Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 03-28-2007, 08:48 PM   #1 (permalink)
I helped the forums.
 
Michael77's Avatar
 
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)


HJT Help Please, 2nd Request, SLOW Start-up, Malware?

WinXP starts very, very sloooooow, ten minutes until internet connects, will not print, wireless network problems with Vista laptop, Panda on-line runs, shows virus, spyware, then closes without report. I posted another log about a month or so ago, but have been busy and using the laptop, but now must resolve. Problems are getting worse. Thanks in advance for your help! Mike.




Deckard's System Scanner v20070318.32
Run by Michael Shackelford on 2007-03-28 at 21:32:04
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
128: 2007-03-29 02:32:17 UTC - RP859 - Deckard's System Scanner Restore Point
127: 2007-03-29 00:56:05 UTC - RP858 - Software Distribution Service 2.0
126: 2007-03-28 0031 UTC - RP857 - System Checkpoint
125: 2007-03-26 22:18:55 UTC - RP856 - System Checkpoint
124: 2007-03-25 21:23:56 UTC - RP855 - Software Distribution Service 2.0


-- First Restore Point --
1: 2006-12-29 22:31:26 UTC - RP732 - System Checkpoint


Performed disk cleanup.


-- HijackThis (run as Michael Shackelford.exe) ---------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 9:32:49 PM, on 3/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\SPOOL\DRIVERS\W32X86\3\DLBUJSWX.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\Michael Shackelford\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\MICHAE~1.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe"
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} - http://dlmanager.akamaitools.com.edg...ex-2.0.5.0.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-36.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1129351655375
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/40...02/Coupons.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/pro...tor/WebAAS.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\puresp3.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing)
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PowerPanel Personal Edition Service (ppped) - Unknown owner - C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe


-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R0 cbidf - c:\windows\system32\drivers\cbidf2k.sys
R0 dac2w2k - c:\windows\system32\drivers\dac2w2k.sys
R0 drvmcdb - c:\windows\system32\drivers\drvmcdb.sys
R0 GBDevice - c:\windows\system32\drivers\gbdevice.sys
R0 GoBack2K - c:\windows\system32\drivers\goback2k.sys
R1 BANTExt (Belarc SMBios Access) - c:\windows\system32\drivers\bantext.sys
R1 omci (OMCI WDM Device Driver) - c:\windows\system32\drivers\omci.sys
R1 SRTSPX - c:\windows\system32\drivers\srtspx.sys
R1 sscdbhk5 - c:\windows\system32\drivers\sscdbhk5.sys
R1 ssrtln - c:\windows\system32\drivers\ssrtln.sys
R2 drvnddm - c:\windows\system32\drivers\drvnddm.sys
R2 MCSTRM - c:\windows\system32\drivers\mcstrm.sys
R2 pnarp (Network Magic Device Discovery Driver) - c:\windows\system32\drivers\pnarp.sys
R2 purendis (Network Magic Wireless Driver) - c:\windows\system32\drivers\purendis.sys
R2 tfsnboio - c:\windows\system32\dla\tfsnboio.sys
R2 tfsncofs - c:\windows\system32\dla\tfsncofs.sys
R2 tfsndrct - c:\windows\system32\dla\tfsndrct.sys
R2 tfsndres - c:\windows\system32\dla\tfsndres.sys
R2 tfsnifs - c:\windows\system32\dla\tfsnifs.sys
R2 tfsnopio - c:\windows\system32\dla\tfsnopio.sys
R2 tfsnpool - c:\windows\system32\dla\tfsnpool.sys
R2 tfsnudf - c:\windows\system32\dla\tfsnudf.sys
R2 tfsnudfa - c:\windows\system32\dla\tfsnudfa.sys
R2 WIBUKEY (WIBU-KEY Kernel Driver) - c:\windows\system32\drivers\wibukey.sys
R3 emupia (E-mu Plug-in Architecture Driver) - c:\windows\system32\drivers\emupia2k.sys
R3 hcwPP2 (Hauppauge WinTV PVR PCI II ([23|25|26]xxx)) - c:\windows\system32\drivers\hcwpp2.sys
R3 MODEMCSA (Unimodem Streaming Filter Device) - c:\windows\system32\drivers\modemcsa.sys
R3 mohfilt - c:\windows\system32\drivers\mohfilt.sys
R3 ROOTMODEM (Microsoft Legacy Modem Driver) - c:\windows\system32\drivers\rootmdm.sys
R3 SRTSP - c:\windows\system32\drivers\srtsp.sys

S2 GBFSHook - c:\windows\system32\drivers\gbfshook.sys
S3 Bridge (MAC Bridge) - c:\windows\system32\drivers\bridge.sys
S3 BridgeMP (MAC Bridge Miniport) - c:\windows\system32\drivers\bridge.sys
S3 hap17v2k (Creative P17V HAL Driver) - c:\windows\system32\drivers\hap17v2k.sys
S3 HidBatt (HID UPS Battery Driver) - c:\windows\system32\drivers\hidbatt.sys
S3 P2k (Motorola USB Device) - c:\windows\system32\drivers\p2k.sys
S3 SDdriver - c:\windows\system32\drivers\sddriver.sys
S3 SRTSPL - c:\windows\system32\drivers\srtspl.sys
S3 TVICHW32 - c:\windows\system32\drivers\tvichw32.sys
S3 usbsermpt (Motorola USB Modem Driver for MPT) - c:\windows\system32\drivers\usbsermpt.sys
S3 wanatw (WAN Miniport (ATW)) - c:\windows\system32\drivers\wanatw4.sys (file missing)
S3 WpdUsb - c:\windows\system32\drivers\wpdusb.sys


