InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 1601. |
Solve : Backdoor.Win32.Bifrose.cwlo? |
|
Answer» I RECENTLY replaced Avast with Kaspersky Internet Security 2011 and after LEAVING the PC for a while Kaspersky flagged that it had found Backdoor.Win32.Bifrose.cwlo Detected (1) When I press to disinfect nothing appears to happen and the entry STILL remains in the Active threats page yet it appears to have been deleted as it shows on the neutralised page too. Quote Deleted (2) The files above do not appear to exist when I navigate to the folders. I'm running Windows 7 Professional 64bitHJT Log: Code: [Select]Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 17:47:18, on 06/11/2010 Platform: Windows 7 (WinNT 6.00.3504) MSIE: Internet Explorer v9.00 (9.00.7930.16406) Boot mode: Normal Running processes: C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe C:\Program Files\Lenovo\Zoom\TpScrex.exe C:\Program Files (x86)\Scrybe\scrybe.exe C:\Windows\SysWOW64\rundll32.exe C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe C:\Program Files (x86)\Lenovo\Client Security Solution\password_manager.exe C:\Users\Cameron\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Cameron\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Cameron\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Cameron\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Cameron\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Cameron\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Cameron\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Cameron\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Cameron\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Cameron\Desktop\Bob.exe C:\Windows\SysWOW64\DllHost.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo.MSN.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL O2 - BHO: Password Manager Browser Helper Object - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll O3 - Toolbar: C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll O4 - HKLM\..\Run: [DockingDetection] C:\PROGRA~2\Lenovo\LENOVO~1\DOCKIN~1.EXE O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor O4 - HKLM\..\Run: [Message Center Plus] C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe /start O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" O4 - HKCU\..\Run: [Google Update] "C:\Users\Cameron\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %PROGRAMFILES%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - Global Startup: Bluetooth.lnk = ? O4 - Global Startup: Scrybe.lnk = ? O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000 O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105 O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm O9 - Extra button: C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll O9 - Extra button: (no name) - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll O9 - Extra 'Tools' menuitem: Lenovo Password Manager... - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O20 - AppInit_DLLs: ,C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE O23 - Service: AcPrfMgrSvc - Lenovo - C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe O23 - Service: AcSvc - Lenovo - C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe O23 - Service: %SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe O23 - Service: %SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: %systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing) O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe O23 - Service: keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: %SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE O23 - Service: %systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: %systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: %SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Scrybe Updater (ScrybeUpdater) - Synaptics, Inc. - C:\Program Files (x86)\Scrybe\Service\ScrybeUpdater.exe O23 - Service: %SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: %systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: %SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\Program Files (x86)\Lenovo\System Update\SUService.exe O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing) O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe O23 - Service: TurboBoost - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe O23 - Service: %SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: %SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: %SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: %systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: wampapache - Apache Software Foundation - C:\Program Files (x86)\wamp\bin\apache\apache2.2.11\bin\httpd.exe O23 - Service: wampmysqld - Unknown owner - C:\Program Files (x86)\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe O23 - Service: %SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: %systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: %Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: %PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: Zune Wireless Configuration Service (ZuneWlanCfgSvc) - Unknown owner - C:\Windows\system32\ZuneWlanCfgSvc.exe (file missing) -- End of file - 14721 bytes MBAM Log: Code: [Select]Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 5062 Windows 6.1.7600 Internet Explorer 9.0.7930.16406 06/11/2010 19:40:54 mbam-log-2010-11-06 (19-40-54).txt Scan type: Quick scan Objects scanned: 171379 Time elapsed: 20 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Also since this appears to be within one of the Google Chrome Cache files, is it likely that my PC is infected or is it a case that chrome has cached it but it is in no way a danger.SAS Log [code]SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 11/06/2010 at 09:25 PM Application Version : 4.45.1000 Core Rules Database Version : 5758 Trace Rules Database Version: 3570 Scan type : Complete Scan Total Scan Time : 02:05:20 Memory items scanned : 725 Memory threats detected : 0 Registry items scanned : 17229 Registry threats detected : 0 File items scanned : 49102 File threats detected : 756 Adware.Tracking Cookie C:\Users\Cameron\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Cameron\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Cameron\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Cameron\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Cameron\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Cameron\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Cameron\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Cameron\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Cameron\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .atdmt.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .mediaplex.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .kontera.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .ad.uk.doubleclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adbrite.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .atdmt.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tacoda.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] eas.apm.emediate.eu [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .collective-media.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .microsoftsto.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .invitemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .uk.at.atwola.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .imrworldwide.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .imrworldwide.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] uk.sitestat.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] uk.sitestat.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .advertising.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .ru4.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .ru4.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tradedoubler.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .liveperson.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .burstnet.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .weborama.fr [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .dmtracker.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] server.lon.liveperson.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] in.getclicky.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .xiti.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adxpose.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .interclick.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .interclick.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .smartadserver.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .smartadserver.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adbrite.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adbrite.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .at.atwola.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tribalfusion.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tribalfusion.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adbrite.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .eas.apm.emediate.eu [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .ads.pointroll.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .pointroll.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .pointroll.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .ads.pointroll.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .ads.pointroll.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .ads.pointroll.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .ads.pointroll.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .ads.pointroll.