![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
I helped the forums.
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)
|
HJT Help Please, 2nd Request, SLOW Start-up, Malware?
WinXP starts very, very sloooooow, ten minutes until internet connects, will not print, wireless network problems with Vista laptop, Panda on-line runs, shows virus, spyware, then closes without report. I posted another log about a month or so ago, but have been busy and using the laptop, but now must resolve. Problems are getting worse. Thanks in advance for your help! Mike.
Deckard's System Scanner v20070318.32 Run by Michael Shackelford on 2007-03-28 at 21:32:04 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- Successfully created a Deckard's System Scanner Restore Point. -- Last 5 Restore Point(s) -- 128: 2007-03-29 02:32:17 UTC - RP859 - Deckard's System Scanner Restore Point 127: 2007-03-29 00:56:05 UTC - RP858 - Software Distribution Service 2.0 126: 2007-03-28 00 31 UTC - RP857 - System Checkpoint125: 2007-03-26 22:18:55 UTC - RP856 - System Checkpoint 124: 2007-03-25 21:23:56 UTC - RP855 - Software Distribution Service 2.0 -- First Restore Point -- 1: 2006-12-29 22:31:26 UTC - RP732 - System Checkpoint Performed disk cleanup. -- HijackThis (run as Michael Shackelford.exe) --------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 9:32:49 PM, on 3/28/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe C:\WINDOWS\System32\snmp.exe C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe C:\Program Files\SpywareGuard\sgmain.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\SPOOL\DRIVERS\W32X86\3\DLBUJSWX.EXE C:\WINDOWS\system32\spoolsv.exe C:\Documents and Settings\Michael Shackelford\Desktop\dss.exe C:\PROGRA~1\HIJACK~1\MICHAE~1.EXE R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe" O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe" O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative.com/su/ocx/15015/CTSUEng.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/LSSupCtl.cab O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} - http://dlmanager.akamaitools.com.edg...ex-2.0.5.0.cab O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/S...in/AvSniff.cab O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-36.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/S.../bin/cabsa.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1129351655375 O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/40...02/Coupons.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/pro...tor/WebAAS.cab O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/SymAData.cab O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative.com/su/ocx/15023/CTPID.cab O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\puresp3.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing) O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PowerPanel Personal Edition Service (ppped) - Unknown owner - C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- File Associations ----------------------------------------------------------- All associations okay. -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R0 cbidf - c:\windows\system32\drivers\cbidf2k.sys R0 dac2w2k - c:\windows\system32\drivers\dac2w2k.sys R0 drvmcdb - c:\windows\system32\drivers\drvmcdb.sys R0 GBDevice - c:\windows\system32\drivers\gbdevice.sys R0 GoBack2K - c:\windows\system32\drivers\goback2k.sys R1 BANTExt (Belarc SMBios Access) - c:\windows\system32\drivers\bantext.sys R1 omci (OMCI WDM Device Driver) - c:\windows\system32\drivers\omci.sys R1 SRTSPX - c:\windows\system32\drivers\srtspx.sys R1 sscdbhk5 - c:\windows\system32\drivers\sscdbhk5.sys R1 ssrtln - c:\windows\system32\drivers\ssrtln.sys R2 drvnddm - c:\windows\system32\drivers\drvnddm.sys R2 MCSTRM - c:\windows\system32\drivers\mcstrm.sys R2 pnarp (Network Magic Device Discovery Driver) - c:\windows\system32\drivers\pnarp.sys R2 purendis (Network Magic Wireless Driver) - c:\windows\system32\drivers\purendis.sys R2 tfsnboio - c:\windows\system32\dla\tfsnboio.sys R2 tfsncofs - c:\windows\system32\dla\tfsncofs.sys R2 tfsndrct - c:\windows\system32\dla\tfsndrct.sys R2 tfsndres - c:\windows\system32\dla\tfsndres.sys R2 tfsnifs - c:\windows\system32\dla\tfsnifs.sys R2 tfsnopio - c:\windows\system32\dla\tfsnopio.sys R2 tfsnpool - c:\windows\system32\dla\tfsnpool.sys R2 tfsnudf - c:\windows\system32\dla\tfsnudf.sys R2 tfsnudfa - c:\windows\system32\dla\tfsnudfa.sys R2 WIBUKEY (WIBU-KEY Kernel Driver) - c:\windows\system32\drivers\wibukey.sys R3 emupia (E-mu Plug-in Architecture Driver) - c:\windows\system32\drivers\emupia2k.sys R3 hcwPP2 (Hauppauge WinTV PVR PCI II ([23|25|26]xxx)) - c:\windows\system32\drivers\hcwpp2.sys R3 MODEMCSA (Unimodem Streaming Filter Device) - c:\windows\system32\drivers\modemcsa.sys R3 mohfilt - c:\windows\system32\drivers\mohfilt.sys R3 ROOTMODEM (Microsoft Legacy Modem Driver) - c:\windows\system32\drivers\rootmdm.sys R3 SRTSP - c:\windows\system32\drivers\srtsp.sys S2 GBFSHook - c:\windows\system32\drivers\gbfshook.sys S3 Bridge (MAC Bridge) - c:\windows\system32\drivers\bridge.sys S3 BridgeMP (MAC Bridge Miniport) - c:\windows\system32\drivers\bridge.sys S3 hap17v2k (Creative P17V HAL Driver) - c:\windows\system32\drivers\hap17v2k.sys S3 HidBatt (HID UPS Battery Driver) - c:\windows\system32\drivers\hidbatt.sys S3 P2k (Motorola USB Device) - c:\windows\system32\drivers\p2k.sys S3 SDdriver - c:\windows\system32\drivers\sddriver.sys S3 SRTSPL - c:\windows\system32\drivers\srtspl.sys S3 TVICHW32 - c:\windows\system32\drivers\tvichw32.sys S3 usbsermpt (Motorola USB Modem Driver for MPT) - c:\windows\system32\drivers\usbsermpt.sys S3 wanatw (WAN Miniport (ATW)) - c:\windows\system32\drivers\wanatw4.sys (file missing) S3 WpdUsb - c:\windows\system32\drivers\wpdusb.sys -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- R2 GBPoll (GoBack Polling Service) - "c:\program files\norton systemworks\norton goback\gbpoll.exe" R2 IISADMIN (IIS Admin) - c:\windows\system32\inetsrv\inetinfo.exe R2 MSFtpsvc (FTP Publishing) - c:\windows\system32\inetsrv\inetinfo.exe R2 nmservice (Pure Networks Network Magic Service) - "c:\program files\pure networks\network magic\nmsrvc.exe" R2 ppped (PowerPanel Personal