Jump to content

So I am trying to remove Norton's AntiVirus


Recommended Posts

Hello all,

I have downloaded the program that is supposed to uninstall Norton anti-virus from my machine. I'm looking to you all for help in learning whether or not it is entirely gone; also judging by the amount of stuff the system scanners you all recommend found, I'm interested in learning what I can do to rid my system of any and all malware and optimize performance.

Here is the MBAM log:

Malwarebytes' Anti-Malware 1.24

Database version: 1015

Windows 5.1.2600 Service Pack 2

8:11:17 PM 8/1/2008

mbam-log-8-1-2008 (20-11-13).txt

Scan type: Quick Scan

Objects scanned: 46696

Time elapsed: 5 minute(s), 38 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 5

Registry Values Infected: 1

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> No action taken.

HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> No action taken.

HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> No action taken.

HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> No action taken.

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> No action taken.

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> No action taken.

------------------------------------------------------------------------------------------------------------------------------------------------------

Here is the Panda log:

;*******************************************************************************

********************************************************************************

*

*******************

ANALYSIS: 2008-08-01 21:25:39

PROTECTIONS: 0

MALWARE: 37

SUSPECTS: 1

;*******************************************************************************

********************************************************************************

*

*******************

PROTECTIONS

Description Version Active Updated

;===============================================================================

================================================================================

=

===================

;===============================================================================

================================================================================

=

===================

MALWARE

Id Description Type Active Severity Disinfectable Disinfected Location

;===============================================================================

================================================================================

=

===================

00139059 Cookie/Traffic Marketplace TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.trafficmp.com/]

00139059 Cookie/Traffic Marketplace TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.trafficmp.com/]

00139059 Cookie/Traffic Marketplace TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.trafficmp.com/]

00139059 Cookie/Traffic Marketplace TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.trafficmp.com/]

00139059 Cookie/Traffic Marketplace TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.trafficmp.com/]

00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.casalemedia.com/]

00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.casalemedia.com/]

00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.casalemedia.com/]

00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.casalemedia.com/]

00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Cookies\hp_owner@casalemedia[1].txt

00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.casalemedia.com/]

00139060 Cookie/Casalemedia TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.casalemedia.com/]

00139060 Cookie/Casalemedia TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.casalemedia.com/]

00139060 Cookie/Casalemedia TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.casalemedia.com/]

00139060 Cookie/Casalemedia TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.casalemedia.com/]

00139060 Cookie/Casalemedia TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.casalemedia.com/]

00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.casalemedia.com/]

00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.casalemedia.com/]

00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.casalemedia.com/]

00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.casalemedia.com/]

00139060 Cookie/Casalemedia TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.casalemedia.com/]

00139060 Cookie/Casalemedia TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.casalemedia.com/]

00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.casalemedia.com/]

00139061 Cookie/Doubleclick TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.doubleclick.net/]

00139061 Cookie/Doubleclick TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.doubleclick.net/]

00139061 Cookie/Doubleclick TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.doubleclick.net/]

00139061 Cookie/Doubleclick TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.doubleclick.net/]

00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Cookies\hp_owner@doubleclick[1].txt

00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.doubleclick.net/]

00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.doubleclick.net/]

00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.doubleclick.net/]

00139061 Cookie/Doubleclick TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.doubleclick.net/]

00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.atdmt.com/]

00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.atdmt.com/]

00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Cookies\hp_owner@atdmt[2].txt

00139064 Cookie/Atlas DMT TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.atdmt.com/]

00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.atdmt.com/]

00139064 Cookie/Atlas DMT TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.atdmt.com/]

00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.247realmedia.com/]

00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.247realmedia.com/]

00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.247realmedia.com/]

00145405 Cookie/RealMedia TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.247realmedia.com/]

00145405 Cookie/RealMedia TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.247realmedia.com/]

00145405 Cookie/RealMedia TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.247realmedia.com/]

00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.fastclick.net/]

00145457 Cookie/FastClick TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.fastclick.net/]

00145457 Cookie/FastClick TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.fastclick.net/]

00145457 Cookie/FastClick TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.fastclick.net/]

00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.fastclick.net/]