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 GBPoll (GoBack Polling Service) - "c:\program files\norton systemworks\norton goback\gbpoll.exe"
R2 IISADMIN (IIS Admin) - c:\windows\system32\inetsrv\inetinfo.exe
R2 MSFtpsvc (FTP Publishing) - c:\windows\system32\inetsrv\inetinfo.exe
R2 nmservice (Pure Networks Network Magic Service) - "c:\program files\pure networks\network magic\nmsrvc.exe"
R2 ppped (PowerPanel Personal Edition Service) - "c:\program files\cyberpower powerpanel personal edition\ppped.exe"
R2 SMTPSVC (Simple Mail Transfer Protocol (SMTP)) - c:\windows\system32\inetsrv\inetinfo.exe
R2 SNMP (SNMP Service) - c:\windows\system32\snmp.exe
R2 Speed Disk service - c:\progra~1\norton~1\norton~3\speedd~1\nopdb.exe

S3 dlbu_device - c:\windows\system32\dlbucoms.exe -service
S3 LPDSVC (TCP/IP Print Server) - c:\windows\system32\tcpsvcs.exe
S3 MHN - c:\windows\system32\svchost.exe -k netsvcs
S3 nmraapache (Pure Networks Net2Go Service) - "c:\program files\pure networks\network magic\webserver\bin\nmraapache.exe" -k runservice
S4 InCDsrvR (InCD Helper (read only)) - c:\program files\ahead\incd\incdsrv.exe -r
S4 NSCService (Norton Protection Center Service) - "c:\program files\common files\symantec shared\security console\nscsrvce.exe"


-- Scheduled Tasks -------------------------------------------------------------

2007-03-25 14:53:13 592 --a------ C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Michael Shackelford.job<NORTON~1.JOB>


-- Files created between 2007-02-28 and 2007-03-28 -----------------------------

2007-03-28 19:56:09 0 d-------- C:\WINDOWS\LastGood
2007-03-25 15:19:11 4 --a------ C:\WINDOWS\system32\5D4079
2007-03-24 11:35:43 0 d-------- C:\spoolerlogs<SPOOLE~1>
2007-03-24 11:29:46 0 d-------- C:\Program Files\Dl_cats
2007-03-24 08:50:12 23600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-03-04 00:23:53 172032 --a------ C:\WINDOWS\system32\nvudisp.exe
2007-03-03 21:41:39 21312 --a------ C:\WINDOWS\choice.exe
2007-03-03 21:34:44 0 d-------- C:\ie-spyad2<IE-SPY~1>
2007-03-03 21:31:27 0 d-------- C:\Program Files\SpywareGuard<SPYWAR~2>
2007-03-03 21:23:39 0 d-------- C:\Program Files\SpywareBlaster<SPYWAR~1>
2007-03-03 18:24:55 0 d-------- C:\Program Files\Lavasoft
2007-03-03 18:20:15 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard<WISEIN~1>


-- Find3M Report ---------------------------------------------------------------

2007-03-28 20:22:34 0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1>
2007-03-28 20:22:32 0 d-------- C:\Program Files\Norton Internet Security<NORTON~2>
2007-03-28 20:22:04 0 d-------- C:\Program Files\CyberPower PowerPanel Personal Edition<CYBERP~1>
2007-03-28 20:21:47 0 d-------- C:\Program Files\Common Files\Pure Networks Shared<PURENE~1>
2007-03-28 20:21:46 0 d-------- C:\Program Files\HighMAT CD Writing Wizard<HIGHMA~1>
2007-03-28 20:21:44 0 d-------- C:\Program Files\PowerArchiver<POWERA~1>
2007-03-28 20:21:44 0 d-------- C:\Program Files\DVD Region+CSS Free<DVDREG~1>
2007-03-28 20:21:14 0 d-------- C:\Program Files\Google
2007-03-25 15:21:30 0 d-------- C:\Program Files\Comcast Rhapsody<COMCAS~1>
2007-03-25 15:21:30 0 d-------- C:\Documents and Settings\Michael Shackelford\Application Data\Real
2007-03-25 10:38:29 0 d-------- C:\Program Files\Java
2007-03-25 10:31:14 0 d-------- C:\Program Files\Comcast
2007-03-25 10:21:35 0 d-------- C:\Program Files\Dell Photo AIO Printer 942<DELLPH~1>
2007-03-24 18:51:31 0 d-------- C:\Program Files\Norton SystemWorks<NORTON~1>
2007-03-24 18:22:15 0 d-------- C:\Program Files\Quicken WillMaker Plus 2007<QUICKE~1>
2007-03-03 23:57:03 0 d-------- C:\Documents and Settings\Michael Shackelford\Application Data\Adobe
2007-03-03 23:56:02 0 d-------- C:\Documents and Settings\Michael Shackelford\Application Data\AdobeUM
2007-03-03 18:25:05 0 d-------- C:\Documents and Settings\Michael Shackelford\Application Data\Lavasoft
2007-03-03 17:24:29 0 dr-h----- C:\Documents and Settings\Michael Shackelford\Application Data\yahoo!
2007-03-03 14:24:27 0 d-------- C:\Program Files\Intel
2007-03-03 14:23:17 0 d--h----- C:\Program Files\InstallShield Installation Information<INSTAL~1>
2007-02-25 22:34:00 0 d-------- C:\Program Files\MSECache
2007-02-25 18:41:26 0 d-------- C:\Program Files\Symantec
2007-02-25 18:41:25 48776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-02-25 18:30:06 0 d-------- C:\Documents and Settings\Michael Shackelford\Application Data\Symantec
2007-02-25 18:07:58 0 d-------- C:\Program Files\The Weather Channel FW<THEWEA~1>
2007-02-23 15:21:52 421888 --a------ C:\WINDOWS\system32\dlbudrs.dll
2007-02-18 15:21:01 0 d-------- C:\Program Files\Quicken
2007-02-18 15:20:39 0 d-------- C:\Program Files\Common Files\Palo Alto Software<PALOAL~1>
2007-02-18 14:33:49 28335 --a------ C:\Documents and Settings\Michael Shackelford\Application Data\Comma Separated Values (Windows).ADR<COMMAS~1.ADR>
2007-02-17 09:35:20 0 d---s---- C:\Documents and Settings\Michael Shackelford\Application Data\Microsoft<MICROS~1>
2007-02-10 17:08:33 0 d-------- C:\Program Files\DeductionPro 2006<DEDUCT~1>
2007-02-10 15:15:08 0 d-------- C:\Program Files\WILLPower<WILLPO~1>
2007-02-10 13:57:15 0 d-------- C:\Documents and Settings\Michael Shackelford\Application Data\Intuit
2007-02-10 13:21:18 0 d-------- C:\Program Files\TaxCut06
2007-02-10 13:17:55 118784 --a------ C:\WINDOWS\system32\pdfmona.dll
2007-02-10 13:17:55 51716 --a------ C:\WINDOWS\system32\pdf995mon.dll<PDF995~1.DLL>
2007-02-10 11:55:45 164 --a------ C:\install.dat
2007-02-06 09:27:30 0 d-------- C:\Program Files\DIFX
2007-02-04 18:09:30 0 d-------- C:\Program Files\MSBuild
2007-02-04 18:05:47 0 d-------- C:\Program Files\Reference Assemblies<REFERE~1>
2007-02-04 00:40:27 0 d-------- C:\Program Files\Pure Networks<PURENE~1>
2007-01-22 02:19:00 69632 --a------ C:\WINDOWS\system32\dlbucfg.dll
2007-01-19 16:23:54 1721976 --a------ C:\WINDOWS\system32\inetclnt.dll
2007-01-08 20:01:14 17408 --a------ C:\WINDOWS\system32\corpol.dll