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .ads.pointroll.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] eas.apm.emediate.eu [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .atdmt.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .atdmt.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .msnportal.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adinterax.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .microsoftoffice.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] advancedsearch.virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] advancedsearch.virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ads.audience2media.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .cisco.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .kantarmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .paypal.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .w3counter.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .mediacollege.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adserver.adtechus.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .invitemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ext-us.bestofmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] my.stats2.com.re.getclicky.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .247realmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .canoe.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .www.discountelectronicsstore.co.uk [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .discountelectronicsstore.co.uk [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .discountelectronicsstore.co.uk [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] counter.hitslink.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .spylog.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .apmebf.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .videoegg.adbureau.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .vdwp.solution.weborama.fr [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .vdwp.solution.weborama.fr [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .vdwp.solution.weborama.fr [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .vdwp.solution.weborama.fr [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .nextag.co.uk [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .nextag.co.uk [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.googleadservices.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] server.lon.liveperson.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .fastclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .fastclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.googleadservices.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tribalfusion.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tribalfusion.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tribalfusion.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .antistat.co.uk [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .antistat.co.uk [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .mediaplex.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .content.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .cneteurope.122.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .collective-media.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .122.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.linuxquestions.org [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .casalemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .casalemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .legolas-media.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .legolas-media.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .uk.at.atwola.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .uk.at.atwola.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .uk.at.atwola.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .kontera.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.linuxquestions.org [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.linuxquestions.org [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .www.linuxquestions.org [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .www.linuxquestions.org [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .www.linuxquestions.org [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .ad-emea.doubleclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] server.lon.liveperson.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] webstats.plus.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .interclick.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .clickteam.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .clickteam.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tradedoubler.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tradedoubler.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .sfcglobalgateway.122.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .cubestat.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .cubestat.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .viacom.adbureau.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .viacom.adbureau.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .viacom.adbureau.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .viacom.adbureau.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .viacom.adbureau.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.googleadservices.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] counter.sc [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] dc.tremormedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .trackalyzer.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .stats.paypal.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adfarm1.adition.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ad3.adfarm1.adition.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ww251.smartadserver.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] user.lucidmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revenue.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .247realmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tracker.xilo.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tracker.xilo.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .advertising.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .yieldmanager.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .casalemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .casalemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .casalemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .casalemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] s3.trafficmaxx.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .audience2media.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .e-2dj6wnkispdziho.stats.esomniture.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .e-2dj6wjmyghdjchp.stats.esomniture.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .atdmt.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .atdmt.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] *Blocked Russian URL* [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .www.burstnet.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .shop.virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .shop.virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .virginmediapeople.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .virginmediapeople.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tracking.foxnews.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tracking.foxnews.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adinterax.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .virilion.122.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .collective-media.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .pro-market.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .commission-junction.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .commission-junction.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.mediacollege.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.mediacollege.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .mediacollege.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .technoratimedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .technoratimedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .technoratimedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .e-2dj6wnmigmc5cdo.stats.esomniture.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .invitemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .e-2dj6wfk4sgdzkhq.stats.esomniture.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .e-2dj6aekyohdzico.stats.esomniture.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] stats.cihar.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .w3counter.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .192com.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .f2network.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .associatedcontent.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .kantarmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .bs.serving-sys.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adviva.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] eas.apm.emediate.eu [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .ehg-techtarget.hitbox.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .e-2dj6wjkoenazskp.stats.esomniture.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .gostats.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .doubleclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .e-2dj6waliolajgkp.stats.esomniture.