00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.fastclick.net/]

00145457 Cookie/FastClick TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.fastclick.net/]

00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.fastclick.net/]

00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.fastclick.net/]

00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.fastclick.net/]

00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.fastclick.net/]

00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.fastclick.net/]

00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.fastclick.net/]

00145457 Cookie/FastClick TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.fastclick.net/]

00145457 Cookie/FastClick TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.fastclick.net/]

00145457 Cookie/FastClick TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.fastclick.net/]

00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Cookies\hp_owner@fastclick[1].txt

00145457 Cookie/FastClick TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.fastclick.net/]

00145731 Cookie/Tribalfusion TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.tribalfusion.com/]

00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.tribalfusion.com/]

00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.tribalfusion.com/]

00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.tribalfusion.com/]

00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Cookies\hp_owner@tribalfusion[2].txt

00145731 Cookie/Tribalfusion TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.tribalfusion.com/]

00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.tribalfusion.com/]

00145731 Cookie/Tribalfusion TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.tribalfusion.com/]

00145731 Cookie/Tribalfusion TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.tribalfusion.com/]

00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.mediaplex.com/]

00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.mediaplex.com/]

00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.mediaplex.com/]

00145738 Cookie/Mediaplex TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.mediaplex.com/]

00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Cookies\hp_owner@mediaplex[1].txt

00145738 Cookie/Mediaplex TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.mediaplex.com/]

00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.mediaplex.com/]

00145738 Cookie/Mediaplex TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.mediaplex.com/]

00145738 Cookie/Mediaplex TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.mediaplex.com/]

00145881 Cookie/NewMedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.anm.co.uk/]

00167747 Cookie/Azjmp TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Cookies\hp_owner@azjmp[2].txt

00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.statcounter.com/]

00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.statcounter.com/]

00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.statcounter.com/]

00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.statcounter.com/]

00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.statcounter.com/]

00167753 Cookie/Statcounter TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.statcounter.com/]

00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.statcounter.com/]

00168048 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Cookies\hp_owner@perf.overture[1].txt

00168048 Cookie/Overture TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.perf.overture.com/]

00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[ad.yieldmanager.com/]

00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[ad.yieldmanager.com/]

00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[ad.yieldmanager.com/]

00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[ad.yieldmanager.com/]

00168056 Cookie/YieldManager TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][ad.yieldmanager.com/]

00168056 Cookie/YieldManager TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][ad.yieldmanager.com/]

00168056 Cookie/YieldManager TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][ad.yieldmanager.com/]

00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[ad.yieldmanager.com/]

00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ad.yieldmanager[1].txt

00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[ad.yieldmanager.com/]

00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.apmebf.com/]

00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.apmebf.com/]

00168076 Cookie/BurstNet TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.burstnet.com/]

00168076 Cookie/BurstNet TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.burstnet.com/]

00168076 Cookie/BurstNet TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Cookies\hp_owner@burstnet[1].txt

00168076 Cookie/BurstNet TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.burstnet.com/]

00168076 Cookie/BurstNet TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.burstnet.com/]

00168076 Cookie/BurstNet TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.burstnet.com/]

00168076 Cookie/BurstNet TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.burstnet.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.serving-sys.com/]

00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.serving-sys.com/]

00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.bs.serving-sys.com/]

00168093 Cookie/Serving-sys TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.bs.serving-sys.com/]

00168093 Cookie/Serving-sys TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.bs.serving-sys.com/]

00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.bs.serving-sys.com/]

00168097 Cookie/BurstBeacon TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[www.burstbeacon.com/]

00168109 Cookie/Adtech TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.adtech.de/]

00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][server.iad.liveperson.net/hc/1433104]

00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][server.iad.liveperson.net/]

00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Cookies\hp_owner@server.iad.liveperson[1].txt

00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[server.iad.liveperson.net/hc/73335289]

00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[server.iad.liveperson.net/]

00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][server.iad.liveperson.net/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Cookies\hp_owner@advertising[1].txt

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.advertising.com/]

