTECT\00000426.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.15:C:\RECYCLER\NPROTECT\00000427.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.15:C:\RECYCLER\NPROTECT\00000428.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.15:C:\RECYCLER\NPROTECT\00000440.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.15:C:\RECYCLER\NPROTECT\00000441.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\00000442.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\00000444.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\00000447.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\00000638.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\00000789.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\00000442.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\00000444.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\00000447.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\00000638.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\00000789.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\00000442.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\00000444.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\00000447.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\00000638.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\00000789.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\00000442.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\00000444.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\00000447.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\00000638.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\00000789.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\00000855.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\00000855.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\00000639.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\00000648.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\00000855.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.22:C:\RECYCLER\NPROTECT\00000639.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.22:C:\RECYCLER\NPROTECT\00000648.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.22:C:\RECYCLER\NPROTECT\00000855.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.23:C:\RECYCLER\NPROTECT\00000639.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.23:C:\RECYCLER\NPROTECT\00000648.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.24:C:\RECYCLER\NPROTECT\00000639.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.24:C:\RECYCLER\NPROTECT\00000648.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.26:C:\RECYCLER\NPROTECT\00000649.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.26:C:\RECYCLER\NPROTECT\00000654.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.26:C:\RECYCLER\NPROTECT\00000655.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.27:C:\RECYCLER\NPROTECT\00000649.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.27:C:\RECYCLER\NPROTECT\00000654.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.27:C:\RECYCLER\NPROTECT\00000655.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.28:C:\RECYCLER\NPROTECT\00000415.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.28:C:\RECYCLER\NPROTECT\00000649.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.28:C:\RECYCLER\NPROTECT\00000654.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.28:C:\RECYCLER\NPROTECT\00000655.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.28:C:\RECYCLER\NPROTECT\00000656.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.28:C:\RECYCLER\NPROTECT\00000657.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.29:C:\RECYCLER\NPROTECT\00000414.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.29:C:\RECYCLER\NPROTECT\00000415.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.29:C:\RECYCLER\NPROTECT\00000418.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.29:C:\RECYCLER\NPROTECT\00000649.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.29:C:\RECYCLER\NPROTECT\00000654.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.29:C:\RECYCLER\NPROTECT\00000655.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.29:C:\RECYCLER\NPROTECT\00000656.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.29:C:\RECYCLER\NPROTECT\00000657.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.29:C:\RECYCLER\NPROTECT\00000659.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.30:C:\RECYCLER\NPROTECT\00000414.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.30:C:\RECYCLER\NPROTECT\00000418.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.30:C:\RECYCLER\NPROTECT\00000420.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.30:C:\RECYCLER\NPROTECT\00000656.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.30:C:\RECYCLER\NPROTECT\00000657.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.30:C:\RECYCLER\NPROTECT\00000659.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.31:C:\RECYCLER\NPROTECT\00000420.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.31:C:\RECYCLER\NPROTECT\00000656.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.31:C:\RECYCLER\NPROTECT\00000657.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.31:C:\RECYCLER\NPROTECT\00000659.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.31:C:\RECYCLER\NPROTECT\00000660.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.31:C:\RECYCLER\NPROTECT\00000661.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.31:C:\RECYCLER\NPROTECT\00000662.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.31:C:\RECYCLER\NPROTECT\00000713.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.32:C:\RECYCLER\NPROTECT\00000659.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.32:C:\RECYCLER\NPROTECT\00000660.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.32:C:\RECYCLER\NPROTECT\00000661.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.32:C:\RECYCLER\NPROTECT\00000662.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.32:C:\RECYCLER\NPROTECT\00000713.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.33:C:\RECYCLER\NPROTECT\00000660.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.33:C:\RECYCLER\NPROTECT\00000661.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.33:C:\RECYCLER\NPROTECT\00000662.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.33:C:\RECYCLER\NPROTECT\00000713.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.34:C:\RECYCLER\NPROTECT\00000660.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.34:C:\RECYCLER\NPROTECT\00000661.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.34:C:\RECYCLER\NPROTECT\00000662.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.34:C:\RECYCLER\NPROTECT\00000713.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.34:C:\RECYCLER\NPROTECT\00000784.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.35:C:\RECYCLER\NPROTECT\00000784.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.35:C:\RECYCLER\NPROTECT\00000788.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.36:C:\RECYCLER\NPROTECT\00000784.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.36:C:\RECYCLER\NPROTECT\00000788.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.37:C:\RECYCLER\NPROTECT\00000784.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.37:C:\RECYCLER\NPROTECT\00000788.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.38:C:\RECYCLER\NPROTECT\00000788.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.6:C:\RECYCLER\NPROTECT\00000429.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\00000421.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\00000422.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\00000423.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\00000429.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\00000430.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\00000431.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\00000432.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\00000433.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\00000436.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.8:C:\RECYCLER\NPROTECT\00000421.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.8:C:\RECYCLER\NPROTECT\00000422.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.8:C:\RECYCLER\NPROTECT\00000423.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.8:C:\RECYCLER\NPROTECT\00000430.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.8:C:\RECYCLER\NPROTECT\00000431.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.8:C:\RECYCLER\NPROTECT\00000432.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.8:C:\RECYCLER\NPROTECT\00000433.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.9:C:\RECYCLER\NPROTECT\00000429.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.9:C:\RECYCLER\NPROTECT\00000430.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.9:C:\RECYCLER\NPROTECT\00000431.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.9:C:\RECYCLER\NPROTECT\00000432.MOZ -> TrackingCookie.Fastclick : Cleaned.