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .medicaldevicelink.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtechus.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] adserver1.backbeatmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .eyewonder.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tradedoubler.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.burstbeacon.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .burstbeacon.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .technoratimedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .technoratimedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .chitika.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.burstnet.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .harrenmedianetwork.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] stats.blogcatalog.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .mediaconverter.org [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .mediaconverter.org [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.mediaconverter.org [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .ehg-techtarget.hitbox.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .hitbox.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .hitbox.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .ehg-techtarget.hitbox.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .audience2media.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ads.audience2media.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .collective-media.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .sonyeurope.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .fastclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] rotator.adjuggler.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] rotator.adjuggler.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] rotator.adjuggler.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .fastclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .e-2dj6wfloggc5ifq.stats.esomniture.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adbrite.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adbrite.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adbrite.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adecn.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .apmebf.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .burstnetads.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .burstnet.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .burstnetads.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .e-2dj6wjk4gidpgho.stats.esomniture.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .liveperson.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .liveperson.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] advancedsearch.virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] www.qsstats.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .invitemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .smartadserver.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .smartadserver.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .advertising.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .at.atwola.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .at.atwola.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tacoda.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tradedoubler.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tradedoubler.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] t4.trackalyzer.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adviva.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .specificclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .specificclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .specificclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .specificclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .specificclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .specificclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .specificclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .specificclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .specificclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .clicksor.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .clicksor.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .myroitracking.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .clicksor.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .clicksor.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .clicksor.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .clicksor.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .advertising.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .advertising.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .advertising.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .advertising.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .content.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .mediaplex.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .media6degrees.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .media6degrees.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .media6degrees.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .media6degrees.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .media6degrees.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .media6degrees.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .media6degrees.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .media6degrees.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .invitemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .invitemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .invitemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .invitemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .smartadserver.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .fastclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .fastclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .clickfuse.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tribalfusion.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .legolas-media.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .kontera.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .kontera.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .questionmarket.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .questionmarket.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tacoda.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tacoda.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tacoda.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tacoda.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .tacoda.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .statcounter.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .invitemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .kaspersky.122.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] statse.webtrendslive.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] server.iad.liveperson.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .liveperson.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .bs.serving-sys.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .serving-sys.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .serving-sys.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .serving-sys.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .serving-sys.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .serving-sys.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .serving-sys.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .serving-sys.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ] statse.webtrendslive.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .doubleclick.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .invitemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .invitemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .invitemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .invitemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .invitemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .invitemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .invitemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .tribalfusion.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .apmebf.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .mediaplex.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .kontera.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .collective-media.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .collective-media.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .collective-media.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .collective-media.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .media6degrees.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .media6degrees.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .media6degrees.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .atdmt.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .atdmt.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .statcounter.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .media6degrees.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .microsoftsto.112.2o7.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .adxpose.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .chitika.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .adbrite.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .adbrite.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .adbrite.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .fastclick.