00169287 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Cookies\hp_owner@adrevolver[1].txt

00170304 Cookie/WebtrendsLive TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][statse.webtrendslive.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.ads.pointroll.com/]

00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ads.pointroll[1].txt

00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.overture.com/]

00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.overture.com/]

00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.overture.com/]

00170554 Cookie/Overture TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.overture.com/]

00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.overture.com/]

00170554 Cookie/Overture TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.overture.com/]

00170556 Cookie/RealMedia TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.realmedia.com/]

00170556 Cookie/RealMedia TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.realmedia.com/]

00170556 Cookie/RealMedia TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.realmedia.com/]

00170556 Cookie/RealMedia TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.realmedia.com/]

00170556 Cookie/RealMedia TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.realmedia.com/]

00170556 Cookie/RealMedia TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.realmedia.com/]

00170556 Cookie/RealMedia TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.realmedia.com/]

00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.realmedia.com/]

00170556 Cookie/RealMedia TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.realmedia.com/]

00171982 Cookie/QuestionMarket TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.questionmarket.com/]

00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.questionmarket.com/]

00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.questionmarket.com/]

00171982 Cookie/QuestionMarket TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.questionmarket.com/]

00172221 Cookie/Zedo TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.zedo.com/]

00172221 Cookie/Zedo TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.zedo.com/]

00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.zedo.com/]

00172221 Cookie/Zedo TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.zedo.com/]

00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.zedo.com/]

00172221 Cookie/Zedo TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.zedo.com/]

00172221 Cookie/Zedo TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.zedo.com/]

00172221 Cookie/Zedo TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.zedo.com/]

00172221 Cookie/Zedo TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.zedo.com/]

00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.zedo.com/]

00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.zedo.com/]

00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.zedo.com/]

00172221 Cookie/Zedo TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.zedo.com/]

00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Cookies\hp_owner@zedo[1].txt

00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.zedo.com/]

00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.zedo.com/]

00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.zedo.com/]

00172221 Cookie/Zedo TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.zedo.com/]

00173520 Cookie/Bluestreak TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.bluestreak.com/]

00173520 Cookie/Bluestreak TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Cookies\hp_owner@bluestreak[2].txt

00173520 Cookie/Bluestreak TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.bluestreak.com/]

00182104 Cookie/Hitbox TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.phg.hitbox.com/]

00182104 Cookie/Hitbox TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.phg.hitbox.com/]

00182104 Cookie/Hitbox TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.phg.hitbox.com/]

00184846 Cookie/Adrevolver TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.adrevolver.com/]

00184846 Cookie/Adrevolver TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.adrevolver.com/]

00184846 Cookie/Adrevolver TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.adrevolver.com/]

00184846 Cookie/Adrevolver TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.adrevolver.com/]

00184846 Cookie/Adrevolver TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.adrevolver.com/]

00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.adrevolver.com/]

00184846 Cookie/Adrevolver TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.adrevolver.com/]

00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.adrevolver.com/]

00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.adrevolver.com/]

00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.adrevolver.com/]

00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.adrevolver.com/]

00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.adrevolver.com/]

00184846 Cookie/Adrevolver TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.adrevolver.com/]

00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.adrevolver.com/]

00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Cookies\hp_owner@adrevolver[2].txt

00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.go.com/]

00194327 Cookie/Go TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.go.com/]

00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Netscape\NSB\Profiles\hcdblz4i.default\cookies.txt[.go.com/]

00194327 Cookie/Go TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\4860_51c1a567d_[cookies.txt][.go.com/]

00207338 Cookie/Target TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.target.com/]

00207338 Cookie/Target TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.target.com/]

00207338 Cookie/Target TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.target.com/]

00207338 Cookie/Target TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.target.com/]

00207862 Cookie/did-it TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.did-it.com/]

00207862 Cookie/did-it TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.did-it.com/]

00207862 Cookie/did-it TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.did-it.com/]

00262020 Cookie/Atwola TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.atwola.com/]

00262020 Cookie/Atwola TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][.atwola.com/]

00262020 Cookie/Atwola TrackingCookie No 0 Yes No C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\yj48pzds.default\cookies.txt[.atwola.com/]