-- Registry Dump ---------------------------------------------------------------


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"IAAnotif"="\"C:\\Program Files\\Intel\\Intel Application Accelerator\\iaanotif.exe\""
"CTSysVol"="\"C:\\Program Files\\Creative\\SBAudigy2ZS\\Surround Mixer\\CTSysVol.exe\" /r"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"osCheck"="\"C:\\Program Files\\Norton Internet Security\\osCheck.exe\""
"nmapp"="\"C:\\Program Files\\Pure Networks\\Network Magic\\nmapp.exe\" -autorun -nosplash"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"
"DLBUCATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\DLBUtime.dll,_RunDLLEntry@16"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Acrobat Assistant.lnk"
"backup"="C:\\WINDOWS\\pss\\Acrobat Assistant.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Distillr\\acrotray.exe "
"item"="Acrobat Assistant"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~2.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoStart IR.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\AutoStart IR.lnk"
"backup"="C:\\WINDOWS\\pss\\AutoStart IR.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\WinTV\\Ir.exe /QUIET"
"item"="AutoStart IR"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\QuickBooks Update Agent.lnk"
"backup"="C:\\WINDOWS\\pss\\QuickBooks Update Agent.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\Intuit\\QUICKB~1\\QBUpdate\\qbupdate.exe "
"item"="QuickBooks Update Agent"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Venturi 2.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Venturi 2.lnk"
"backup"="C:\\WINDOWS\\pss\\Venturi 2.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Venturi2\\CONFIG~1\\ventcfg.exe "
"item"="Venturi 2"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Michael Shackelford^Start Menu^Programs^Startup^Motorola Share.lnk]
"path"="C:\\Documents and Settings\\Michael Shackelford\\Start Menu\\Programs\\Startup\\Motorola Share.lnk"
"backup"="C:\\WINDOWS\\pss\\Motorola Share.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\MOTORO~1\\agent.exe "
"item"="Motorola Share"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="apdproxy"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CTDetect"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Creative\\MediaSource\\Detector\\CTDetect.exe\" /R"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDET]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CTDVDDET"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Creative\\SBAudigy2ZS\\DVDAudio\\CTDVDDET.EXE\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ctfmon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\ctfmon.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CTHELPER"
"hkey"="HKLM"
"command"="CTHELPER.EXE"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell Photo AIO Printer 942]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dlbubmgr"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Dell Photo AIO Printer 942\\dlbubmgr.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellMCM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="memcard"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Dell Photo AIO Printer 942\\memcard.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="tfswctrl"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DVDLauncher"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ehtray"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\ehome\\ehtray.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="IntelMEM"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Intel\\Modem Event Monitor\\IntelMEM.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="isuspm"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\isuspm.exe\" -startup"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="issch"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mimboot"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\MUSICM~1\\MUSICM~3\\mimboot.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mnyexpr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Microsoft Money\\System\\mnyexpr.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nbj"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\nbj.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mssysmgr"
"hkey"="HKCU"
"command"="C:\\PROGRA~1\\Nero\\data\\xtras\\mssysmgr.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerPanel Personal Edition User Interaction]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="pppeuser"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\CyberPower PowerPanel Personal Edition\\pppeuser.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RealPlay"
"hkey"="HKLM"
"command"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="GoogleToolbarNotifier"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="sgtray"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AdobeUpdateManager"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_9 -reboot 1"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="UpdReg"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\UpdReg.EXE"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MSASCui"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="WMPNSCFG"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UleadBurningHelper"=dword:00000002
"svcWRSSSDK"=dword:00000002
"SAVScan"=dword:00000003
"ose"=dword:00000003
"InCDsrvR"=dword:00000002
"Adobe LM Service"=dword:00000003