Edition Service) - "c:\program files\cyberpower powerpanel personal edition\ppped.exe" R2 SMTPSVC (Simple Mail Transfer Protocol (SMTP)) - c:\windows\system32\inetsrv\inetinfo.exe R2 SNMP (SNMP Service) - c:\windows\system32\snmp.exe R2 Speed Disk service - c:\progra~1\norton~1\norton~3\speedd~1\nopdb.exe S3 dlbu_device - c:\windows\system32\dlbucoms.exe -service S3 LPDSVC (TCP/IP Print Server) - c:\windows\system32\tcpsvcs.exe S3 MHN - c:\windows\system32\svchost.exe -k netsvcs S3 nmraapache (Pure Networks Net2Go Service) - "c:\program files\pure networks\network magic\webserver\bin\nmraapache.exe" -k runservice S4 InCDsrvR (InCD Helper (read only)) - c:\program files\ahead\incd\incdsrv.exe -r S4 NSCService (Norton Protection Center Service) - "c:\program files\common files\symantec shared\security console\nscsrvce.exe" -- Scheduled Tasks ------------------------------------------------------------- 2007-03-25 14:53:13 592 --a------ C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Michael Shackelford.job<NORTON~1.JOB> -- Files created between 2007-02-28 and 2007-03-28 ----------------------------- 2007-03-28 19:56:09 0 d-------- C:\WINDOWS\LastGood 2007-03-25 15:19:11 4 --a------ C:\WINDOWS\system32\5D4079 2007-03-24 11:35:43 0 d-------- C:\spoolerlogs<SPOOLE~1> 2007-03-24 11:29:46 0 d-------- C:\Program Files\Dl_cats 2007-03-24 08:50:12 23600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS 2007-03-04 00:23:53 172032 --a------ C:\WINDOWS\system32\nvudisp.exe 2007-03-03 21:41:39 21312 --a------ C:\WINDOWS\choice.exe 2007-03-03 21:34:44 0 d-------- C:\ie-spyad2<IE-SPY~1> 2007-03-03 21:31:27 0 d-------- C:\Program Files\SpywareGuard<SPYWAR~2> 2007-03-03 21:23:39 0 d-------- C:\Program Files\SpywareBlaster<SPYWAR~1> 2007-03-03 18:24:55 0 d-------- C:\Program Files\Lavasoft 2007-03-03 18:20:15 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard<WISEIN~1> -- Find3M Report --------------------------------------------------------------- 2007-03-28 20:22:34 0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1> 2007-03-28 20:22:32 0 d-------- C:\Program Files\Norton Internet Security<NORTON~2> 2007-03-28 20:22:04 0 d-------- C:\Program Files\CyberPower PowerPanel Personal Edition<CYBERP~1> 2007-03-28 20:21:47 0 d-------- C:\Program Files\Common Files\Pure Networks Shared<PURENE~1> 2007-03-28 20:21:46 0 d-------- C:\Program Files\HighMAT CD Writing Wizard<HIGHMA~1> 2007-03-28 20:21:44 0 d-------- C:\Program Files\PowerArchiver<POWERA~1> 2007-03-28 20:21:44 0 d-------- C:\Program Files\DVD Region+CSS Free<DVDREG~1> 2007-03-28 20:21:14 0 d-------- C:\Program Files\Google 2007-03-25 15:21:30 0 d-------- C:\Program Files\Comcast Rhapsody<COMCAS~1> 2007-03-25 15:21:30 0 d-------- C:\Documents and Settings\Michael Shackelford\Application Data\Real 2007-03-25 10:38:29 0 d-------- C:\Program Files\Java 2007-03-25 10:31:14 0 d-------- C:\Program Files\Comcast 2007-03-25 10:21:35 0 d-------- C:\Program Files\Dell Photo AIO Printer 942<DELLPH~1> 2007-03-24 18:51:31 0 d-------- C:\Program Files\Norton SystemWorks<NORTON~1> 2007-03-24 18:22:15 0 d-------- C:\Program Files\Quicken WillMaker Plus 2007<QUICKE~1> 2007-03-03 23:57:03 0 d-------- C:\Documents and Settings\Michael Shackelford\Application Data\Adobe 2007-03-03 23:56:02 0 d-------- C:\Documents and Settings\Michael Shackelford\Application Data\AdobeUM 2007-03-03 18:25:05 0 d-------- C:\Documents and Settings\Michael Shackelford\Application Data\Lavasoft 2007-03-03 17:24:29 0 dr-h----- C:\Documents and Settings\Michael Shackelford\Application Data\yahoo! 2007-03-03 14:24:27 0 d-------- C:\Program Files\Intel 2007-03-03 14:23:17 0 d--h----- C:\Program Files\InstallShield Installation Information<INSTAL~1> 2007-02-25 22:34:00 0 d-------- C:\Program Files\MSECache 2007-02-25 18:41:26 0 d-------- C:\Program Files\Symantec 2007-02-25 18:41:25 48776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL 2007-02-25 18:30:06 0 d-------- C:\Documents and Settings\Michael Shackelford\Application Data\Symantec 2007-02-25 18:07:58 0 d-------- C:\Program Files\The Weather Channel FW<THEWEA~1> 2007-02-23 15:21:52 421888 --a------ C:\WINDOWS\system32\dlbudrs.dll 2007-02-18 15:21:01 0 d-------- C:\Program Files\Quicken 2007-02-18 15:20:39 0 d-------- C:\Program Files\Common Files\Palo Alto Software<PALOAL~1> 2007-02-18 14:33:49 28335 --a------ C:\Documents and Settings\Michael Shackelford\Application Data\Comma Separated Values (Windows).ADR<COMMAS~1.ADR> 2007-02-17 09:35:20 0 d---s---- C:\Documents and Settings\Michael Shackelford\Application Data\Microsoft<MICROS~1> 2007-02-10 17:08:33 0 d-------- C:\Program Files\DeductionPro 2006<DEDUCT~1> 2007-02-10 15:15:08 0 d-------- C:\Program Files\WILLPower<WILLPO~1> 2007-02-10 13:57:15 0 d-------- C:\Documents and Settings\Michael Shackelford\Application Data\Intuit 2007-02-10 13:21:18 0 d-------- C:\Program Files\TaxCut06 2007-02-10 13:17:55 118784 --a------ C:\WINDOWS\system32\pdfmona.dll 2007-02-10 13:17:55 51716 --a------ C:\WINDOWS\system32\pdf995mon.dll<PDF995~1.DLL> 2007-02-10 11:55:45 164 --a------ C:\install.dat 2007-02-06 09:27:30 0 d-------- C:\Program Files\DIFX 2007-02-04 18:09:30 0 d-------- C:\Program Files\MSBuild 2007-02-04 18:05:47 0 d-------- C:\Program Files\Reference Assemblies<REFERE~1> 2007-02-04 00:40:27 0 d-------- C:\Program Files\Pure Networks<PURENE~1> 2007-01-22 02:19:00 69632 --a------ C:\WINDOWS\system32\dlbucfg.dll 2007-01-19 16:23:54 1721976 --a------ C:\WINDOWS\system32\inetclnt.dll 2007-01-08 20:01:14 17408 --a------ C:\WINDOWS\system32\corpol.dll -- Registry Dump --------------------------------------------------------------- [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "IAAnotif"="\"C:\\Program Files\\Intel\\Intel Application Accelerator\\iaanotif.exe\"" "CTSysVol"="\"C:\\Program Files\\Creative\\SBAudigy2ZS\\Surround Mixer\\CTSysVol.exe\" /r" "ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\"" "osCheck"="\"C:\\Program Files\\Norton Internet Security\\osCheck.exe\"" "nmapp"="\"C:\\Program Files\\Pure Networks\\Network Magic\\nmapp.exe\" -autorun -nosplash" "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto" "DLBUCATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\DLBUtime.dll,_RunDLLEntry@16" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\"" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Acrobat Assistant.lnk" "backup"="C:\\WINDOWS\\pss\\Acrobat Assistant.