00325830 Cookie/Bridgetrack TrackingCookie No 0 No No C:\Documents and Settings\HP_Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\HP_Owner\state\backup\co\cookies.txt\106000_577c57b40_[cookies.txt][citi.bridgetrack.com/]

00377802 Spyware/PeoplePC Spyware No 0 Yes No C:\Program Files\Online Services\PeoplePC\ISP5900\Dll\RAS.DLL

;===============================================================================

================================================================================

=

===================

SUSPECTS

Sent Location

;===============================================================================

================================================================================

=

===================

No C:\Program Files\Online Services\PeoplePC\ISP5900\Branding\ppal3ppc.exe

;===============================================================================

================================================================================

=

===================

VULNERABILITIES

Id Severity Description

;===============================================================================

================================================================================

=

===================

;===============================================================================

================================================================================

=

===================

---------------------------------------------------------------------------------------------------------------------------------------

Finally here is the HijackThis! log:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 10:47:50 PM, on 8/1/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Common Files\LightScribe\LSSrvc.exe

C:\Program Files\Common Files\Motive\McciCMService.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Program Files\HP\HP Software Update\HPwuSchd2.exe

C:\HP\KBD\KBD.EXE

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\QuickTime\QTTask.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\AT&T\Internet Security Wizard\ISW.exe

C:\Program Files\FastAccessDSL\HelpCenter43\bin\sprtcmd.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Picasa2\PicasaMediaDetector.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\WINDOWS\ALCMTR.EXE

C:\WINDOWS\ALCWZRD.EXE

c:\windows\system\hpsysdrv.exe

C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe

C:\Program Files\Java\jre1.5.0_05\bin\jucheck.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\WINDOWS\system32\WISPTIS.EXE

C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: AT&&T Toolbar - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\PROGRA~1\ATTTOO~1\ATTTOO~1.DLL

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll

O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\webhelper.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll

O3 - Toolbar: AT&&T Toolbar - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\PROGRA~1\ATTTOO~1\ATTTOO~1.DLL

O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe

O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe

O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE

O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run

O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe

O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [iSW.exe] "C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" /AUTORUN

O4 - HKLM\..\Run: [HelpCenter4.1] C:\Program Files\FastAccessDSL\HelpCenter43\bin\sprtcmd.exe /P HelpCenter4.1

O4 - HKLM\..\RunOnce: [spybotDeletingA5862] command /c del "C:\WINDOWS\wt\webdriver.dll"

O4 - HKLM\..\RunOnce: [spybotDeletingC5315] cmd /c del "C:\WINDOWS\wt\webdriver.dll"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe

O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\HP_Owner\Application Data\mjusbsp\cdloader2.exe" MAGICJACK

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\RunOnce: [spybotDeletingB5469] command /c del "C:\WINDOWS\wt\webdriver.dll"

O4 - HKCU\..\RunOnce: [spybotDeletingD1241] cmd /c del "C:\WINDOWS\wt\webdriver.dll"

O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm

O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe

O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe

--

End of file - 8920 bytes

Thanks for all your help and hard work!!!

Link to post
Share on other sites

Your Java application is out of date and causes a slight security risk as a result.

Please follow these steps to remove older version Java components

1. Close any open programs you may have running, especially your web

browser.

2. Click Start-->Control Panel-->Add or Remove Programs.

3. Click once on any item listing Java Runtime Environment in the name (to highlight it) then click the "Remove" or "Change/Remove" button.

Not every version of Java will begin with "Java" so be sure to read each entry in the list.

Repeat step 3 as many times as necessary to remove all versions of Java.

**If you are asked to reboot at any point during the uninstallations, please do so. Then go back to Add/Remove and continue with the rest of the removals...when finished uninstalling all of them, reboot the computer.

4. Navigate to and delete:

  • C:\Program Files\Java <=this folder if found

5. Then go to this page.

Scroll down to where it says "The Java Runtime Environment (JRE) allows end-users to run Java applications" and click the "Download" button to the right. Select the platform for "Windows".

6. Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement", then click Continue...The page will refresh

Then, click on the link to download Windows Offline Installation. Save it to your desktop.

Now, from your desktop, double-click on the executable to install the newest version.

Your log shows a remnant of Symantec still running. This would be due to having the Spybot Search and Destroy 'Tea Timer' function enabled. To completely remove Symantec, please disable Tea timer before we make any other attempt:

1) Run Spybot-S&D

2) Go to the Mode menu, and make sure "Advanced Mode" is selected

3) On the left hand side, choose Tools -> Resident

4) Uncheck "Resident TeaTimer" and OK any prompts

5) Restart your computer.

...remember to re-enable it once we're convinced the system is clear.

Your Panda log shows lots of troublesome cookies and one adware menace.

Let's remove the adware problem by uninstalling WeatherBug...the adware.minibug is part of this program and should disappear with the uninstallation of WeatherBug. If you used the program for weather alerts just let us know and we can recommend an alternative "ad free" software for either the desktop or just a link to the web site where you can customize settings for your preferences.

Click start-->Control Panel-->Add/Remove Programs...scroll down the list to locate the program name WeatherBug and click Remove.

Next, return to the control panel and click-->Internet Options-->Advanced Tab...scroll down to the Security section. Check the box "Empty Temporary Internet Files folder when browser is closed". Click "Apply", "OK" and close the Control Panel. Reboot the system to properly record the changes made to the hard disk.

With this configuration you will eliminate troublesome cookies upon closing the browser and reduce disk clutter. This will help speed up security scanning software as well...but you will need to sign in again at any web sites where you use an I.D. and password.

Now, while Tea Timer has been disabled, run the Symantec Removal tool again. Do nothing else with the system while the tool is running. When it completes, reboot the system again.

When the system comes back up please do this:

Click start-->Run...in the run box, type Notepad.exe and click "OK"...a blank notepad will open.

Copy the data in the code box below into the blank notepad and save it to your Desktop as deletereg.reg...Set File type to "all files"

REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Alcmtr"=-

Double-click that file and confirm you want to merge it with the registry.

Reboot the computer once more to properly record the changes made.

Run HijackThis and post back a fresh HijackThis log. Please advise how the system performs and what you intend to do about having no on board protection against the unintended download and installation of other malware. If you need some recommendations for free security software let us know and we will provide some links. Thanks!

Link to post
Share on other sites

Thanks for the help!

Here is the fresh HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 9:10:39 AM, on 8/2/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Common Files\LightScribe\LSSrvc.exe

C:\Program Files\Common Files\Motive\McciCMService.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe

C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Picasa2\PicasaMediaDetector.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\HijackThis\HijackThis.exe

C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: AT&&T Toolbar - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\PROGRA~1\ATTTOO~1\ATTTOO~1.DLL

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll

O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\webhelper.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll

O3 - Toolbar: AT&&T Toolbar - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\PROGRA~1\ATTTOO~1\ATTTOO~1.DLL

O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe

O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\HP_Owner\Application Data\mjusbsp\cdloader2.exe" MAGICJACK

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm

O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe

O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe

--

End of file - 7646 bytes

For virus protection, I have downloaded Avira's AntiVir program (the one with the red umbrella). It comes highly recommended, but if you have a better idea, I'm all ears. Thanks a lot for your help!!!!

Link to post
Share on other sites

Avira is excellent...you're in good shape now. I see the Symantec entry is still there. No surprise. Otherwise, the log looks fine.

The entry:

O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe

...is the Symantec entry we still need to remove. Uninstall Spybot Search and Destroy first, then try the removal tool again. I know this particular file to be stubborn as it creates user Mode Rootkit functionality. While Spybot is uninstalled, boot into safe mode and try running the tool there. You may have an issue with it in safe mode but we should try that first. Sometimes, removing Symantec is worse than the malware itself!

Post back your results. Thanks!