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .fastclick.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .advertising.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .adviva.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .adviva.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .tacoda.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .tacoda.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .tacoda.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .tacoda.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .tacoda.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .tacoda.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .advertising.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .at.atwola.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .at.atwola.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .zedo.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .zedo.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .zedo.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .zedo.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .zedo.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .advertising.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .advertising.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .advertising.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .advertising.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .content.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .mediaplex.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] in.getclicky.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] tracking.dc-storm.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] tracking.dc-storm.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .roiservice.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] *Blocked Russian URL* [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] *Blocked Russian URL* [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .adbrite.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .adbrite.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .www.burstnet.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .bs.serving-sys.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .serving-sys.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .serving-sys.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .serving-sys.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .serving-sys.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .serving-sys.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .serving-sys.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .serving-sys.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .burstnet.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] www.burstnet.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .burstnet.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] stats1.clicktracks.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] stats1.clicktracks.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] stats1.clicktracks.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] stats1.clicktracks.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .revsci.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .revsci.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .hitbox.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .texasinstrument.122.2o7.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .hitbox.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .ehg-ti.hitbox.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .smartadserver.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .smartadserver.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .smartadserver.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .smartadserver.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .smartadserver.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .content.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .xiti.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .content.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .adbrite.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .kontera.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .kontera.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .kontera.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] www.googleadservices.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .at.atwola.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .tacoda.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .tacoda.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .atwola.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .questionmarket.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .specificclick.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .specificclick.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .interclick.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .media6degrees.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .media6degrees.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .media6degrees.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .trafficmp.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .trafficmp.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .trafficmp.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .interclick.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .interclick.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .tacoda.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .dmtracker.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .adtech.de [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .revsci.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ads.neudesicmediagroup.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ads.neudesicmediagroup.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ads.neudesicmediagroup.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .atdmt.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .atdmt.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .fastclick.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .fastclick.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .fastclick.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .tradedoubler.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .tradedoubler.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .tradedoubler.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .tradedoubler.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .revsci.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .imrworldwide.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .imrworldwide.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .adserver.adtechus.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .cmp.112.2o7.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .casalemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .casalemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .casalemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .casalemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .casalemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .casalemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .casalemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .casalemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .content.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .casalemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .i7media.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .i7media.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .i7media.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .i7media.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] www.googleadservices.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .liveperson.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] server.iad.liveperson.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .liveperson.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .mustardseedmedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .mustardseedmedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .mustardseedmedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] mustardseedmedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .adbrite.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .adbrite.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .mustardseedmedia.disqus.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .mustardseedmedia.disqus.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .mustardseedmedia.disqus.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ads.neudesicmediagroup.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ads.neudesicmediagroup.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] ads.neudesicmediagroup.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] secure.arixmedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .mustardseedmedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .revsci.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .advertising.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .yieldmanager.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] www.qsstats.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] www.qsstats.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .liveperson.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ] .zedo.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\ProfilIt seems to have been a false positive. - Marking as solved |
|
| 1602. |
Solve : Virus? Pop up guard/Security Analysis? |
|
Answer» Ok. Let's do some cleanup. |
|
| 1603. |
Solve : sound goes out, yadaying running, Downloader.Tiny.BB, Help!!!? |
|
Answer» 18424 09:15:45 (0) ** WMIDiag v2.0 started on Tuesday, September 14, 2010 at 09:11.