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Distillr\\acrotray.exe " "item"="Acrobat Assistant" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk" "backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Adobe\\ACROBA~2.0\\Reader\\READER~1.EXE " "item"="Adobe Reader Speed Launch" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoStart IR.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\AutoStart IR.lnk" "backup"="C:\\WINDOWS\\pss\\AutoStart IR.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\WinTV\\Ir.exe /QUIET" "item"="AutoStart IR" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\QuickBooks Update Agent.lnk" "backup"="C:\\WINDOWS\\pss\\QuickBooks Update Agent.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\COMMON~1\\Intuit\\QUICKB~1\\QBUpdate\\qbupdate.exe " "item"="QuickBooks Update Agent" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Venturi 2.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Venturi 2.lnk" "backup"="C:\\WINDOWS\\pss\\Venturi 2.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Venturi2\\CONFIG~1\\ventcfg.exe " "item"="Venturi 2" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Michael Shackelford^Start Menu^Programs^Startup^Motorola Share.lnk] "path"="C:\\Documents and Settings\\Michael Shackelford\\Start Menu\\Programs\\Startup\\Motorola Share.lnk" "backup"="C:\\WINDOWS\\pss\\Motorola Share.lnkStartup" "location"="Startup" "command"="C:\\PROGRA~1\\MOTORO~1\\agent.exe " "item"="Motorola Share" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="apdproxy" "hkey"="HKLM" "command"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="CTDetect" "hkey"="HKCU" "command"="\"C:\\Program Files\\Creative\\MediaSource\\Detector\\CTDetect.exe\" /R" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDET] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="CTDVDDET" "hkey"="HKLM" "command"="\"C:\\Program Files\\Creative\\SBAudigy2ZS\\DVDAudio\\CTDVDDET.EXE\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ctfmon" "hkey"="HKCU" "command"="C:\\WINDOWS\\system32\\ctfmon.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="CTHELPER" "hkey"="HKLM" "command"="CTHELPER.EXE" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell Photo AIO Printer 942] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="dlbubmgr" "hkey"="HKLM" "command"="\"C:\\Program Files\\Dell Photo AIO Printer 942\\dlbubmgr.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellMCM] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="memcard" "hkey"="HKLM" "command"="\"C:\\Program Files\\Dell Photo AIO Printer 942\\memcard.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="tfswctrl" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="DVDLauncher" "hkey"="HKLM" "command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ehtray" "hkey"="HKLM" "command"="C:\\WINDOWS\\ehome\\ehtray.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="IntelMEM" "hkey"="HKLM" "command"="\"C:\\Program Files\\Intel\\Modem Event Monitor\\IntelMEM.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="isuspm" "hkey"="HKLM" "command"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\isuspm.exe\" -startup" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="issch" "hkey"="HKLM" "command"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="mimboot" "hkey"="HKLM" "command"="C:\\PROGRA~1\\MUSICM~1\\MUSICM~3\\mimboot.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="mnyexpr" "hkey"="HKCU" "command"="\"C:\\Program Files\\Microsoft Money\\System\\mnyexpr.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="nbj" "hkey"="HKCU" "command"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\nbj.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NeroCheck" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\NeroCheck.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="mssysmgr" "hkey"="HKCU" "command"="C:\\PROGRA~1\\Nero\\data\\xtras\\mssysmgr.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerPanel Personal Edition User Interaction] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="pppeuser" "hkey"="HKCU" "command"="\"C:\\Program Files\\CyberPower PowerPanel Personal Edition\\pppeuser.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="qttask" "hkey"="HKLM" "command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RealPlay" "hkey"="HKLM" "command"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="GoogleToolbarNotifier" "hkey"="HKCU" "command"="\"C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="realsched" "hkey"="HKLM" "command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="sgtray" "hkey"="HKLM" "command"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="AdobeUpdateManager" "hkey"="HKCU" "command"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_9 -reboot 1" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="UpdReg" "hkey"="HKLM" "command"="C:\\WINDOWS\\UpdReg.EXE" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="MSASCui" "hkey"="HKLM" "command"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="WMPNSCFG" "hkey"="HKCU" "command"="\"C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "UleadBurningHelper"=dword:00000002 "svcWRSSSDK"=dword:00000002 "SAVScan"=dword:00000003 "ose"=dword:00000003 "InCDsrvR"=dword:00000002 "Adobe LM Service"=dword:00000003 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{93994DE8-8239-4655-B1D1-5F4E91300429}"="" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\ 63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\ 6d,73,73,74,79,6c,65,73,00 "InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\ 73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoCDBurning"=dword:00000000 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoViewOnDrive"=dword:00000000 [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0 *newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_COMHOST -- End of Deckard's System Scanner: finished at 2007-03-28 at 21:33:27 --------- |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#3 (permalink) |
|
I helped the forums.