Link to post
Share on other sites

Hmmm, well I find it hard to believe that the Symantec programmers would overlook the need to stop services before trying to delete them but I can bet stranger things have happened. Before we try to hack the registry, let's try this now:

Click Start-->Run...type SERVICES.MSC & then click on the OK button

1. Locate the service - Symantec RemoteAssist - Symantec, Inc

2. Double-click on it to open the Properties dialog.

- Stop the service by using the Stop button.

- Change the Startup type to Disabled & then click on the OK button

3. Then start HiJackThis & go to Config...-->Misc.Tools-->Delete an NT service

4. In the popup box that appears, copy/paste Symantec RemoteAssist - Symantec, Inc

5. Click on the OK button & answer YES if prompted to reboot

Post back your results and let us know, if it's still there are you comfortable with working in the Registry? Thanks!

Link to post
Share on other sites

That worked.

Here's the fresh HijackThis log (anything else you see in it?):

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 11:34:40 AM, on 8/2/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Common Files\LightScribe\LSSrvc.exe

C:\Program Files\Common Files\Motive\McciCMService.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Picasa2\PicasaMediaDetector.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe

C:\HP\KBD\KBD.EXE

C:\WINDOWS\ALCMTR.EXE

C:\WINDOWS\ALCWZRD.EXE

C:\WINDOWS\system32\wuauclt.exe

c:\windows\system\hpsysdrv.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: AT&&T Toolbar - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\PROGRA~1\ATTTOO~1\ATTTOO~1.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll

O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\webhelper.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll

O3 - Toolbar: AT&&T Toolbar - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\PROGRA~1\ATTTOO~1\ATTTOO~1.DLL

O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe

O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\HP_Owner\Application Data\mjusbsp\cdloader2.exe" MAGICJACK

O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm

O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe

--

End of file - 7084 bytes

Thanks for all the help. I'm going out to run some errands; won't be back until later this evening but I will check back here as soon as I can.

Have a great day!

Link to post
Share on other sites

You're looking good now. Before we send you on though, this file is still running:

C:\WINDOWS\ALCMTR.EXE

...and I should bring to your attention that it is part of your Realtek AC97 Audio Event Monitor.

The file is considered "Spyware" since it is used surreptitiously to monitor one's actions on the web. It's not doing anything malicious as some do like remote controled programs etc., but it is being used by Realtek to gather data about customers and then sends the information to their server.

If you delete this file, then you won't be able to properly update your drivers in the future. It IS recommended that you disable the startup.

I have not seen this item running in your startup listing but the process is running nonetheless which is why I constructed the deletereg.reg file to remove the registry entry that points to that file. Once the file is merged into the registry that "run" command on startup is gone. That only removes the registry entry and not the file itself so you should still be able to update just fine...you just won't be subject to any spying on the web.

While Spybot has been removed, run that .reg file again, reboot and post back another fresh HijackThis log. Thanks!

Link to post
Share on other sites

After uninstalling Spybot again, I added

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Alcmtr"=-

to the registry as deletereg.reg. Unfortunately the ALCMTR.exe is still there. I checked msconfig and its not listed in the startup, so I don't know how to disable it from the startup or how to get rid of it. Any suggestions?

heres the fresh HijackThis:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 5:03:10 PM, on 8/2/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Common Files\LightScribe\LSSrvc.exe

C:\Program Files\Common Files\Motive\McciCMService.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Picasa2\PicasaMediaDetector.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe

C:\HP\KBD\KBD.EXE

C:\WINDOWS\ALCMTR.EXE

C:\WINDOWS\ALCWZRD.EXE

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\HijackThis\HijackThis.exe

c:\windows\system\hpsysdrv.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\iPod\bin\iPodService.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: AT&&T Toolbar - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\PROGRA~1\ATTTOO~1\ATTTOO~1.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll

O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\webhelper.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll

O3 - Toolbar: AT&&T Toolbar - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\PROGRA~1\ATTTOO~1\ATTTOO~1.DLL

O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe

O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\HP_Owner\Application Data\mjusbsp\cdloader2.exe" MAGICJACK

O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm

O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe

--

End of file - 7162 bytes

Link to post
Share on other sites

It's odd that the process is running without the startup entry in the hjt log. I've not seen that before and haven't been able to find any other example of it from a google search.

