Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93084 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Help with HiJackthis Log


  • This topic is locked This topic is locked
13 replies to this topic

#1 TCUser2

TCUser2

    New Member

  • New Member
  • Pip
  • 6 posts

Posted 16 March 2007 - 07:20 PM

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:35:37 PM, on 3/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\ClocX\ClocX.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/explore.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\DESKTOP\utilities\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ClocX] C:\Program Files\ClocX\ClocX.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-21-1547161642-1580818891-682003330-1006\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup (User 'Leanne')
O4 - HKUS\S-1-5-21-1547161642-1580818891-682003330-1006\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c (User 'Leanne')
O4 - HKUS\S-1-5-21-1547161642-1580818891-682003330-1006\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Leanne')
O4 - HKUS\S-1-5-21-1547161642-1580818891-682003330-1006\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe (User 'Leanne')
O4 - HKUS\S-1-5-21-1547161642-1580818891-682003330-1006\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart (User 'Leanne')
O4 - HKUS\S-1-5-21-1547161642-1580818891-682003330-1006\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Leanne')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: CreataCard Gold 3 Forget Me Not Reminders Tray Icon.lnk = C:\Program Files\CreataCard\Gold\FMRemind.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Support - {6137A22B-7653-4383-B7BA-8056BA10D091} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: Help - {80F91D55-DCA1-4B6C-9E0B-FDE073EFF698} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {FE5EB236-AEA5-4C9D-A3C7-C634BFEEB60D} - http://www.comcast.net (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell....iler/SysPro.CAB
O16 - DPF: {0441781A-3075-4C8F-9FDB-A6BCAE8769A1} (vmLaunch Class) - http://downloads.com.../vmLauncher.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative....015/CTSUEng.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.s...rl/LSSupCtl.cab
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.micr...ActiveX/odc.cab
O16 - DPF: {416792D8-F532-493A-BECC-1C99A1501FF9} (vmLaunch Class) - http://media2.comcas...vmLauncher2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://leannemaries....ad/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safe...lscbase8460.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1122147819031
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symant...ex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1123718319156
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.s...rl/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://liveca12.cust...l/java/RntX.cab
O16 - DPF: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} (ActiveCGM Control) - https://www.dot7.sta...t/ACGM/acgm.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Abmdrvk - - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 12205 bytes

    Advertisements

Register to Remove


#2 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 17 March 2007 - 07:56 AM

Hello and Welcome to the Forum.

Please delete any HijackThis Folders and Files you have now.Use Add/Remove Programs and remove HijackThis. The version you're running is a Beta and still has bugs.

you can get a complete installer that installs HijackThis to C:\Program Files\HijackThis, making an entry in the start menu and also providing a desktop shortcut from http://downloads.mal...om/HJTsetup.exe.

Click on the link and select Save, save it to your desktop and double click HJTsetup.exe.

Open HijackThis and select: Do a system scan and save a log file.

When the scan is finished, Click Edit> Select All> Edit> Copy> and paste its contents here please use the [Add Reply] button below.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#3 TCUser2

TCUser2

    New Member

  • New Member
  • Pip
  • 6 posts

Posted 17 March 2007 - 08:10 AM

Hello and thank you for your quick response. Here it is. The only thing I can comment on about this log is that I don't have any epson devices. I appreciate your feedback.
Logfile of HijackThis v1.99.1
Scan saved at 10:02:36 AM, on 3/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\ClocX\ClocX.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\CreataCard\Gold\FMRemind.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\WISPTIS.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Utilities\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/explore.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\DESKTOP\utilities\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ClocX] C:\Program Files\ClocX\ClocX.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: CreataCard Gold 3 Forget Me Not Reminders Tray Icon.lnk = C:\Program Files\CreataCard\Gold\FMRemind.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Support - {6137A22B-7653-4383-B7BA-8056BA10D091} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: Help - {80F91D55-DCA1-4B6C-9E0B-FDE073EFF698} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {FE5EB236-AEA5-4C9D-A3C7-C634BFEEB60D} - http://www.comcast.net (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell....iler/SysPro.CAB
O16 - DPF: {0441781A-3075-4C8F-9FDB-A6BCAE8769A1} (vmLaunch Class) - http://downloads.com.../vmLauncher.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative....015/CTSUEng.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.s...rl/LSSupCtl.cab
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.micr...ActiveX/odc.cab
O16 - DPF: {416792D8-F532-493A-BECC-1C99A1501FF9} (vmLaunch Class) - http://media2.comcas...vmLauncher2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://leannemaries....ad/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safe...lscbase8460.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1122147819031
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symant...ex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1123718319156
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.s...rl/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://liveca12.cust...l/java/RntX.cab
O16 - DPF: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} (ActiveCGM Control) - https://www.dot7.sta...t/ACGM/acgm.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Abmdrvk - - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Also, I don't know what goes on when I have all programs closed that causes my CPU load to spike regularly and frequently to 99%, but it happens. (I think it is Norton)