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_COMHOST


-- End of Deckard's System Scanner: finished at 2007-03-28 at 21:33:27 ---------
Attached Files
File Type: txt extra.txt (37.6 KB, 2 views)
Michael77 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 03-31-2007, 09:49 AM   #2 (permalink)
I helped the forums.
 
Michael77's Avatar
 
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)


Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?

Bump.
Michael77 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-01-2007, 07:30 AM   #3 (permalink)
I helped the forums.
 
Michael77's Avatar
 
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)


HJT Help Please, 2nd Request, SLOW Start-up, MORE INFO...

Bump.

More info:

Dell PC w/XP Media Edition 2005 has slow start-up problems, then slow afterwords as well. IE will not connect for ten minutes or so, but Firefox will connect right away. May be a spyware/malware problem? Other problems include print spool errors, etc. Sorry I can't be more help!

My first post on this was 3/3/07 and went unanswered, I posted a new log on 3/28/07 and still no reply. I have tried everything on my own (maybe too much) and followed all of the pre-post instructions. I know you guys are busy, but please take a look.

I made a donation after my first visit to this site and will again. Also have recommended others to the site since. Thank you in advance for your help.

Mike
Michael77 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-01-2007, 09:01 AM   #4 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 27,043
OS: WinXP and Vista


Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?

Hello Mike,

Donations are appreciated, but certainly not a prerequisite to get our attention.

We've been swamped and many threads have gone unanswered--our apologies for the oversight of your threads.

Please give me some time to go over these new logs as well as the logs in your previous thread. I'll have a reply for you as soon as possible.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-01-2007, 09:39 AM   #5 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 27,043
OS: WinXP and Vista


Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?

Hello Mike,

I'm not seeing much in these logs. Upload this file C:\WINDOWS\system32\dlbudrs.dll to http://virusscan.jotti.org and report back what it found.

At the top of the window you should see "File to Upload & scan" and a blank box. Copy and paste the red text from above into the box. Then click "submit".

When it is finished, please copy and paste the information listed under "Service" and "Scanner Results" here.

If the site is too busy, upload it here http://www.virustotal.com/en/indexf.html

--------------------------------------------------------------

Please copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.

***************************************************

Download AVG Anti Spyware

Use the link at the bottom of the page under "AVG Anti-Spyware Free for Windows"

  • Install AVG Anti Spyware
  • Double-click the icon on Desktop to launch AVG
  • On the top of the main screen click Shield
  • Click the word active to change it to inactive
  • On the top of the main screen click Update.
  • Then click on Start Update. The update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
When you have finished updating, EXIT AVG Anti Spyware. Do Not run a scan just yet, we will shortly.

--------------------------------------------------------------------

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Use the up arrow key to highlight Safe Mode and press Enter.
5) Login with your usual account. Make sure to close any open browsers.

--------------------------------------------------------------------

IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
Run AVG Anti-Spyware with it's updated definitions:(...it's important that all windows must be closed)
  • Click Scanner
  • Click on the Scan tab
  • Click Complete System Scan to begin scanning.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, **Please ensure it is set to Quarantine then select "Apply all actions"
  • Once finished, click the Save report button, then click Save Report As and save it to your desktop. (make sure to remember where you saved that file, this is important).
**AVG Anti-Spyware is compatible with most AV and anti-spyware products, and the free version will continue to be useful as a second anti-malware scanner.

--------------------------------------------------------------------

Reboot into Normal Mode.

--------------------------------------------------------------------

Since Firefox works well for you, I'd like you to install the IE Tab add on for Firefox. We can use that Tab to perform an online scan and see if it will complete for you.

https://addons.mozilla.org/firefox/1419/

Further instructions about how to use it can be found here.

Once you've gotten the IE tab installed in Firefox, run an online scan at Panda:

Make sure you've activated the IE Tab and perform this online scan using the IETab in Firefox at Panda ActiveScan
  1. Click on located at the bottom of the page.
  2. A "pop up" window will appear. * Please ensure that your pop up blocker doesn't block it *
  3. Enter your e-mail address, country, and state & click "Free Online Scan" *The download of the 8 MB Panda's ActiveX control will take place*
Begin the scan by selecting
  • If it finds any malware, it will offer you a report.
  • Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
  • Click on then click
* You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
* Turn off the real time scanner of any existing antivirus program while performing the online scan


-------------------------------------------------------------

Run dss.exe once again.


Please include the following in your next reply:

jotti results
AVG A-S results
Panda results
New main.txt
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-01-2007, 05:03 PM   #6 (permalink)
I helped the forums.
 
Michael77's Avatar
 
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)


Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?

Thanks for the look-see, I donated because I thought it was a worthy cause , not because I needed/wanted help. The "dlbudrs.dll" file appears to be safe, see the results of the scan attached. I cannot run Firefox in IE view until after about ten minutes or so following a re-boot, same as running IE itself. I did run PandaScan with FF in IE view and the same things happens, it identifies some spyware, but closes itself after the scan with no offer to fix, buy, see report, or save report. Real-time scanners turned off, AV turned off, Anti-Spy, SpyGurad, etc. turned off and I have tried to remain on-line and off-line, no difference. Therefore I do not have a PandaScan report.