FASTPROX.DLL WBEMPROX.DLL
Log created at 19:47 on 04/10/2010 by Brett Administrator - Elevation successful ========== filefind ========== Searching for "FASTPROX.DLL" C:\Documents and Settings\Deborah\Desktop\i386\fastprox.dll --a---- 472064 bytes [02:08 22/04/2005] [10:00 04/08/2004] C28500101BC66FDABD830F8DE51A59A0 C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\fastprox.dll --a---- 473600 bytes [03:14 17/04/2009] [10:56 09/02/2009] 600519339671DCFA3DD20216A19817BB C:\WINDOWS\$NtServicePackUninstall$\fastprox.dll -----c- 472064 bytes [23:00 05/10/2008] [10:00 04/08/2004] C28500101BC66FDABD830F8DE51A59A0 C:\WINDOWS\$NtUninstallKB956572$\fastprox.dll -----c- 472064 bytes [04:58 17/04/2009] [00:11 14/04/2008] 60027BEA3E76D7DD8D96C02432BFDE82 C:\WINDOWS\ServicePackFiles\i386\fastprox.dll ------- 472064 bytes [16:47 04/09/2008] [00:11 14/04/2008] 60027BEA3E76D7DD8D96C02432BFDE82 C:\WINDOWS\system32\dllcache\fastprox.dll ------- 473600 bytes [03:14 17/04/2009] [12:10 09/02/2009] 378A0AEFB11D8B0DC8C27B9F7604B88D C:\WINDOWS\system32\wbem\fastprox.dll --a---- 473600 bytes [18:01 10/08/2004] [12:10 09/02/2009] 378A0AEFB11D8B0DC8C27B9F7604B88D Searching for "WBEMPROX.DLL" C:\Documents and Settings\Deborah\Desktop\i386\wbemprox.dll --a---- 18944 bytes [02:08 22/04/2005] [10:00 04/08/2004] 851547797C2A7F8A04841644C471A567 C:\WINDOWS\$NtServicePackUninstall$\wbemprox.dll -----c- 18944 bytes [23:00 05/10/2008] [10:00 04/08/2004] 851547797C2A7F8A04841644C471A567 C:\WINDOWS\ServicePackFiles\i386\wbemprox.dll ------- 18944 bytes [16:49 04/09/2008] [00:12 14/04/2008] 205ADD80FF8099B1A8101EB490B933D1 C:\WINDOWS\system32\wbem\wbemprox.dll --a---- 18944 bytes [18:01 10/08/2004] [00:12 14/04/2008] 205ADD80FF8099B1A8101EB490B933D1 -= EOF =- Quote from: DragonMaster Jay on July 07, 2010, 07:27:43 PM Please visit this webpage for a tutorial on downloading and running ComboFix: Thanks for sharing the link!Before we can continue, I need to know how your computer is running, Mr Hopeless.It's making these ticking noises, they usually start after I turn on the modem. The sound works okay. Internet speed seems to be okay, no internet popups, etc. I'm getting those windows about the WMI change noted above.What I highly recommend now is a reformat and a reinstallation of Windows XP. Please let me know if you are prepared to do so. So, with that said, do you have your Windows XP CD? Guides for format and reinstall: http://www.geekpolice.net/tutorials-guides-f13/how-to-reformat-and-reinstall-your-operating-system-t15119.htm#95115 http://www.helpmyos.com/tutorials-software-alternatives-to-proprietary-f19/how-to-reformat-and-reinstall-your-operating-system-the-easy-way-t1307.htm#3143I have reinstalled Windows. Thanks for the effort. This thread can be closed. |
|
| 1604. |
Solve : question about "learning" - evilfantasy? |
|
Answer» HELLO evilfantasy, in an earlier post by LINUX, Re.........., another poster also asked why they couldn't offer HELP. your response was (in blue) that "there are different levels of learning." the subject being, virus, malware, trojans, etc. removal. where does one find the subject to LEARN it ? sites, books, school ? i've been to your site and there is SO much you offer people and you do not ask for payment (that i saw). BHAW !!! i have a he!l of alot of respect for you and thank you for all the help you've given me and others. You can CHECK out this site for more information. |
|
| 1605. |
Solve : C:\windows\system32\sshnas21.dll? |
|
Answer» Quote from: PuB_Evo on October 29, 2010, 07:11:31 PM I went into MSCONFIG to try and disable UAC, however when I went tools>UAC SETTINGS>launch, it said access denied. I tried doing it through Control Panel>user accounts but it wouldn't save the settings, once I clicked OK, nothing would happen, and if I left it, then went back to it, the setting would then get reverted. My friend said my Administrative privledges are probably corrupt or something similar. The above is still the same and i do not have admin rights yet, i am assuming the edited registry isn't helping. I also cannot get Adobe to D/L like before even adding it to the exceptions list on Firefox. Internet EXPLORER was able to play videos fine.Did you try updating Adobe through Internet Explorer? Here is the error popping twice when i try to update Adobe Flash Player 10.1 via Internet Explorer. Everything that happen was just very wrong and weird. LOOKS like its a nasty one. Just realized that all adobe softwares are affected and asking for licensing. These include the Adobe reader + my Adobe design premium CS4 package. Online PDF files still works fine in Internet Explorer though, just not for Firefox and the software itself.If this is paid for version of Adobe, perhaps you should consult them about this problem. Please let me know what you find.Nothing helps at all, i reformatted. Can you suggestion some(Win7 64bits OS) good free browsing softwares that protects and a decent free firewall? Im currently using only Avast Anti-virus.I prefer MicroSoft Security ESSENTIALS. No registration req'd, high efficiency and not a resource hog. Before we continue download and install a free antivirus. Remember to only install one antivirus! 