#4 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 17 March 2007 - 08:22 AM

frequently to 99%, but it happens. (I think it is Norton)

Very well could be.

Do you use IncrediMail?


Click Start > Run > and type in:

services.msc

Click OK.

In the services window find EPSON Printer Status Agent2 (EPSONStatusAgent2)
Right click and choose "Properties". On the "General" tab under "Service
Status" click the "Stop" button to stop the service. Beside "Startup Type"
in the dropdown menu select "Disabled". Click Apply then OK.

Do the same for Abmdrvk if listed:

Exit the
Services utility.



Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - Global Startup: CreataCard Gold 3 Forget Me Not Reminders Tray Icon.lnk = C:\Program Files\CreataCard\Gold\FMRemind.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell....iler/SysPro.CAB
O16 - DPF: {0441781A-3075-4C8F-9FDB-A6BCAE8769A1} (vmLaunch Class) - http://downloads.com.../vmLauncher.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative....015/CTSUEng.cab
O16 - DPF: {416792D8-F532-493A-BECC-1C99A1501FF9} (vmLaunch Class) - http://media2.comcas...vmLauncher2.cab
O23 - Service: Abmdrvk - - (no file)
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe

Close ALL windows and browsers except HijackThis and click "Fix checked"


Delete this file:
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe



Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#5 TCUser2

TCUser2

    New Member

  • New Member
  • Pip
  • 6 posts

Posted 17 March 2007 - 09:54 AM

I still have an Epson folder left - may I delete it safely? Yes, I do have incredimail. What is Office 11 I wonder

Thanks again. Firefox is very, very slow starting up (and I've done it about 3 times since reboot)....

Logfile of HijackThis v1.99.1
Scan saved at 11:42:06 AM, on 3/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\ClocX\ClocX.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Utilities\Hijackthis\HijackThis.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/explore.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\DESKTOP\utilities\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [ClocX] C:\Program Files\ClocX\ClocX.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Support - {6137A22B-7653-4383-B7BA-8056BA10D091} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: Help - {80F91D55-DCA1-4B6C-9E0B-FDE073EFF698} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {FE5EB236-AEA5-4C9D-A3C7-C634BFEEB60D} - http://www.comcast.net (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.s...rl/LSSupCtl.cab
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.micr...ActiveX/odc.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://leannemaries....ad/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safe...lscbase8460.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1122147819031
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symant...ex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1123718319156
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.s...rl/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://liveca12.cust...l/java/RntX.cab
O16 - DPF: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} (ActiveCGM Control) - https://www.dot7.sta...t/ACGM/acgm.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Abmdrvk - - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Also, if you have any insight on why I can't capture screen shots w/my PRT SCREEN key as I could before.
Thanks again...

#6 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 17 March 2007 - 10:00 AM

http://www.winsupers...ice11_beta1.asp

Also, if you have any insight on why I can't capture screen shots w/my PRT SCREEN key as I could before.

That I don't know.

I still have an Epson folder left - may I delete it safely?

Look in add/remove programs first.


Download AVG Anti-Spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select " "Quarantine" .".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
  • Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close AVG Anti-Spyware and reboot your system back into Normal Mode and post the
    results of the AVG Anti-Spyware report scan along with a new HijackThis log.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#7 TCUser2

TCUser2

    New Member

  • New Member
  • Pip
  • 6 posts

Posted 17 March 2007 - 11:51 AM

Will do...I do Spybot SD and Adaware regularly.... Epson is not in my program list to uninstall. Be right back.Thanks!