Here are the other scan reports:



Service
Service load: 0% 100%

File: dlbudrs.dll
Status: OK
MD5 6b2508e2b976416df8f57ff3c6e1fd52
Packers detected: -

Scanner results
Scan taken on 01 Apr 2007 17:51:20 (GMT)
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing



Complete scanning result of "dlbudrs.dll", received in VirusTotal at 04.01.2007, 19:51:11 (CET).

Antivirus Version Update Result
AhnLab-V3 2007.3.31.0 04.01.2007 no virus found
AntiVir 7.3.1.47 04.01.2007 no virus found
Authentium 4.93.8 03.31.2007 no virus found
Avast 4.7.936.0 03.31.2007 no virus found
AVG 7.5.0.447 03.31.2007 no virus found
BitDefender 7.2 04.01.2007 no virus found
CAT-QuickHeal 9.00 03.31.2007 no virus found
ClamAV devel-20070312 04.01.2007 no virus found
DrWeb 4.33 04.01.2007 no virus found
eSafe 7.0.15.0 04.01.2007 no virus found
eTrust-Vet 30.6.3527 03.31.2007 no virus found
Ewido 4.0 04.01.2007 no virus found
FileAdvisor 1 04.01.2007 no virus found
Fortinet 2.85.0.0 04.01.2007 no virus found
F-Prot 4.3.1.45 03.30.2007 no virus found
F-Secure 6.70.13030.0 04.01.2007 no virus found
Ikarus T3.1.1.3 04.01.2007 no virus found
Kaspersky 4.0.2.24 04.01.2007 no virus found
McAfee 4997 03.31.2007 no virus found
Microsoft 1.2306 04.01.2007 no virus found
NOD32v2 2161 04.01.2007 no virus found
Norman 5.80.02 03.31.2007 no virus found
Panda 9.0.0.4 04.01.2007 no virus found
Prevx1 V2 04.01.2007 no virus found
Sophos 4.16.0 03.30.2007 no virus found
Sunbelt 2.2.907.0 03.31.2007 no virus found
Symantec 10 04.01.2007 no virus found
TheHacker 6.1.6.083 03.30.2007 no virus found
UNA 1.83 03.16.2007 no virus found
VBA32 3.11.3 04.01.2007 no virus found
VirusBuster 4.3.7:9 04.01.2007 no virus found
Webwasher-Gateway 6.0.1 04.01.2007 no virus found


Aditional Information
File size: 421888 bytes
MD5: 6b2508e2b976416df8f57ff3c6e1fd52
SHA1: e3d1ffefcc24e2c9f7533a82f4679b4decdd42be



---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 3:43:53 PM 4/1/2007

+ Scan result:



C:\WINDOWS\SYSTEM32\B4FM.dll -> Adware.BurnFree : Cleaned with backup (quarantined).
C:\Documents and Settings\Michael Shackelford\Local Settings\Temporary Internet Files\Content.IE5\EZBM30FO\mm[1].js -> Adware.Chitika : Cleaned with backup (quarantined).
C:\WINDOWS\cpbrkpie.ocx -> Adware.Coupons : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP854\A0111446.EXE -> Not-A-Virus.Downloader.Win32.DigStream.a : Cleaned with backup (quarantined).
:mozilla.185:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.185:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.185:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.185:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.185:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.185:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.185:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.185:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.185:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.185:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.185:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.185:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.185:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.192:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Cnn : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Cnn : Cleaned.
:mozilla.12:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.21:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.22:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.6:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.6:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.6:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.6:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.6:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.6:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Com : Cleaned.
:mozilla.73:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.73:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.73:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.73:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.73:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.73:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.73:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.73:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.73:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.73:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.74:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.74:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.74:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.81:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.82:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.83:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.83:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.83:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.83:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.83:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.83:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.83:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.83:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.183:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.183:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.183:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.183:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.183:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.183:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.183:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.183:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.183:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.183:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.183:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.183:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.183:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.184:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.184:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.184:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.184:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.184:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.184:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.184:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.184:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.184:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.184:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.184:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.184:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.184:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.140:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.140:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.140:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.140:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.140:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.140:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.140:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.140:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.140:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.140:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.141:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.141:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.141:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.141:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.141:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.141:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.141:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.141:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.141:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.141:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.141:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.141:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.141:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.142:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.142:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.142:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.148:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.149:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.150:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.151:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.151:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.151:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.151:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.151:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.151:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.151:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Liveperson : Cleaned.
:mozilla.151:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@search.msn[1].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\Michael Shackelford\Cookies\michael_shackelford@search.msn[1].txt -> TrackingCookie.Msn : Cleaned.
:mozilla.78:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.78:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.78:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.78:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.78:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.78:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.78:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.78:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.78:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.78:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.79:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.79:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.79:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.86:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.87:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.88:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.88:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.88:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.88:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.88:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.88:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.88:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.88:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Netflame : Cleaned.
:mozilla.206:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.206:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.206:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.206:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.206:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.206:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.206:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.206:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.206:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.206:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.206:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.206:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.206:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.212:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.213:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.213:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.213:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.213:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Paypal : Cleaned.
:mozilla.214:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\Michael Shackelford\Cookies\michael_shackelford@www.paypal[1].txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\Michael Shackelford\Cookies\michael shackelford@guide.real[1].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Michael Shackelford\Cookies\michael shackelford@realguide.real[2].txt -> TrackingCookie.Real : Cleaned.
:mozilla.161:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.161:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.161:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.161:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.161:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.161:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.161:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.161:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.161:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.161:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.161:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.161:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.161:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.162:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.162:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.162:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.162:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.162:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.162:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.162:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.162:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.162:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.162:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.162:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.162:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.162:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.163:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.163:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.163:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.163:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.163:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.163:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.163:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.163:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.163:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.163:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.163:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.163:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.163:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.164:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.164:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.164:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.164:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.164:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.164:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.164:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.164:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.164:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.164:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.164:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.164:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.164:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Tacoda : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.173:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.182:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.182:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.182:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.182:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.182:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.182:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.182:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Zedo : Cleaned.
:mozilla.182:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Zedo : Cleaned.