1) Avast! Home Edition 2) AVG Free Edition 3) Avira AntiVir Personal 4) Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download 4-a) Microsoft Security Essentials for Windows XP 5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one) 6) PC Tools AntiVirus Free Edition It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time. ***************************************** Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to USE only one firewall at the same time. ************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|
| 1606. |
Solve : poor start up. and slow? |
|
Answer» Ok. Please re-enable your emulations drivers as per instructions in Reply # 27.
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your NEXT reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET ONLINE Scanner\log.txt dave ran the file .said there was no infections .but i didn't get a log file sorry. can run again and try to get one ..things seem better then they were . thanksSometimes when there are no infections, a report doesn't show up. Are you having any other problems with your computer?everything else seems good except when i close my broswer the screen closes real slow from top to bottom. instead of just closing out. if you know what i mean.. anyway thanks dave seems like you cleared up a lot of things. Quote when i close my broswer the screen closes real slow from top to bottom. instead of just closing out. if you know what i mean..That sounds like a software or hardware problem than a malware-induced problem. You could try starting a new thread on one of the software or hardware forums to get some help for that. Let's do some clean-up. To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
******************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. *************************************** To turn off Windows XP System Restore: NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK. 1. Click Start. 2. Right-click the My Computer icon, and then click Properties. 3. Click the System Restore tab. 4. Check "Turn off System Restore" or "Turn off System Restore on all drives" 5. Click Apply. 6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this. 7. Click OK. 8. Restart the computer and follow the instructions in the next section to turn on System Restore. To turn on Windows XP System Restore: 1. Click Start. 2. Right-click My Computer, and then click Properties. 3. Click the System Restore tab. 4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives." 5. Click Apply, and then click OK. This should give you a new, clean Restore Point. ***************************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone HOME" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. *************************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything LISTED. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|
| 1607. |
Solve : notebook broken!!AHHHHH!!? |
|
Answer» Hi! Finally back! I called asus tech & asked about recovery console & he took me to the bios to disable BOOT booster, then hit f9 but after about 5 tries & just kept loading windows, he said my partition was gone & needed recovery disc,(which they want 30.for!) can`t believe I didnt get one when I bought it! grrrr! So whaddya think now? Thnx!!It would appear that they have you over a barrel but it would be $30 well-spent. |
|
| 1608. |
Solve : will you run this one for me, too ?? |
|
Answer» Logfile of Trend Micro HijackThis v2.0.4 |
|
| 1609. |
Solve : Please help! Can't access my email and keep crashing because of a virus?? |
|