#8 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 17 March 2007 - 12:39 PM

:thumbup:

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#9 TCUser2

TCUser2

    New Member

  • New Member
  • Pip
  • 6 posts

Posted 17 March 2007 - 02:30 PM

OK: Abmdrvk wasnot in services.msc to remove - also, using HJ doesn't remove it from report:
Logfile of HijackThis v1.99.1
Scan saved at 4:12:12 PM, on 3/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Documents and Settings\Owner\Desktop\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\ClocX\ClocX.exe
C:\Documents and Settings\Owner\Desktop\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Utilities\Hijackthis\HijackThis.exe
C:\Program Files\Utilities\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/explore.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\DESKTOP\utilities\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [ClocX] C:\Program Files\ClocX\ClocX.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\Owner\Desktop\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Support - {6137A22B-7653-4383-B7BA-8056BA10D091} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: Help - {80F91D55-DCA1-4B6C-9E0B-FDE073EFF698} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {FE5EB236-AEA5-4C9D-A3C7-C634BFEEB60D} - http://www.comcast.net (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.s...rl/LSSupCtl.cab
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.micr...ActiveX/odc.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://leannemaries....ad/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safe...lscbase8460.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1122147819031
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symant...ex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1123718319156
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.s...rl/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://liveca12.cust...l/java/RntX.cab
O16 - DPF: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} (ActiveCGM Control) - https://www.dot7.sta...t/ACGM/acgm.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Abmdrvk - - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Documents and Settings\Owner\Desktop\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

avg REPORT THERE WERE 4007 - REPORT TOO LONG SO I'M TRUNCATING OR IF YOU HAVE ANY OTHER ideas
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 3:46:56 PM 3/17/2007

+ Scan result:




:mozilla.167:C:\RECYCLER\NPROTECT\00447194.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00447130.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00447192.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.168:C:\RECYCLER\NPROTECT\00447198.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00447200.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.172:C:\RECYCLER\NPROTECT\00447203.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.174:C:\RECYCLER\NPROTECT\00447136.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.174:C:\RECYCLER\NPROTECT\00447194.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.175:C:\RECYCLER\NPROTECT\00447130.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.175:C:\RECYCLER\NPROTECT\00447136.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.175:C:\RECYCLER\NPROTECT\00447192.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.175:C:\RECYCLER\NPROTECT\00447194.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.175:C:\RECYCLER\NPROTECT\00447198.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.175:C:\RECYCLER\NPROTECT\00447232.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.176:C:\RECYCLER\NPROTECT\00447130.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.176:C:\RECYCLER\NPROTECT\00447136.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.176:C:\RECYCLER\NPROTECT\00447192.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.176:C:\RECYCLER\NPROTECT\00447194.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.176:C:\RECYCLER\NPROTECT\00447198.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.177:C:\RECYCLER\NPROTECT\00447130.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.177:C:\RECYCLER\NPROTECT\00447136.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.177:C:\RECYCLER\NPROTECT\00447192.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.177:C:\RECYCLER\NPROTECT\00447194.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.177:C:\RECYCLER\NPROTECT\00447198.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.178:C:\RECYCLER\NPROTECT\00447130.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.178:C:\RECYCLER\NPROTECT\00447136.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.178:C:\RECYCLER\NPROTECT\00447192.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.178:C:\RECYCLER\NPROTECT\00447194.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.178:C:\RECYCLER\NPROTECT\00447198.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.179:C:\RECYCLER\NPROTECT\00447130.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.179:C:\RECYCLER\NPROTECT\00447136.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.179:C:\RECYCLER\NPROTECT\00447192.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.179:C:\RECYCLER\NPROTECT\00447194.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.179:C:\RECYCLER\NPROTECT\00447198.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.179:C:\RECYCLER\NPROTECT\00447200.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.179:C:\RECYCLER\NPROTECT\00447203.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00447130.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00447136.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00447192.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00447194.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00447198.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00447200.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.180:C:\RECYCLER\NPROTECT\00447203.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00447130.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00447192.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00447198.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00447200.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00447203.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.181:C:\RECYCLER\NPROTECT\00447235.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.182:C:\RECYCLER\NPROTECT\00447200.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.182:C:\RECYCLER\NPROTECT\00447203.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.182:C:\RECYCLER\NPROTECT\00447232.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.182:C:\RECYCLER\NPROTECT\00447253.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.183:C:\RECYCLER\NPROTECT\00447200.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.183:C:\RECYCLER\NPROTECT\00447203.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.183:C:\RECYCLER\NPROTECT\00447232.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.184:C:\RECYCLER\NPROTECT\00447200.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.184:C:\RECYCLER\NPROTECT\00447203.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.184:C:\RECYCLER\NPROTECT\00447232.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.185:C:\RECYCLER\NPROTECT\00447200.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.185:C:\RECYCLER\NPROTECT\00447203.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.185:C:\RECYCLER\NPROTECT\00447232.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.186:C:\RECYCLER\NPROTECT\00447232.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.187:C:\RECYCLER\NPROTECT\00447232.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.187:C:\RECYCLER\NPROTECT\00447509.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.188:C:\RECYCLER\NPROTECT\00447232.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.188:C:\RECYCLER\NPROTECT\00447235.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.188:C:\RECYCLER\NPROTECT\00447511.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.188:C:\RECYCLER\NPROTECT\00447516.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00447235.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00447253.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.189:C:\RECYCLER\NPROTECT\00447263.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00447235.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.190:C:\RECYCLER\NPROTECT\00447253.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00447235.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00447253.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00447267.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.191:C:\RECYCLER\NPROTECT\00447269.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00447235.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.192:C:\RECYCLER\NPROTECT\00447253.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00447235.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00447253.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.193:C:\RECYCLER\NPROTECT\00447273.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.193:C:\RECYCLER\NPROT
:mozilla.198:C:\RECYCLER\NPROTECT\00447263.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.198:C:\RECYCLER\NPROTECT\00447267.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.198:C:\RECYCLER\NPROTECT\00447269.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.198:C:\RECYCLER\NPROTECT\00447509.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.198:C:\RECYCLER\NPROTECT\00447511.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.198:C:\RECYCLER\NPROTECT\00447516.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.199:C:\RECYCLER\NPROTECT\00447263.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.199:C:\RECYCLER\NPROTECT\00447267.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.199:C:\RECYCLER\NPROTECT\00447269.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.199:C:\RECYCLER\NPROTECT\00447509.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozillleaned.