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)
|
HJT Help Please, 2nd Request, SLOW Start-up, MORE INFO...
Bump.
More info: Dell PC w/XP Media Edition 2005 has slow start-up problems, then slow afterwords as well. IE will not connect for ten minutes or so, but Firefox will connect right away. May be a spyware/malware problem? Other problems include print spool errors, etc. Sorry I can't be more help! My first post on this was 3/3/07 and went unanswered, I posted a new log on 3/28/07 and still no reply. I have tried everything on my own (maybe too much) and followed all of the pre-post instructions. I know you guys are busy, but please take a look. I made a donation after my first visit to this site and will again. Also have recommended others to the site since. Thank you in advance for your help. Mike |
|
|
|
|
#4 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 27,043
OS: WinXP and Vista
|
Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?
Hello Mike,
Donations are appreciated, but certainly not a prerequisite to get our attention. ![]() We've been swamped and many threads have gone unanswered--our apologies for the oversight of your threads. ![]() Please give me some time to go over these new logs as well as the logs in your previous thread. I'll have a reply for you as soon as possible. |
|
|
|
|
#5 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 27,043
OS: WinXP and Vista
|
Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?
Hello Mike,
I'm not seeing much in these logs. Upload this file C:\WINDOWS\system32\dlbudrs.dll to http://virusscan.jotti.org and report back what it found. At the top of the window you should see "File to Upload & scan" and a blank box. Copy and paste the red text from above into the box. Then click "submit". When it is finished, please copy and paste the information listed under "Service" and "Scanner Results" here. If the site is too busy, upload it here http://www.virustotal.com/en/indexf.html -------------------------------------------------------------- Please copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions. *************************************************** Download AVG Anti Spyware Use the link at the bottom of the page under "AVG Anti-Spyware Free for Windows" ![]()
-------------------------------------------------------------------- Next, please reboot your computer in Safe Mode by doing the following: 1) Restart your computer 2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8. 3) Instead of Windows loading as normal, a menu should appear 4) Use the up arrow key to highlight Safe Mode and press Enter. 5) Login with your usual account. Make sure to close any open browsers. -------------------------------------------------------------------- IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess: Run AVG Anti-Spyware with it's updated definitions:(...it's important that all windows must be closed)
-------------------------------------------------------------------- Reboot into Normal Mode. -------------------------------------------------------------------- Since Firefox works well for you, I'd like you to install the IE Tab add on for Firefox. We can use that Tab to perform an online scan and see if it will complete for you. https://addons.mozilla.org/firefox/1419/ Further instructions about how to use it can be found here. Once you've gotten the IE tab installed in Firefox, run an online scan at Panda: Make sure you've activated the IE Tab and perform this online scan using the IETab in Firefox at Panda ActiveScan
![]()
* Turn off the real time scanner of any existing antivirus program while performing the online scan ------------------------------------------------------------- Run dss.exe once again. Please include the following in your next reply: jotti results AVG A-S results Panda results New main.txt |
|
|
|
|
#6 (permalink) |
|
I helped the forums.
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)
|
Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?