:mozilla.9:C:\RECYCLER\NPROTECT\00000433.MOZ -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@fastclick[3].txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00001507.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\00001511.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\00001514.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\00001547.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\00001551.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\00001552.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.6:C:\RECYCLER\NPROTECT\00001505.MOZ -> TrackingCookie.Googleadservices : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@ehg-intel.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@hg1.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@adserv.internetfuel[1].txt -> TrackingCookie.Internetfuel : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@linksynergy[1].txt -> TrackingCookie.Linksynergy : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@paycounter[1].txt -> TrackingCookie.Paycounter : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@paycounter[2].txt -> TrackingCookie.Paycounter : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@www.qksrv[1].txt -> TrackingCookie.Qksrv : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@c.sexcounter[1].txt -> TrackingCookie.Sexcounter : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@c.sexcounter[2].txt -> TrackingCookie.Sexcounter : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@sexlist[1].txt -> TrackingCookie.Sexlist : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@sexlist[2].txt -> TrackingCookie.Sexlist : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter1.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter10.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter10.sextracker[2].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter12.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter13.sextracker[2].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter14.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter14.sextracker[2].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter16.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter16.sextracker[2].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter2.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter2.sextracker[2].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter3.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter3.sextracker[2].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter5.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter6.sextracker[2].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter7.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter7.sextracker[2].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter8.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@counter9.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@sextracker[2].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.11:C:\RECYCLER\NPROTECT\00001870.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.11:C:\RECYCLER\NPROTECT\00001879.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00002024.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00001485.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00001880.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00001882.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00001896.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00001909.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00001910.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00001911.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00001912.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00001913.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00002024.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00002175.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\00002273.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.15:C:\RECYCLER\NPROTECT\00000421.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.15:C:\RECYCLER\NPROTECT\00000422.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.15:C:\RECYCLER\NPROTECT\00000423.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.15:C:\RECYCLER\NPROTECT\00000424.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.15:C:\RECYCLER\NPROTECT\00001916.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.15:C:\RECYCLER\NPROTECT\00002175.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\00000425.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\00000427.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\00000428.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\00000426.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\00000429.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\00000430.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\00000431.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\00000432.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\00000433.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\00000435.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\00000436.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\00000439.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\00000434.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\00000437.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\00000440.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\00000441.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\00001502.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\00001503.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\00001504.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\00001505.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\00002276.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\00002277.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\00002278.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\00002279.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\00002280.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\00002281.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\00002282.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\00002284.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.21:C:\Documents and Settings\Casey Crowell\Application Data\Mozilla\Firefox\Profiles\rf14mi4j.Default User\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\00001486.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\00001487.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\00001488.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\00001491.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\00001497.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\00001498.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\00001499.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\00002285.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\00002288.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\00002302.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\00002340.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.22:C:\RECYCLER\NPROTECT\00000442.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.22:C:\RECYCLER\NPROTECT\00000444.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.22:C:\RECYCLER\NPROTECT\00000447.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.22:C:\RECYCLER\NPROTECT\00000638.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.23:C:\RECYCLER\NPROTECT\00001507.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.24:C:\RECYCLER\NPROTECT\00001511.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.24:C:\RECYCLER\NPROTECT\00001514.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.25:C:\RECYCLER\NPROTECT\00000414.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.25:C:\RECYCLER\NPROTECT\00000415.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.25:C:\RECYCLER\NPROTECT\00001547.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.25:C:\RECYCLER\NPROTECT\00001551.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.25:C:\RECYCLER\NPROTECT\00001552.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.26:C:\RECYCLER\NPROTECT\00000418.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.27:C:\RECYCLER\NPROTECT\00000639.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.27:C:\RECYCLER\NPROTECT\00000648.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.32:C:\RECYCLER\NPROTECT\00000649.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.32:C:\RECYCLER\NPROTECT\00000654.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.32:C:\RECYCLER\NPROTECT\00000655.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.34:C:\RECYCLER\NPROTECT\00000656.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.34:C:\RECYCLER\NPROTECT\00000657.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.35:C:\RECYCLER\NPROTECT\00000659.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.37:C:\RECYCLER\NPROTECT\00000660.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.37:C:\RECYCLER\NPROTECT\00000661.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.37:C:\RECYCLER\NPROTECT\00000662.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.37:C:\RECYCLER\NPROTECT\00000713.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.40:C:\RECYCLER\NPROTECT\00000784.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.41:C:\RECYCLER\NPROTECT\00000788.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.51:C:\RECYCLER\NPROTECT\00000789.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.51:C:\RECYCLER\NPROTECT\00000855.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.9:C:\RECYCLER\NPROTECT\00000420.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.9:C:\RECYCLER\NPROTECT\00001259.MOZ -> TrackingCookie.Tribalfusion : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@servedfor.valuead[1].txt -> TrackingCookie.Valuead : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@x10[2].txt -> TrackingCookie.X10 : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@xxxcounter[1].txt -> TrackingCookie.Xxxcounter : Cleaned.
C:\Program Files\EarthLink 5.0\jimbink06@earthlink.net\Cookies\casey crowell@xxxcounter[2].txt -> TrackingCookie.Xxxcounter : Cleaned.
C:\Documents and Settings\Casey Crowell\.jpi_cache\file\1.0\Dummy.class-498f6d05-2afba381.class -> Trojan.ClassLoader.Dummy.c : Cleaned with backup (quarantined).
C:\Documents and Settings\Casey Crowell\.jpi_cache\file\1.0\Dummy.class-54bc8047-2403d6b1.class -> Trojan.ClassLoader.Dummy.c : Cleaned with backup (quarantined).