:mozilla.201:C:\RECYCLER\NPROTECT\00447269.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.201:C:\RECYCLER\NPROTECT\00447273.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.201:C:\RECYCLER\NPROTECT\00447275.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.201:C:\RECYCLER\NPROTECT\00447277.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.201:C:\RECYCLER\NPROTECT\00447280.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.201:C:\RECYCLER\NPROTECT\00447282.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.201:C:\RECYCLER\NPROTECT\00447336.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.201:C:\RECYCLER\NPROTECT\00447511.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.201:C:\RECYCLER\NPROTECT\00447516.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.202:C:\RECYCLER\NPROTECT\00447263.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.202:C:\RECYCLER\NPROTECT\00447267.MOZ -> TrackingCookie.Hitbox : Cleaned.
:
:mozilla.348:C:\RECYCLER\NPROTECT\00447282.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.348:C:\RECYCLER\NPROTECT\00447336.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.350:C:\RECYCLER\NPROTECT\00447263.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.351:C:\RECYCLER\NPROTECT\00447338.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.351:C:\RECYCLER\NPROTECT\00447340.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.351:C:\RECYCLER\NPROTECT\00447343.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.351:C:\RECYCLER\NPROTECT\00447361.MOZ -> TrackingCookie.Hitbox : Cleaned.
:mozilla.354:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.355:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.356:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.357:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.358:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.434:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.445:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-1.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.46:F:\User Data\Mozilla\pgdc571e.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.47:F:\User Data\Mozilla\pgdc571e.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.48:F:\User Data\Mozilla\pgdc571e.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.491:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-1.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.492:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-1.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.49:F:\User Data\Mozilla\pgdc571e.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.52:F:\User Data\XP\Documents and Settings\Leanne Votta\Application Data\Mozilla\Profiles\default\lu677qzt.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.53:F:\User Data\XP\Documents and Settings\Leanne Votta\Application Data\Mozilla\Profiles\default\lu677qzt.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.54:F:\User Data\XP\Documents and Settings\Leanne Votta\Application Data\Mozilla\Profiles\default\lu677qzt.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.558:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.55:F:\User Data\XP\Documents and Settings\Leanne Votta\Application Data\Mozilla\Profiles\default\lu677qzt.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.8:F:\User Data\XP\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\zqxopy3v.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.912:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.913:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.919:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.306:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-1.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.742:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.195:F:\User Data\Mozilla\pgdc571e.default\cookies.txt -> TrackingCookie.Information : Cleaned.
C:\RECYCLER\NPROTECT\00448865.TXT -> TrackingCookie.Live : Cleaned.
:mozilla.26:F:\User Data\XP\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\zqxopy3v.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.27:F:\User Data\XP\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\zqxopy3v.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.28:F:\User Data\XP\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\zqxopy3v.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.599:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.600:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.601:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.631:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.632:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.633:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.705:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.706:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.127:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-1.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.715:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.12:C:\RECYCLER\NPROTECT\00447200.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\00447200.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.15:C:\RECYCLER\NPROTECT\00447203.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.164:C:\RECYCLER\NPROTECT\00447136.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.164:C:\RECYCLER\NPROTECT\00447194.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.165:C:\RECYCLER\NPROTECT\00447130.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.165:C:\RECYCLER\NPROTECT\00447136.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.165:C:\RECYCLER\NPROTECT\00447192.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.165:C:\RECYCLER\NPROTECT\00447194.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.165:C:\RECYCLER\NPROTECT\00447198.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.166:C:\RECYCLER\NPROTECT\00447130.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.166:C:\RECYCLER\NPROTECT\00447192.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.166:C:\RECYCLER\NPROTECT\00447198.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\00447203.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\00447232.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.225:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.22:C:\RECYCLER\NPROTECT\00447232.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.22:C:\RECYCLER\NPROTECT\00447511.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.22:C:\RECYCLER\NPROTECT\00447516.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.23:C:\RECYCLER\NPROTECT\00447511.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.23:C:\RECYCLER\NPROTECT\00447516.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.26:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.27:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.28:C:\RECYCLER\NPROTECT\00447235.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.29:C:\RECYCLER\NPROTECT\00447235.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.40:C:\RECYCLER\NPROTECT\00447253.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.41:C:\RECYCLER\NPROTECT\00447253.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.45:C:\RECYCLER\NPROTECT\00447509.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.46:C:\RECYCLER\NPROTECT\00447509.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.47:C:\RECYCLER\NPROTECT\00447263.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.48:C:\RECYCLER\NPROTECT\00447263.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.49:C:\RECYCLER\NPROTECT\00447267.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.49:C:\RECYCLlex : Cleaned.
:mozilla.54:C:\RECYCLER\NPROTECT\00447340.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.54:C:\RECYCLER\NPROTECT\00447343.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.54:C:\RECYCLER\NPROTECT\00447361.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.55:C:\RECYCLER\NPROTECT\00447338.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.55:C:\RECYCLER\NPROTECT\00447340.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.55:C:\RECYCLER\NPROTECT\00447343.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.55:C:\RECYCLER\NPROTECT\00447361.MOZ -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.82:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-1.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\RECYCLER\NPROTECT\00448854.TXT -> TrackingCookie.Mediaplex : Cleaned.