::Report end
Attached Files
File Type: txt dssmain.txt (30.4 KB, 0 views)
Michael77 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-03-2007, 07:02 AM   #7 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 27,043
OS: WinXP and Vista


Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?

Let's see if Kaspersky's online scanner will complete for you:

Please perform an online scan with Internet Explorer at Kaspersky Online Scanner

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply

**Note for Internet Explorer 7 users**

If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-03-2007, 05:34 PM   #8 (permalink)
I helped the forums.
 
Michael77's Avatar
 
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)


Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, April 03, 2007 6:27:53 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 3/04/2007
Kaspersky Anti-Virus database records: 290647
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\

Scan Statistics:
Total number of scanned objects: 228785
Number of viruses found: 4
Number of infected objects: 12
Number of suspicious objects: 0
Duration of the scan process: 02:44:05

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ad391678a806ec4d691e83aaa393b6f_5b150187-0f05-4c72-917c-77c8e6964ac4 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\LOGS\ehRecvr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Pure Networks\Network Magic\Log\logfile.nmapp_exe.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Pure Networks\Network Magic\Log\logfile.nmsrvc_exe.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-04-03_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\16351005.exe Infected: Trojan.Win32.Agent.qt skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1716610D.exe Infected: Trojan.Win32.Agent.qt skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\177F209A.exe Infected: Trojan.Win32.Agent.qt skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\182253E6.exe Infected: Trojan.Win32.Agent.qt skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\19B72A29.exe Infected: Trojan.Win32.Agent.qt skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\9413D31E.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SubEng\submissions.idx Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Downloads\ComcastToolbar.exe/data0055 Infected: not-a-virus:AdWare.Win32.BHO.al skipped
C:\Documents and Settings\All Users\Documents\My Downloads\ComcastToolbar.exe NSIS: infected - 1 skipped
C:\Documents and Settings\All Users\Documents\Old Dell XPS 933\ofcdatafiles\outlook backup.pst/Personal Folders/Inbox/03 Aug 2001 15:42 from endofauction@ebay.com:eBay End of Auction.eml Infected: Trojan-Spy.HTML.Bayfraud.ib skipped
C:\Documents and Settings\All Users\Documents\Old Dell XPS 933\ofcdatafiles\outlook backup.pst Mail MS Mail: infected - 1 skipped
C:\Documents and Settings\All Users\Documents\Old Dell XPS 933\ofcdatafiles\outlook.pst/Personal Folders/Inbox/eBay Stuff/02 Jun 2002 00:15 from endofauction@ebay.com:eBay End of Auction.eml Infected: Trojan-Spy.HTML.Bayfraud.ib skipped
C:\Documents and Settings\All Users\Documents\Old Dell XPS 933\ofcdatafiles\outlook.pst Mail MS Mail: infected - 1 skipped
C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\MSDVRMM_3838572047_655360_178649 Object is locked skipped
C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\SBE1.tmp Object is locked skipped
C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\{3C6FD663-F130-487E-9769-7E17370C1EB1}.TmpSBE Object is locked skipped
C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Michael Shackelford\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Michael Shackelford\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Michael Shackelford\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Michael Shackelford\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Michael Shackelford\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Michael Shackelford\Local Settings\History\History.IE5\MSHist012007040320070404\index.dat Object is locked skipped
C:\Documents and Settings\Michael Shackelford\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Michael Shackelford\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Michael Shackelford\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Inetpub\catalog.wci\00000002.ps1 Object is locked skipped
C:\Inetpub\catalog.wci\00000002.ps2 Object is locked skipped
C:\Inetpub\catalog.wci\00010001.ci Object is locked skipped
C:\Inetpub\catalog.wci\cicat.fid Object is locked skipped
C:\Inetpub\catalog.wci\cicat.hsh Object is locked skipped
C:\Inetpub\catalog.wci\CiCL0001.000 Object is locked skipped
C:\Inetpub\catalog.wci\CiP10000.000 Object is locked skipped
C:\Inetpub\catalog.wci\CiP20000.000 Object is locked skipped
C:\Inetpub\catalog.wci\CiPT0000.000 Object is locked skipped
C:\Inetpub\catalog.wci\CiSL0001.000 Object is locked skipped
C:\Inetpub\catalog.wci\CiSP0000.000 Object is locked skipped
C:\Inetpub\catalog.wci\CiST0000.000 Object is locked skipped
C:\Inetpub\catalog.wci\CiVP0000.000 Object is locked skipped
C:\Inetpub\catalog.wci\INDEX.000 Object is locked skipped
C:\Inetpub\catalog.wci\propstor.bk1 Object is locked skipped
C:\Inetpub\catalog.wci\propstor.bk2 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\eengine\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\NFWEVT.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\RECYCLER\NPROTECT\NPROTECT.LOG Object is locked skipped
C:\System Volume Information\catalog.wci\00000002.ps1 Object is locked skipped
C:\System Volume Information\catalog.wci\00000002.ps2 Object is locked skipped
C:\System Volume Information\catalog.wci\00010002.ci Object is locked skipped
C:\System Volume Information\catalog.wci\cicat.fid Object is locked skipped
C:\System Volume Information\catalog.wci\cicat.hsh Object is locked skipped
C:\System Volume Information\catalog.wci\CiCL0001.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiP10000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiP20000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiPT0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiSL0001.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiSP0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiST0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiVP0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\INDEX.000 Object is locked skipped
C:\System Volume Information\catalog.wci\propstor.bk1 Object is locked skipped
C:\System Volume Information\catalog.wci\propstor.bk2 Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP860\A0116453.ocx Infected: not-a-virus:AdWare.Win32.Coupons.h skipped
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP862\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\ModemLog_Intel(R) 537EP V9x DF PCI Modem.txt Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{69E7DCB1-CE60-4477-968E-265FCC67728D}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\Media Ce.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\Logfiles\W3SVC1\ex070403.log Object is locked skipped
C:\WINDOWS\SYSTEM32\Logfiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\SYSTEM32\MsDtc\MSDTC.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\MsDtc\Trace\DTCTRACE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_86c.dat Object is locked skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
F:\RECYCLED\NPROTECT\NPROTECT.LOG Object is locked skipped