Are you having any sound issues?

Let's upload that file for a free scan at VirusTotal. Navigate to the file indicated below in Bold and upload the file for a free scan:

C:\Windows\ALCMTR.EXE

If you're unsure how to do that, follow the instructions below:

  1. Click in the "Upload a file" box to put the cursor there then click the Browse button next to it.
  2. In the File Upload window that opens, click the drop down arrow in the "Look in" box and select your Local Disk.
  3. Click the "Windows" folder and click "Open", use the scroll bar to scroll across and locate the file ALCMTR.EXE and click open.
  4. Now click the Send button. Please copy the "Results" to submit with your next reply.
Link to post
Share on other sites

I haven't noticed any sound issues. These are the results, but it said that the file had already been analyzed. Thanks!

File Alcmtr.exe received on 08.03.2008 18:57:58 (CET)

Current status: finished

Result: 0/36 (0.00%)

Compact Compact

Print results Print results

Antivirus Version Last Update Result

AhnLab-V3 2008.7.29.1 2008.08.02 -

AntiVir 7.8.1.15 2008.08.01 -

Authentium 5.1.0.4 2008.08.03 -

Avast 4.8.1195.0 2008.08.03 -

AVG 8.0.0.156 2008.08.02 -

BitDefender 7.2 2008.08.03 -

CAT-QuickHeal 9.50 2008.08.02 -

ClamAV 0.93.1 2008.08.03 -

DrWeb 4.44.0.09170 2008.08.03 -

eSafe 7.0.17.0 2008.08.03 -

eTrust-Vet 31.6.6002 2008.08.02 -

Ewido 4.0 2008.08.03 -

F-Prot 4.4.4.56 2008.08.03 -

F-Secure 7.60.13501.0 2008.08.03 -

Fortinet 3.14.0.0 2008.08.03 -

GData 2.0.7306.1023 2008.08.03 -

Ikarus T3.1.1.34.0 2008.08.03 -

K7AntiVirus 7.10.402 2008.08.02 -

Kaspersky 7.0.0.125 2008.08.03 -

McAfee 5352 2008.08.01 -

Microsoft 1.3807 2008.08.03 -

NOD32v2 3322 2008.08.03 -

Norman 5.80.02 2008.08.01 -

Panda 9.0.0.4 2008.08.03 -

PCTools 4.4.2.0 2008.08.03 -

Prevx1 V2 2008.08.03 -

Rising 20.55.62.00 2008.08.03 -

Sophos 4.31.0 2008.08.03 -

Sunbelt 3.1.1537.1 2008.08.01 -

Symantec 10 2008.08.03 -

TheHacker 6.2.96.392 2008.08.02 -

TrendMicro 8.700.0.1004 2008.08.01 -

VBA32 3.12.8.2 2008.08.02 -

ViRobot 2008.8.1.1321 2008.08.01 -

VirusBuster 4.5.11.0 2008.08.02 -

Webwasher-Gateway 6.6.2 2008.08.03 -

Additional information

File size: 69632 bytes

MD5...: 8b4cbba1ea526830c7f97e7822e2493a

SHA1..: e519f493e42694c564aaa347745bab035bbcb3d9

SHA256: 1dfd05b1c0050db44f5b4293e5574bfc292af804a63fc0a70131bb498c326977

SHA512: d1264f010d21aed0db2cc5749327866605ed701db42541cfe712ba2cedba7836

0cb2322b76d7101ddf18b7f9311c185d3c08589a4b66d00ea57977664299c6e6

PEiD..: Armadillo v1.71

PEInfo: PE Structure information

( base data )

entrypointaddress.: 0x403be0

timedatestamp.....: 0x427755ce (Tue May 03 10:43:26 2005)

machinetype.......: 0x14c (I386)

( 4 sections )

name viradd virsiz rawdsiz ntrpy md5

.text 0x1000 0x610e 0x7000 5.95 8847136ed928b3d6bf22476d6cfa16dc

.rdata 0x8000 0x11be 0x2000 3.62 44d6d751816684771102662d858f1eb7

.data 0xa000 0x325c 0x3000 1.32 db9e3f59949d45ef77c97f790cfa285b

.rsrc 0xe000 0x3c60 0x4000 2.71 f7d9818085605d7244ef821b6becc72e

( 7 imports )