F:\User Data\XP\Documents and Settings\Guest\Cookies\guest@search.msn[2].txt -> TrackingCookie.Msn : Cleaned.
F:\User Data\XP\Documents and Settings\Leanne Votta\Cookies\leanne votta@search.msn[1].txt -> TrackingCookie.Msn : Cleaned.
:r : Cleaned.
:mozilla.353:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.354:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.355:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.356:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.357:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.358:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.359:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.360:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.361:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.362:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.363:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.364:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.365:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.366:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.367:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.368:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.369:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.370:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.371:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.372:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.373:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.374:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.375:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.376:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies-2.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.763:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.764:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.765:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.766:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.767:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.768:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.769:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.770:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.771:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.772:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.773:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.774:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.775:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.776:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.777:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.778:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.779:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.780:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.781:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.782:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.783:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.784:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.785:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.786:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.787:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.788:C:\Documents and Settings\Leanne\Application Data\Mozilla\Firefox\Profiles\9jjzlq2m.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.100:C:\RECYCLER\NPROTECT\00447130.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.100:C:\RECYCLER\NPROTECT\00447192.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.100:C:\RECYCLER\NPROTECT\00447198.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.100:C:\RECYCLER\NPROTECT\00447200.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.100:C:\RECYCLER\NPROTECT\00447203.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.101:C:\RECYCLER\NPROTECT\00447136.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.101:C:\RECYCLER\NPROTECT\00447194.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.102:C:\RECYCLER\NPROTECT\00447130.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.102:C:\RECYCLER\NPROTECT\00447136.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.102:C:\RECYCLER\NPROTECT\00447192.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.102:C:\RECYCLER\NPROTECT\00447194.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.102:C:\RECYCLER\NPROTECT\00447198.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.103:C:\RECYCLER\NPROTECT\00447130.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.103:C:\RECYCLER\NPROTECT\00447192.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.103:C:\RECYCLER\NPROTECT\00447198.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.103:C:\RECYCLER\NPROTECT\00447232.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.103:C:\RECYCLER\NPROTECT\00447235.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.104:C:\RECYCLER\NPROTECT\00447253.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.109:C:\RECYCLER\NPROTECT\00447200.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.109:C:\RECYCLER\NPROTECT\00447203.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.109:C:\RECYCLER\NPROTECT\00447235.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.109:C:\RECYCLER\NPROTECT\00447509.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.110:C:\RECYCLER\NPROTECT\00447200.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.110:C:\RECYCLER\NPROTECT\00447203.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.110:C:\RECYCLER\NPROTECT\00447253.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.111:C:\RECYCLER\NPROTECT\00447200.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.111:C:\RECYCLER\NPROTECT\00447203.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.111:C:\RECYCLER\NPROTECT\00447263.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.112:C:\RECYCLER\NPROTECT\00447232.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.113:C:\RECYCLER\NPROTECT\00447200.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.113:C:\RECYCLER\NPROTECT\00447203.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.113:C:\RECYCLER\NPROTECT\00447232.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.113:C:\RECYCLER\NPROTECT\00447267.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.113:C:\RECYCLER\NPROTECT\00447269.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.113:C:\RECYCLER\NPROTECT\00447511.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.113:C:\RECYCLER\NPROTECT\00447516.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.114:C:\RECYCLER\NPROTECT\00447200.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.114:C:\RECYCLER\NPROTECT\00447203.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.114:C:\RECYCLER\NPROTECT\00447232.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.115:C:\RECYCLER\NPROTECT\00447273.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.115:C:\RECYCLER\NPROTECT\00447275.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.115:C:\RECYCLER\NPROTECT\00447277.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.115:C:\RECYCLER\NPROTECT\00447280.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.115:C:\RECYCLER\NPROTECT\00447282.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.115:C:\RECYCLER\NPROTECT\00447336.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.115:C:\RECYCLER\NPROTECT\00447509.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.116:C:\RECYCLER\NPROTECT\00447232.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.117:C:\RECYCLER\NPROTECT\00447232.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.117:C:\RECYCLER\NPROTECT\00447263.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.118:C:\RECYCLER\NPROTECT\00447235.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.118:C:\RECYCLER\NPROTECT\00447338.