Scan process completed.
Attached Files
File Type: txt kaspersky.txt (29.8 KB, 1 views)
Michael77 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-03-2007, 06:08 PM   #9 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 27,043
OS: WinXP and Vista


Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?

This is what Kaspersky trims down to:

Quote:
C:\Documents and Settings\All Users\Documents\My Downloads\ ComcastToolbar.exe/data0055 Infected: not-a-virus:AdWare.Win32.BHO.al skipped

C:\Documents and Settings\All Users\Documents\My Downloads\ ComcastToolbar.exe NSIS: infected - 1 skipped

C:\Documents and Settings\All Users\Documents\Old Dell XPS 933\ofcdatafiles\outlook backup.pst/ Personal Folders/Inbox/03 Aug 2001 15:42 from endofauction@ebay.com:eBay End of Auction.eml Infected: Trojan-Spy.HTML.Bayfraud.ib skipped

C:\Documents and Settings\All Users\Documents\Old Dell XPS 933\ofcdatafiles\ outlook backup.pst Mail MS Mail: infected - 1 skipped

C:\Documents and Settings\All Users\Documents\Old Dell XPS 933\ofcdatafiles\outlook.pst/ Personal Folders/Inbox/eBay Stuff/02 Jun 2002 00:15 from endofauction@ebay.com:eBay End of Auction.eml Infected: Trojan-Spy.HTML.Bayfraud.ib skipped

C:\Documents and Settings\All Users\Documents\Old Dell XPS 933\ofcdatafiles\ outlook.pst Mail MS Mail: infected - 1 skipped
You'll need to go into your Outlook mail and navigate to the specific folders to delete those e-mails I highlighted in red.

Delete the following file:

C:\Documents and Settings\All Users\Documents\My Downloads\ ComcastToolbar.exe

-----------------------------------------------------------

How long have you used Norton Go-Back? Have you added any new programs just before your issues began?
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-03-2007, 09:02 PM   #10 (permalink)
I helped the forums.
 
Michael77's Avatar
 
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)


Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?

I deleted the entire folder where each of the files in red were located and have done a fresh reboot. None of them were necessary. (No difference so far).

I have never used Norton Go-Back, but do know that it is installed. I did just recently install Norton Internet Security 2007, but will be happy to uninstall it if that will make everything better. I also have Norton System Works installed from a year ago and have been using its AV and other programs with no problems that I am aware of until now. I can easily live without any of its programs and start using the ones suggested here instead.

Please let me know what and how to proceed from here. Thanks again, Mike.
Michael77 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-03-2007, 09:44 PM   #11 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 27,043
OS: WinXP and Vista


Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?

Hi Mike,

I'd just about bet that all those extra Norton products are at the root of your problem.

GoBack is installed as part of Norton System Works unless you opt out. It is loading at startup and running behind the scenes all the time:

O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe


Every time you boot your computer, GoBack is 'taking stock' of the entire system and loading up. Every time you add a new program, or uninstall a program, or download, it's there logging all the changes including the registry changes. GoBack can be a valuable asset, but is basically redundant as Windows XP has a built in System Restore.

Since you've installed Norton Internet Security 2007, all the previous Norton products need to be uninstalled via the Add/Remove programs:

Norton AntiVirus
Norton SystemWorks
Norton SystemWorks 2006
Norton SystemWorks 2006


While you're in the Add/Remove programs, you may as well uninstall your previous version of Java as it is no longer needed and continues to pose a security risk.
Java 2 Runtime Environment, SE v1.4.2_03


Norton GoBack 4.1 <--If curiosity has gotten a hold of you, you can choose to leave this for now and disable the startup and service and see if it makes any difference in your boot time:

Run a scan with HijackThis and fix the following entry:

O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe

Click 'Fix Checked' and close HijackThis.

Next, click Start->Run - type services.msc & then click on the OK button
*Locate the service - GoBack Polling Service (GBPoll)
*Double-click on it to open the Properties dialog.
*Under the General tab
*Stop the service by using the Stop button.
*Change the Startup type to Disabled & then click on the OK button

Reboot your system for that to take effect.