> DSOUND.dll: -

> SETUPAPI.dll: SetupDiGetDeviceRegistryPropertyA, SetupDiGetClassDevsA, SetupDiEnumDeviceInfo, SetupDiGetDeviceInstanceIdA, SetupDiDestroyDeviceInfoList, SetupDiEnumDeviceInterfaces, SetupDiGetDeviceInterfaceDetailA

> KERNEL32.dll: CreateEventA, GetStringTypeA, LCMapStringW, LCMapStringA, MultiByteToWideChar, LoadLibraryA, GetProcAddress, HeapReAlloc, VirtualAlloc, HeapAlloc, GetOEMCP, GetACP, GetCPInfo, WriteFile, RtlUnwind, HeapFree, VirtualFree, HeapCreate, HeapDestroy, GetVersionExA, GetEnvironmentVariableA, GetFileType, GetStdHandle, SetHandleCount, GetEnvironmentStringsW, GetEnvironmentStrings, WideCharToMultiByte, FreeEnvironmentStringsW, FreeEnvironmentStringsA, GetModuleFileNameA, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, ExitProcess, GetVersion, GetCommandLineA, GetStartupInfoA, CreateFileA, DeviceIoControl, LocalAlloc, LocalFree, WaitForMultipleObjects, SetEvent, WaitForSingleObject, WinExec, lstrcmpA, Sleep, CreateMutexA, GetLastError, CloseHandle, GetStringTypeW, CreateThread, lstrcpyA, GetModuleHandleA

> USER32.dll: DispatchMessageA, TranslateMessage, GetMessageA, ShowWindow, LoadStringA, FindWindowA, CharUpperA, BeginPaint, FillRect, EndPaint, SetTimer, GetSysColor, SystemParametersInfoA, GetDC, GetMenuCheckMarkDimensions, ReleaseDC, CreatePopupMenu, InsertMenuItemA, SendMessageA, GetCursorPos, TrackPopupMenu, DestroyMenu, KillTimer, PostQuitMessage, SetForegroundWindow, DefWindowProcA, RegisterWindowMessageA, GetDesktopWindow, GetWindow, GetClassNameA, PostMessageA, LoadIconA, LoadCursorA, RegisterClassA, CreateWindowExA, SetWindowRgn, LoadImageA

> GDI32.dll: FrameRgn, CreateCompatibleDC, BitBlt, DeleteDC, CreatePen, MoveToEx, LineTo, CreateBrushIndirect, Rectangle, GetTextColor, SetTextColor, GetBkMode, SetBkMode, GetTextAlign, SetTextAlign, ExtTextOutA, CreateFontIndirectA, SelectObject, GetTextExtentPoint32A, DeleteObject, CreateRoundRectRgn, CreatePolygonRgn, CombineRgn

> ADVAPI32.dll: RegOpenKeyExA, RegQueryValueExA, RegCreateKeyExA, RegSetValueExA, RegCloseKey

> SHELL32.dll: Shell_NotifyIconA

( 0 exports )

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Link to post
Share on other sites

OK great. Yes, the scanner will point out if a file has been scanned before. Most often that will be the case...the reason that notice is rendered is for your benefit should you find a suspect file that is also found by all of the scanners to be virus free but also has never been scanned before. In that case you would know to quarantine the file since it's impossible to have a file on YOUR system that is the only file out of more than 300 million users. That would most definitely be a file who's characters have been randomly generated by some malicious program.

How's the system running? Are you having any other issues?

Link to post
Share on other sites

  • 3 weeks later...

Since this topic has had no reply for over 5 days it will be closed to prevent other from posting into it. Should you decide to resume with your assistance PM any staff member and we will be happy to reopen the topic.

Note: the fixes in this topic are for this system only. Applying them to your system can cause severe damage and result in utter system failure. If you need help start your own topic and someone will be happy to assist you.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.