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.118:C:\RECYCLER\NPROTECT\00447340.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.118:C:\RECYCLER\NPROTECT\00447343.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.118:C:\RECYCLER\NPROTECT\00447361.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.119:C:\RECYCLER\NPROTECT\00447235.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.119:C:\RECYCLER\NPROTECT\00447253.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.119:C:\RECYCLER\NPROTECT\00447267.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.119:C:\RECYCLER\NPROTECT\00447269.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.119:C:\RECYCLER\NPROTECT\00447511.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.119:C:\RECYCLER\NPROTECT\00447516.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.120:C:\RECYCLER\NPROTECT\00447235.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.120:C:\RECYCLER\NPROTECT\00447253.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.121:C:\RECYCLER\NPROTECT\00447253.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.121:C:\RECYCLER\NPROTECT\00447273.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.121:C:\RECYCLER\NPROTECT\00447275.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.121:C:\RECYCLER\NPROTECT\00447277.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.121:C:\RECYCLER\NPROTECT\00447280.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.121:C:\RECYCLER\NPROTECT\00447282.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.121:C:\RECYCLER\NPROTECT\00447336.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.122:C:\RECYCLER\NPROTECT\00447235.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.123:C:\RECYCLER\NPROTECT\00447235.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.123:C:\RECYCLER\NPROTECT\00447253.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.124:C:\RECYCLER\NPROTECT\00447253.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.124:C:\RECYCLER\NPROTECT\00447338.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.124:C:\RECYCLER\NPROTECT\00447340.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.124:C:\RECYCLER\NPROTECT\00447343.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.124:C:\RECYCLER\NPROTECT\00447361.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.124:C:\RECYCLER\NPROTECT\00447509.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.125:C:\RECYCLER\NPROTECT\00447509.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.126:C:\RECYCLER\NPROTECT\00447263.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.126:C:\RECYCLER\NPROTECT\00447509.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.127:C:\RECYCLER\NPROTECT\00447263.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.127:C:\RECYCLER\NPROTECT\00447511.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.127:C:\RECYCLER\NPROTECT\00447516.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.128:C:\RECYCLER\NPROTECT\00447263.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.128:C:\RECYCLER\NPROTECT\00447267.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.128:C:\RECYCLER\NPROTECT\00447269.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.128:C:\RECYCLER\NPROTECT\00447509.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.128:C:\RECYCLER\NPROTECT\00447511.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.128:C:\RECYCLER\NPROTECT\00447516.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.129:C:\RECYCLER\NPROTECT\00447267.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.129:C:\RECYCLER\NPROTECT\00447269.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.129:C:\RECYCLER\NPROTECT\00447509.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.129:C:\RECYCLER\NPROTECT\00447511.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.129:C:\RECYCLER\NPROTECT\00447516.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.130:C:\RECYCLER\NPROTECT\00447263.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.130:C:\RECYCLER\NPROTECT\00447267.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.130:C:\RECYCLER\NPROTECT\00447269.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.130:C:\RECYCLER\NPROTECT\00447273.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.130:C:\RECYCLER\NPROTECT\00447275.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.130:C:\RECYCLER\NPROTECT\00447277.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.130:C:\RECYCLER\NPROTECT\00447280.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.130:C:\RECYCLER\NPROTECT\00447282.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.130:C:\RECYCLER\NPROTECT\00447336.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.131:C:\RECYCLER\NPROTECT\00447263.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.131:C:\RECYCLER\NPROTECT\00447273.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.131:C:\RECYCLER\NPROTECT\00447275.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.131:C:\RECYCLER\NPROTECT\00447277.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.131:C:\RECYCLER\NPROTECT\00447280.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.131:C:\RECYCLER\NPROTECT\00447282.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.131:C:\RECYCLER\NPROTECT\00447336.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.131:C:\RECYCLER\NPROTECT\00447511.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.131:C:\RECYCLER\NPROTECT\00447516.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.132:C:\RECYCLER\NPROTECT\00447267.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.132:C:\RECYCLER\NPROTECT\00447269.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.132:C:\RECYCLER\NPROTECT\00447273.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.132:C:\RECYCLER\NPROTECT\00447275.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.132:C:\RECYCLER\NPROTECT\00447277.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.132:C:\RECYCLER\NPROTECT\00447280.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.132:C:\RECYCLER\NPROTECT\00447282.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.132:C:\RECYCLER\NPROTECT\00447336.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.132:C:\RECYCLER\NPROTECT\00447511.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.132:C:\RECYCLER\NPROTECT\00447516.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.133:C:\RECYCLER\NPROTECT\00447267.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.133:C:\RECYCLER\NPROTECT\00447269.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.133:C:\RECYCLER\NPROTECT\00447338.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.133:C:\RECYCLER\NPROTECT\00447340.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.133:C:\RECYCLER\NPROTECT\00447343.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.133:C:\RECYCLER\NPROTECT\00447361.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.134:C:\RECYCLER\NPROTECT\00447273.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.134:C:\RECYCLER\NPROTECT\00447275.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.134:C:\RECYCLER\NPROTECT\00447277.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.134:C:\RECYCLER\NPROTECT\00447280.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.134:C:\RECYCLER\NPROTECT\00447282.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.134:C:\RECYCLER\NPROTECT\00447336.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.134:C:\RECYCLER\NPROTECT\00447338.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.134:C:\RECYCLER\NPROTECT\00447340.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.134:C:\RECYCLER\NPROTECT\00447343.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.134:C:\RECYCLER\NPROTECT\00447361.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.135:C:\RECYCLER\NPROTECT\00447273.MOZ -> TrackingCookie.Specificclick : Cleaned.
:mozilla.135:C:\RECYCLER\NPROTECT\00447275.MOZ ->