Thanks for the look-see, I donated because I thought it was a worthy cause
, not because I needed/wanted help. The "dlbudrs.dll" file appears to be safe, see the results of the scan attached. I cannot run Firefox in IE view until after about ten minutes or so following a re-boot, same as running IE itself. I did run PandaScan with FF in IE view and the same things happens, it identifies some spyware, but closes itself after the scan with no offer to fix, buy, see report, or save report. Real-time scanners turned off, AV turned off, Anti-Spy, SpyGurad, etc. turned off and I have tried to remain on-line and off-line, no difference. Therefore I do not have a PandaScan report. Here are the other scan reports: Service Service load: 0% 100% File: dlbudrs.dll Status: OK MD5 6b2508e2b976416df8f57ff3c6e1fd52 Packers detected: - Scanner results Scan taken on 01 Apr 2007 17:51:20 (GMT) AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing Panda Antivirus Found nothing Rising Antivirus Found nothing VirusBuster Found nothing VBA32 Found nothing Complete scanning result of "dlbudrs.dll", received in VirusTotal at 04.01.2007, 19:51:11 (CET). Antivirus Version Update Result AhnLab-V3 2007.3.31.0 04.01.2007 no virus found AntiVir 7.3.1.47 04.01.2007 no virus found Authentium 4.93.8 03.31.2007 no virus found Avast 4.7.936.0 03.31.2007 no virus found AVG 7.5.0.447 03.31.2007 no virus found BitDefender 7.2 04.01.2007 no virus found CAT-QuickHeal 9.00 03.31.2007 no virus found ClamAV devel-20070312 04.01.2007 no virus found DrWeb 4.33 04.01.2007 no virus found eSafe 7.0.15.0 04.01.2007 no virus found eTrust-Vet 30.6.3527 03.31.2007 no virus found Ewido 4.0 04.01.2007 no virus found FileAdvisor 1 04.01.2007 no virus found Fortinet 2.85.0.0 04.01.2007 no virus found F-Prot 4.3.1.45 03.30.2007 no virus found F-Secure 6.70.13030.0 04.01.2007 no virus found Ikarus T3.1.1.3 04.01.2007 no virus found Kaspersky 4.0.2.24 04.01.2007 no virus found McAfee 4997 03.31.2007 no virus found Microsoft 1.2306 04.01.2007 no virus found NOD32v2 2161 04.01.2007 no virus found Norman 5.80.02 03.31.2007 no virus found Panda 9.0.0.4 04.01.2007 no virus found Prevx1 V2 04.01.2007 no virus found Sophos 4.16.0 03.30.2007 no virus found Sunbelt 2.2.907.0 03.31.2007 no virus found Symantec 10 04.01.2007 no virus found TheHacker 6.1.6.083 03.30.2007 no virus found UNA 1.83 03.16.2007 no virus found VBA32 3.11.3 04.01.2007 no virus found VirusBuster 4.3.7:9 04.01.2007 no virus found Webwasher-Gateway 6.0.1 04.01.2007 no virus found Aditional Information File size: 421888 bytes MD5: 6b2508e2b976416df8f57ff3c6e1fd52 SHA1: e3d1ffefcc24e2c9f7533a82f4679b4decdd42be --------------------------------------------------------- AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 3:43:53 PM 4/1/2007 + Scan result: C:\WINDOWS\SYSTEM32\B4FM.dll -> Adware.BurnFree : Cleaned with backup (quarantined). C:\Documents and Settings\Michael Shackelford\Local Settings\Temporary Internet Files\Content.IE5\EZBM30FO\mm[1].js -> Adware.Chitika : Cleaned with backup (quarantined). C:\WINDOWS\cpbrkpie.ocx -> Adware.Coupons : Cleaned with backup (quarantined). C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP854\A0111446.EXE -> Not-A-Virus.Downloader.Win32.DigStream.a : Cleaned with backup (quarantined). :mozilla.185:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.185:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.185:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.185:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.185:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.185:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.185:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.185:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.185:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.185:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.185:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.185:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.185:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.192:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Cnn : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.193:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Cnn : Cleaned. :mozilla.12:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Com : Cleaned. :mozilla.13:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Com : Cleaned. :mozilla.20:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Com : Cleaned. :mozilla.20:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Com : Cleaned. :mozilla.21:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.22:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Com : Cleaned. :mozilla.6:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Com : Cleaned. :mozilla.6:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Com : Cleaned. :mozilla.6:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Com : Cleaned. :mozilla.6:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Com : Cleaned. :mozilla.6:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Com : Cleaned. :mozilla.6:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Com : Cleaned. :mozilla.7:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Com : Cleaned. :mozilla.7:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Com : Cleaned. :mozilla.7:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Com : Cleaned. :mozilla.7:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Com : Cleaned. :mozilla.7:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Com : Cleaned. :mozilla.7:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Com : Cleaned. :mozilla.73:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.73:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.73:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.73:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.73:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.73:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.73:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.73:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.73:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.73:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.74:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.74:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.74:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.82:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.83:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.83:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.83:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.83:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.83:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.83:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.83:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.83:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Googleadservices : Cleaned. :mozilla.183:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.183:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.183:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.183:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.183:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.183:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.183:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.183:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.183:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.183:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.183:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.183:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.183:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.184:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.184:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.184:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.184:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.184:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.184:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.184:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.184:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.184:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.184:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.184:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.184:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.184:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.189:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.190:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.191:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.192:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.140:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.140:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.140:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.140:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.140:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.140:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.140:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.140:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.140:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.140:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.141:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.141:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.141:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.141:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.141:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.141:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.141:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.141:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.141:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.141:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.141:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.141:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.141:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.142:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.142:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.142:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.148:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.149:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.150:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.151:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.151:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.151:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.151:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.151:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.151:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.151:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Liveperson : Cleaned. :mozilla.151:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@search.msn[1].txt -> TrackingCookie.Msn : Cleaned. C:\Documents and Settings\Michael Shackelford\Cookies\michael_shackelford@search.msn[1].txt -> TrackingCookie.Msn : Cleaned. :mozilla.78:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.78:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.78:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.78:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.78:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.78:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.78:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.78:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.78:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.78:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.79:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.79:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.79:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.86:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.87:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.88:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.88:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.88:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.88:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.88:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.88:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.88:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.88:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Netflame : Cleaned. :mozilla.206:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.206:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.206:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.206:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.206:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.206:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.206:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.206:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.206:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.206:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.206:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.206:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.206:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.212:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.213:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Paypal : Cleaned. :mozilla.213:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.213:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.213:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Paypal : Cleaned. :mozilla.214:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Paypal : Cleaned. C:\Documents and Settings\Michael Shackelford\Cookies\michael_shackelford@www.paypal[1].txt -> TrackingCookie.Paypal : Cleaned. C:\Documents and Settings\Michael Shackelford\Cookies\michael shackelford@guide.real[1].txt -> TrackingCookie.Real : Cleaned. C:\Documents and Settings\Michael Shackelford\Cookies\michael shackelford@realguide.real[2].txt -> TrackingCookie.Real : Cleaned. :mozilla.161:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.161:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.161:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.161:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.161:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.161:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.161:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.161:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.161:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.161:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.161:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.161:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.161:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.162:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.162:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.162:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.162:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.162:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.162:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.162:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.162:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.162:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.162:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.162:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.162:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.162:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.163:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.163:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.163:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.163:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.163:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.163:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.163:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.163:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.163:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.163:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.163:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.163:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.163:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.164:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.164:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.164:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.164:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.164:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.164:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.164:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.164:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.164:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.164:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.164:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.164:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.164:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.172:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Tacoda : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00237388.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00237389.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00237391.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00237392.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00237393.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00237395.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00237396.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00237397.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00237399.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00237400.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00237402.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00237403.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.173:C:\RECYCLER\NPROTECT\00237405.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00237775.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238081.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238083.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238084.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238087.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238088.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238089.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238090.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238092.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238093.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238095.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238096.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238097.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238099.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238100.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238101.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238102.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238103.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238105.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238106.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238108.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238109.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238110.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238111.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238113.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238115.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238117.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.180:C:\RECYCLER\NPROTECT\00238128.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\Documents and Settings\Michael Shackelford\Application Data\Mozilla\Firefox\Profiles\pls2usvi.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237406.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237408.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237410.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237411.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237413.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237416.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237419.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237420.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237422.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237423.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237425.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237427.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237429.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237432.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237435.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237447.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237449.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237689.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237777.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237778.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00237780.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00238079.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00238945.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.181:C:\RECYCLER\NPROTECT\00238949.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.182:C:\RECYCLER\NPROTECT\00238130.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.182:C:\RECYCLER\NPROTECT\00238131.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.182:C:\RECYCLER\NPROTECT\00238132.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.182:C:\RECYCLER\NPROTECT\00238134.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.182:C:\RECYCLER\NPROTECT\00238136.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.182:C:\RECYCLER\NPROTECT\00238187.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.182:C:\RECYCLER\NPROTECT\00238895.MOZ -> TrackingCookie.Zedo : Cleaned. :mozilla.182:C:\RECYCLER\NPROTECT\00239021.MOZ -> TrackingCookie.Zedo : Cleaned. ::Report end |
|
|
|
|
#7 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 27,043
OS: WinXP and Vista
|
Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?
Let's see if Kaspersky's online scanner will complete for you:
Please perform an online scan with Internet Explorer at Kaspersky Online Scanner Answer Yes, when prompted to install an ActiveX component.
**Note for Internet Explorer 7 users** If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%. |
|
|
|
|
#8 (permalink) |
|
I helped the forums.
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)
|
Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT Tuesday, April 03, 2007 6:27:53 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.93.0 Kaspersky Anti-Virus database last update: 3/04/2007 Kaspersky Anti-Virus database records: 290647 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ F:\ G:\ Scan Statistics: Total number of scanned objects: 228785 Number of viruses found: 4 Number of infected objects: 12 Number of suspicious objects: 0 Duration of the scan process: 02:44:05 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ad391678a806ec4d691e83aaa393b6f_5b150187-0f05-4c72-917c-77c8e6964ac4 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\LOGS\ehRecvr.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Pure Networks\Network Magic\Log\logfile.nmapp_exe.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Pure Networks\Network Magic\Log\logfile.nmsrvc_exe.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-04-03_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\16351005.exe Infected: Trojan.Win32.Agent.qt skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1716610D.exe Infected: Trojan.Win32.Agent.qt skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\177F209A.exe Infected: Trojan.Win32.Agent.qt skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\182253E6.exe Infected: Trojan.Win32.Agent.qt skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\19B72A29.exe Infected: Trojan.Win32.Agent.qt skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\9413D31E.TMP Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SubEng\submissions.idx Object is locked skipped C:\Documents and Settings\All Users\Documents\My Downloads\ComcastToolbar.exe/data0055 Infected: not-a-virus:AdWare.Win32.BHO.al skipped C:\Documents and Settings\All Users\Documents\My Downloads\ComcastToolbar.exe NSIS: infected - 1 skipped C:\Documents and Settings\All Users\Documents\Old Dell XPS 933\ofcdatafiles\outlook backup.pst/Personal Folders/Inbox/03 Aug 2001 15:42 from endofauction@ebay.com:eBay End of Auction.eml Infected: Trojan-Spy.HTML.Bayfraud.ib skipped C:\Documents and Settings\All Users\Documents\Old Dell XPS 933\ofcdatafiles\outlook backup.pst Mail MS Mail: infected - 1 skipped C:\Documents and Settings\All Users\Documents\Old Dell XPS 933\ofcdatafiles\outlook.pst/Personal Folders/Inbox/eBay Stuff/02 Jun 2002 00:15 from endofauction@ebay.com:eBay End of Auction.eml Infected: Trojan-Spy.HTML.Bayfraud.ib skipped C:\Documents and Settings\All Users\Documents\Old Dell XPS 933\ofcdatafiles\outlook.pst Mail MS Mail: infected - 1 skipped C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\MSDVRMM_3838572047_655360_178649 Object is locked skipped C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\SBE1.tmp Object is locked skipped C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\{3C6FD663-F130-487E-9769-7E17370C1EB1}.TmpSBE Object is locked skipped C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Michael Shackelford\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Michael Shackelford\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped C:\Documents and Settings\Michael Shackelford\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Michael Shackelford\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Michael Shackelford\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Michael Shackelford\Local Settings\History\History.IE5\MSHist012007040320070404\index.dat Object is locked skipped C:\Documents and Settings\Michael Shackelford\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Michael Shackelford\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Michael Shackelford\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Inetpub\catalog.wci\00000002.ps1 Object is locked skipped C:\Inetpub\catalog.wci\00000002.ps2 Object is locked skipped C:\Inetpub\catalog.wci\00010001.ci Object is locked skipped C:\Inetpub\catalog.wci\cicat.fid Object is locked skipped C:\Inetpub\catalog.wci\cicat.hsh Object is locked skipped C:\Inetpub\catalog.wci\CiCL0001.000 Object is locked skipped C:\Inetpub\catalog.wci\CiP10000.000 Object is locked skipped C:\Inetpub\catalog.wci\CiP20000.000 Object is locked skipped C:\Inetpub\catalog.wci\CiPT0000.000 Object is locked skipped C:\Inetpub\catalog.wci\CiSL0001.000 Object is locked skipped C:\Inetpub\catalog.wci\CiSP0000.000 Object is locked skipped C:\Inetpub\catalog.wci\CiST0000.000 Object is locked skipped C:\Inetpub\catalog.wci\CiVP0000.000 Object is locked skipped C:\Inetpub\catalog.wci\INDEX.000 Object is locked skipped C:\Inetpub\catalog.wci\propstor.bk1 Object is locked skipped C:\Inetpub\catalog.wci\propstor.bk2 Object is locked skipped C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped C:\Program Files\Common Files\Symantec Shared\eengine\EPERSIST.DAT Object is locked skipped C:\Program Files\Common Files\Symantec Shared\NFWEVT.LOG Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped C:\RECYCLER\NPROTECT\NPROTECT.LOG Object is locked skipped C:\System Volume Information\catalog.wci\00000002.ps1 Object is locked skipped C:\System Volume Information\catalog.wci\00000002.ps2 Object is locked skipped C:\System Volume Information\catalog.wci\00010002.ci Object is locked skipped C:\System Volume Information\catalog.wci\cicat.fid Object is locked skipped C:\System Volume Information\catalog.wci\cicat.hsh Object is locked skipped C:\System Volume Information\catalog.wci\CiCL0001.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiP10000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiP20000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiPT0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiSL0001.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiSP0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiST0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiVP0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\INDEX.000 Object is locked skipped C:\System Volume Information\catalog.wci\propstor.bk1 Object is locked skipped C:\System Volume Information\catalog.wci\propstor.bk2 Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP860\A0116453.ocx Infected: not-a-virus:AdWare.Win32.Coupons.h skipped C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP862\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\ModemLog_Intel(R) 537EP V9x DF PCI Modem.txt Object is locked skipped C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{69E7DCB1-CE60-4477-968E-265FCC67728D}.crmlog Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\Media Ce.evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped C:\WINDOWS\SYSTEM32\Logfiles\W3SVC1\ex070403.log Object is locked skipped C:\WINDOWS\SYSTEM32\Logfiles\WUDF\WUDFTrace.etl Object is locked skipped C:\WINDOWS\SYSTEM32\MsDtc\MSDTC.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\MsDtc\Trace\DTCTRACE.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_86c.dat Object is locked skipped C:\WINDOWS\WIADEBUG.LOG Object is locked skipped C:\WINDOWS\WIASERVC.LOG Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped F:\RECYCLED\NPROTECT\NPROTECT.LOG Object is locked skipped Scan process completed. |
|
|
|
|
#9 (permalink) | |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 27,043
OS: WinXP and Vista
|
Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?
This is what Kaspersky trims down to:
Quote:
Delete the following file: C:\Documents and Settings\All Users\Documents\My Downloads\ ComcastToolbar.exe ----------------------------------------------------------- How long have you used Norton Go-Back? Have you added any new programs just before your issues began? |
|
|
|
|
|
#10 (permalink) |
|
I helped the forums.
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)
|
Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?
I deleted the entire folder where each of the files in red were located and have done a fresh reboot. None of them were necessary. (No difference so far).
I have never used Norton Go-Back, but do know that it is installed. I did just recently install Norton Internet Security 2007, but will be happy to uninstall it if that will make everything better. I also have Norton System Works installed from a year ago and have been using its AV and other programs with no problems that I am aware of until now. I can easily live without any of its programs and start using the ones suggested here instead. Please let me know what and how to proceed from here. Thanks again, Mike. |
|
|
|
|
#11 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 27,043
OS: WinXP and Vista
|
Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?
Hi Mike,
I'd just about bet that all those extra Norton products are at the root of your problem. GoBack is installed as part of Norton System Works unless you opt out. It is loading at startup and running behind the scenes all the time: O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe Every time you boot your computer, GoBack is 'taking stock' of the entire system and loading up. Every time you add a new program, or uninstall a program, or download, it's there logging all the changes including the registry changes. GoBack can be a valuable asset, but is basically redundant as Windows XP has a built in System Restore. Since you've installed Norton Internet Security 2007, all the previous Norton products need to be uninstalled via the Add/Remove programs: Norton AntiVirus Norton SystemWorks Norton SystemWorks 2006 Norton SystemWorks 2006 While you're in the Add/Remove programs, you may as well uninstall your previous version of Java as it is no longer needed and continues to pose a security risk. Java 2 Runtime Environment, SE v1.4.2_03 Norton GoBack 4.1 <--If curiosity has gotten a hold of you, you can choose to leave this for now and disable the startup and service and see if it makes any difference in your boot time: Run a scan with HijackThis and fix the following entry: O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe Click 'Fix Checked' and close HijackThis. Next, click Start->Run - type services.msc & then click on the OK button *Locate the service - GoBack Polling Service (GBPoll) *Double-click on it to open the Properties dialog. *Under the General tab *Stop the service by using the Stop button. *Change the Startup type to Disabled & then click on the OK button Reboot your system for that to take effect. Let me know if the above procedures have improved your system's behavior |
|
|
|
|
#12 (permalink) |
|
I helped the forums.
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)
|
Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?
OK, I have uninstalled all Norton programs that I could find. I must have disabled GoBack already because I could not find it to fix with HijackThis. I also uninstalled Java 2 Runtime Environment, SE v1.4.2_03 as suggested. No change, IE still "hangs" for about 10 minutes before starting as do some other programs. Still cannot print.
I as of yet have not installed any new AV or Firewall programs to replace the Norton programs. Waiting for advice or instructions. I have included a new HJT log for your info. Thanks again, Mike. Logfile of HijackThis v1.99.1 Scan saved at 9:04:17 PM, on 4/4/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe C:\Program Files\Pure Networks\Network Magic\nmapp.exe C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\SpywareGuard\sgmain.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe" O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative.com/su/ocx/15015/CTSUEng.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/LSSupCtl.cab O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} - http://dlmanager.akamaitools.com.edg...ex-2.0.5.0.cab O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/S...in/AvSniff.cab O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-36.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/S.../bin/cabsa.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1129351655375 O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/40...02/Coupons.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/pro...tor/WebAAS.cab O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/SymAData.cab O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative.com/su/ocx/15023/CTPID.cab O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\puresp3.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing) O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PowerPanel Personal Edition Service (ppped) - Unknown owner - C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe Last edited by Ried; 04-05-2007 at 09:55 AM. |
|
|
|
|
#13 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 27,043
OS: WinXP and Vista
|
Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?