::Report end
greenh is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 10-07-2006, 05:30 PM   #5 (permalink)
Registered User
 
Join Date: Sep 2006
Posts: 7
OS: winxp


Logfile of HijackThis v1.99.1
Scan saved at 4:30:03 PM, on 10/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~2\NORTON~2\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\AOL\1158002726\ee\aolsoftware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
c:\program files\common files\aol\1158002726\ee\aim6.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\SECURI~2\NSCSRVCE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Casey Crowell\My Documents\HijackThis.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com.../fix_homepage/
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: IeCaptureBho Object - {7c1ce531-09e9-4fc5-9803-1c2956615786} - (no file)
O2 - BHO: Norton Personal Firewall 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: (no name) - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - (no file)
O3 - Toolbar: Norton Personal Firewall 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NAV Agent] C:\Documents and Settings\Casey Crowell\NSW2006\NAV\External\NORTON\NAVAPW32.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Common Files\Roxio Shared\System\DirectCD.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~2\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
greenh is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 10-07-2006, 06:26 PM   #6 (permalink)
Security Team (ret.)
 
Pancake's Avatar
 
Join Date: Nov 2003
Location: Victoria.Australia
Posts: 7,404
OS: XP Pro SP3


That should have made a difference.I dont see anymore problems now..
__________________
Eddy
Pancake is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 10-08-2006, 05:22 PM   #7 (permalink)
Registered User
 
Join Date: Sep 2006
Posts: 7
OS: winxp


Great, thank you.
greenh is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 11:39 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85