Let me know if the above procedures have improved your system's behavior
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-04-2007, 08:07 PM   #12 (permalink)
I helped the forums.
 
Michael77's Avatar
 
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)


Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?

OK, I have uninstalled all Norton programs that I could find. I must have disabled GoBack already because I could not find it to fix with HijackThis. I also uninstalled Java 2 Runtime Environment, SE v1.4.2_03 as suggested. No change, IE still "hangs" for about 10 minutes before starting as do some other programs. Still cannot print.

I as of yet have not installed any new AV or Firewall programs to replace the Norton programs. Waiting for advice or instructions. I have included a new HJT log for your info.

Thanks again, Mike.

Logfile of HijackThis v1.99.1
Scan saved at 9:04:17 PM, on 4/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe"
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} - http://dlmanager.akamaitools.com.edg...ex-2.0.5.0.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-36.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1129351655375
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/40...02/Coupons.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/pro...tor/WebAAS.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\puresp3.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing)
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PowerPanel Personal Edition Service (ppped) - Unknown owner - C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Attached Files
File Type: txt newhjtlog.txt (8.9 KB, 1 views)

Last edited by Ried; 04-05-2007 at 09:55 AM.
Michael77 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-05-2007, 10:11 AM   #13 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 27,043
OS: WinXP and Vista


Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?

Hi Mike,

I'm not finding malware to be the source and it could be difficult to pinpoint exactly what is causing the trouble. Do you happen to recall if your issues began around the same time you installed Norton Internet Security 2007?
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-05-2007, 03:23 PM   #14 (permalink)
I helped the forums.
 
Michael77's Avatar
 
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)


Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?

Yes, issues started short time after installing Norton Internet Security 2007, which I have now uninstalled, but sure traces remain I am sure.

I also installed Network Magic with new wireless router for new VISTA laptop at about the same time.

What else can I do to find the source of this problem and/or get back to running normal? Mike.
Michael77 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-05-2007, 06:06 PM   #15 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 27,043
OS: WinXP and Vista


Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?

Hi Mike,

Let's see if Norton did uninstall properly. Run another scan with HijackThis and post the log here.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-06-2007, 07:39 PM   #16 (permalink)
I helped the forums.
 
Michael77's Avatar
 
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)


Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?

OK, here is HJT log immediately after turning power on computer and logging on before IE will start and posting by using Firefox. I will post another immediately after IE and everything else starts in ten minutes or so.


Logfile of HijackThis v1.99.1
Scan saved at 8:31:26 PM, on 4/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\dlbucoms.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe"
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} - http://dlmanager.akamaitools.com.edg...ex-2.0.5.0.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-36.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1129351655375
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/40...02/Coupons.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/pro...tor/WebAAS.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\puresp3.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing)
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PowerPanel Personal Edition Service (ppped) - Unknown owner - C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Michael77 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-06-2007, 08:06 PM   #17 (permalink)
I helped the forums.
 
Michael77's Avatar
 
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)


Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?

OK, I have attached the HJT text file (#2) to this post after IE would start and when seems everything else works somewhat more correctly (still can't print). Mike.

2nd log:

Logfile of HijackThis v1.99.1
Scan saved at 8:57:25 PM, on 4/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe"
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} - http://dlmanager.akamaitools.com.edg...ex-2.0.5.0.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-36.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1129351655375
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/40...02/Coupons.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/pro...tor/WebAAS.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\puresp3.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing)
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PowerPanel Personal Edition Service (ppped) - Unknown owner - C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Michael77 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-06-2007, 09:35 PM   #18 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 27,043
OS: WinXP and Vista


Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?

Hi,

I'm still seeing remnants of Symantec. Here is a guide for uninstalling Norton, including uninstallers. Be sure to use the uninstaller for the version of Norton/Symantec that is active on your system. http://basconotw.mvps.org/SymRem.htm

Post a new HijackThis log after using the uninstaller. Let me know if there is any change in your system's behavior.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-07-2007, 11:57 AM   #19 (permalink)
I helped the forums.
 
Michael77's Avatar
 
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)


Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?

I ran every uninstall and followed every instruction I could find for removing every trace of Norton/Symantec products including going into regedit and deleting every folder and file with Norton or Symantec in the name.

Computer runs the same after several reboots. Explorer and a couple of other programs still take about 10 minutes before they will load. Still no printing.

Here is the latest HJT log:



Logfile of HijackThis v1.99.1
Scan saved at 12:47:12 PM, on 4/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\dlbucoms.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dumprep.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe"
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} - http://dlmanager.akamaitools.com.edg...ex-2.0.5.0.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-36.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1129351655375
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/40...02/Coupons.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/pro...tor/WebAAS.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\puresp3.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing)
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PowerPanel Personal Edition Service (ppped) - Unknown owner - C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
Michael77 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-07-2007, 09:56 PM   #20 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 27,043
OS: WinXP and Vista


Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?

Norton has been removed--nice work.

I still don't like the looks of this file C:\WINDOWS\system32\dlbudrs.dll. I know the virus scan came up with nothing, but I'm also not finding any information at all on this file anywhere.

Rename the file to C:\WINDOWS\system32\dlbudrs.old

If any problems arise, rename it back to dlburds.dll

-------------------------------------------------------------

Run a scan with HijackThis and fix these O16 entries:

O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} - http://dlmanager.akamaitools.com.edg...ex-2.0.5.0.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/40...02/Coupons.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/SymAData.cab


Click 'Fix Checked' and close HijackThis.

Reboot your system. Any change?
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 02:17 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85