Hi Mike,
I'm not finding malware to be the source and it could be difficult to pinpoint exactly what is causing the trouble. Do you happen to recall if your issues began around the same time you installed Norton Internet Security 2007? |
|
|
|
|
#14 (permalink) |
|
I helped the forums.
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)
|
Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?
Yes, issues started short time after installing Norton Internet Security 2007, which I have now uninstalled, but sure traces remain I am sure.
I also installed Network Magic with new wireless router for new VISTA laptop at about the same time. What else can I do to find the source of this problem and/or get back to running normal? Mike. |
|
|
|
|
#15 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 27,043
OS: WinXP and Vista
|
Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?
Hi Mike,
Let's see if Norton did uninstall properly. Run another scan with HijackThis and post the log here. |
|
|
|
|
#16 (permalink) |
|
I helped the forums.
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)
|
Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?
OK, here is HJT log immediately after turning power on computer and logging on before IE will start and posting by using Firefox. I will post another immediately after IE and everything else starts in ten minutes or so.
Logfile of HijackThis v1.99.1 Scan saved at 8:31:26 PM, on 4/6/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\system32\dlbucoms.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\fxssvc.exe C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe C:\Program Files\Pure Networks\Network Magic\nmapp.exe C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\SpywareGuard\sgmain.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe" O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative.com/su/ocx/15015/CTSUEng.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/LSSupCtl.cab O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} - http://dlmanager.akamaitools.com.edg...ex-2.0.5.0.cab O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/S...in/AvSniff.cab O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-36.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/S.../bin/cabsa.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1129351655375 O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/40...02/Coupons.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/pro...tor/WebAAS.cab O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/SymAData.cab O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative.com/su/ocx/15023/CTPID.cab O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\puresp3.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing) O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PowerPanel Personal Edition Service (ppped) - Unknown owner - C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe |
|
|
|
|
#17 (permalink) |
|
I helped the forums.
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)
|
Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?
OK, I have attached the HJT text file (#2) to this post after IE would start and when seems everything else works somewhat more correctly (still can't print). Mike.
2nd log: Logfile of HijackThis v1.99.1 Scan saved at 8:57:25 PM, on 4/6/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe C:\Program Files\Pure Networks\Network Magic\nmapp.exe C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\SpywareGuard\sgmain.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe" O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative.com/su/ocx/15015/CTSUEng.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/LSSupCtl.cab O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} - http://dlmanager.akamaitools.com.edg...ex-2.0.5.0.cab O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/S...in/AvSniff.cab O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-36.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/S.../bin/cabsa.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1129351655375 O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/40...02/Coupons.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/pro...tor/WebAAS.cab O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/SymAData.cab O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative.com/su/ocx/15023/CTPID.cab O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\puresp3.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing) O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PowerPanel Personal Edition Service (ppped) - Unknown owner - C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe |
|
|
|
|
#18 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 27,043
OS: WinXP and Vista
|
Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?
Hi,
I'm still seeing remnants of Symantec. Here is a guide for uninstalling Norton, including uninstallers. Be sure to use the uninstaller for the version of Norton/Symantec that is active on your system. http://basconotw.mvps.org/SymRem.htm Post a new HijackThis log after using the uninstaller. Let me know if there is any change in your system's behavior. |
|
|
|
|
#19 (permalink) |
|
I helped the forums.
Join Date: Nov 2005
Location: chicagoland
Posts: 36
OS: XP (Media Center 2005)
|
Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?
I ran every uninstall and followed every instruction I could find for removing every trace of Norton/Symantec products including going into regedit and deleting every folder and file with Norton or Symantec in the name.
Computer runs the same after several reboots. Explorer and a couple of other programs still take about 10 minutes before they will load. Still no printing. Here is the latest HJT log: Logfile of HijackThis v1.99.1 Scan saved at 12:47:12 PM, on 4/7/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\system32\dlbucoms.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\fxssvc.exe C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe C:\Program Files\Pure Networks\Network Magic\nmapp.exe C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\SpywareGuard\sgmain.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\dumprep.exe C:\WINDOWS\system32\dwwin.exe C:\Program Files\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe" O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative.com/su/ocx/15015/CTSUEng.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/LSSupCtl.cab O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} - http://dlmanager.akamaitools.com.edg...ex-2.0.5.0.cab O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/S...in/AvSniff.cab O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-36.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/S.../bin/cabsa.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1129351655375 O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/40...02/Coupons.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/pro...tor/WebAAS.cab O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/SymAData.cab O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative.com/su/ocx/15023/CTPID.cab O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\puresp3.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing) O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PowerPanel Personal Edition Service (ppped) - Unknown owner - C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe |
|
|
|
|
#20 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 27,043
OS: WinXP and Vista
|
Re: HJT Help Please, 2nd Request, SLOW Start-up, Malware?
Norton has been removed--nice work.
![]() I still don't like the looks of this file C:\WINDOWS\system32\dlbudrs.dll. I know the virus scan came up with nothing, but I'm also not finding any information at all on this file anywhere. Rename the file to C:\WINDOWS\system32\dlbudrs.old If any problems arise, rename it back to dlburds.dll ------------------------------------------------------------- Run a scan with HijackThis and fix these O16 entries: O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/LSSupCtl.cab O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} - http://dlmanager.akamaitools.com.edg...ex-2.0.5.0.cab O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/S...in/AvSniff.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/S.../bin/cabsa.cab O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/40...02/Coupons.cab O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/SymAData.cab Click 'Fix Checked' and close HijackThis. Reboot your system. Any change? |
|
|
| Thread Tools | |
|
|