#10 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 17 March 2007 - 02:37 PM

The only ones that would concern me, would be items that couldn't be cleaned or were just quarantined.

What's showing are just cookies that we'll clean.


As for Abmdrvk, lets do this:

Click "Start"> "Run"> type in Regedit tap Enter Key

Make sure "My Computer" is highlighted

Click "Edit"> "Find"
Type in Abmdrvk tap Enter Key.
Right Click on the file if found and select "Delete"

Tap the "F3" Key to find the next entry of the file. Continue using the "F3" Key until it's finished searching.

Close Regedit.


Empty Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.
Also please describe how your computer behaves at the moment.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#11 TCUser2

TCUser2

    New Member

  • New Member
  • Pip
  • 6 posts

Posted 17 March 2007 - 02:54 PM

The abmdrvk was a file folder - 2 instances....here's new log and FF is still sloooooooooow: I hope I assumed you meant the recycle bin I have (it is called protected by Norton???)

Logfile of HijackThis v1.99.1
Scan saved at 4:46:17 PM, on 3/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Documents and Settings\Owner\Desktop\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\ClocX\ClocX.exe
C:\Documents and Settings\Owner\Desktop\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Utilities\Hijackthis\HijackThis.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\svchost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/explore.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\DESKTOP\utilities\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [ClocX] C:\Program Files\ClocX\ClocX.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\Owner\Desktop\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Support - {6137A22B-7653-4383-B7BA-8056BA10D091} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: Help - {80F91D55-DCA1-4B6C-9E0B-FDE073EFF698} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {FE5EB236-AEA5-4C9D-A3C7-C634BFEEB60D} - http://www.comcast.net (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.s...rl/LSSupCtl.cab
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.micr...ActiveX/odc.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://leannemaries....ad/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safe...lscbase8460.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1122147819031
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symant...ex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1123718319156
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.s...rl/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://liveca12.cust...l/java/RntX.cab
O16 - DPF: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} (ActiveCGM Control) - https://www.dot7.sta...t/ACGM/acgm.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Documents and Settings\Owner\Desktop\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Thanks

#12 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 17 March 2007 - 03:05 PM

If I remember right, you can Right Click on the Recycle Bin and empty the RECYCLER\NPROTECT.

I only have one other thing to try and if it's still slow, we'll uninstall IE7 and go back to IE6.

lets see if this will help speed it up.

Backup Your Registry with ERUNT
  • Please use the following link and scroll down to ERUNT and download it.
    http://aumha.org/freeware/freeware.php
  • For version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe



I recommend you download RegSeeker. Extract it to it's own folder, open and double click RegSeeker.exe to start the program. Maximize the window and click clean registry. Check all sections and click OK. When the scan is complete, verify the backup box in lower left corner is checked and click the select all button, then select all again. Then right click within the search results and select delete. Run it again and again, deleting everything it finds until it finds nothing. Reboot and make sure your programs are working properly, control panel and add/remove programs windows open, etc (basically just do a quick check of everything). In the event anything was 'broken', you can open RegSeeker, click backups and double click any/all files to put the information back. A reboot may be required for the effects to be seen. Reboot When done.

NOTE: To be extra safe you can choose to only remove the items in RED.
Some items may come back because of the programs you have running.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#13 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 24 March 2007 - 06:50 AM

How are you doing with the fix?

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#14 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 26 March 2007 - 05:42 PM

Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoy...showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users