Answer» Quote It found 3 viruses and it cleaned it. Is it really gone from my computer and could there possibly be more?I would say your computer is clean. If there are no other issues, it's time for some cleanup.BTW, the picture of your kitten looks exactly like ours when she was young. * Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box. * Now type commy.exe /uninstall in the runbox * Make sure there's a space between commy.exe and /Uninstall * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and FOLDERS. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. **************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all PROGRAMS when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ********************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and MALICIOUS intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. *************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to ENABLE thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. ALSO stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!Hi SuperDave. I did all the cleaning up and updating. Thank you SO much for helping me and others!! You guys are awesome! And yeah I was looking for a picture and found the kitten picture! I absolutely love cats; I have a black cat at home. Thank you again |
|
| 1610. |
Solve : Running Duplicate Programs? |
|
Answer» Should I disable Windows Essentials AntiVirus and Firewall if I run a 3rd party software? I have Windows XP. I added SuperAntiVirius, ONLINE Armour and Malwarebytes awhle back after I got attacked with MALWARE. This FORUM got me SQUARED away on what to do. Recently I had some issues with OLA so I uninstalled it. I just CHECKED my Windows Security Center and it has firewall and antivirus enabled. |
|
| 1611. |
Solve : SCAN LOGS............? |
|
Answer» I have come on this forum to submit scan logs, have been on XP forum, (Polecat.) Have done Steps A and B. 1, 2, (not the REGISTRY), 3,4 and 5*. Am now trying to download HijackThis.msi, but it will not download for me. Therefore I am sending logs of Step3 and STEP4 now. Will keep trying to download HijackThis and will send log if I succeed. |
|
| 1612. |
Solve : svchost.exe and windows update? |
| Answer» | |
| 1613. |
Solve : Virus question? |
|
Answer» How long does it take a virus to corrupt a computer?No such thing. Depends on the virus and what it does. Some can cause major DAMAGE immediately, some trojans will cause problems down the road. Is there a purpose behind the question?Is there a way to protect websites on shared servers when virus protection is not given by the hosting company? I seem to be continuously hit by them. Thank you.Lawyer, should start your own topic. But to answer your question quickly it depends on the type of webserver you're using. It's more than likely that the server is getting compromised then getting INFECTED from an outside source. I'd make sure to CHANGE all your passwords and if it happens again send an e-mail to your webserver indicating that there is a security breach on the server and that it should be fixed. |
|
| 1614. |
Solve : computer infected : NEED HELPP !!!? |
|
Answer» You can obviously ignore the above post.This is the log from ESETscan ... do you think it would help to update my browserAny program that is out-of-date is susceptible to infections. Let's do some cleanup. * Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box. * Now type commy /uninstall in the runbox * Make SURE there's a space between commy and /Uninstall * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ******************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ************************************* Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. **************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the SCAN to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations ALWAYS update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Edited. |
|
| 1615. |
Solve : Think Point Virus? |
|
Answer» I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can TAKE some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Hi! Dave, After a few attempts, i finally succeeded to download the ESET. I unchecked the box "remove found threats", because i was not sure you wanted it that way. You didn't mention if i needded to keep it on not. Here is the results of the scan: C:\Program Files\YouTube Downloader Toolbar\SearchSettings.dll Win32/Adware.Toolbar.Dealio application C:\Program Files\YouTube Downloader Toolbar\SearchSettings.exe Win32/Adware.Toolbar.Dealio application C:\Program Files\YouTube Downloader Toolbar\WidgiHelper.exe Win32/Adware.Toolbar.Dealio application C:\Program Files\YouTube Downloader Toolbar\IE\1.0\youtubedownloaderToolbarIE.dll Win32/Adware.Toolbar.Dealio application C:\Windows\Installer\6bcc6a.msi Win32/Adware.Toolbar.Dealio application Operating memory Win32/Adware.Toolbar.Dealio application Waiting your intructions eagerly. Regards, YvesPlease run it again and check "remove found threats".Hi! Dave, Here is the results: C:\Program Files\YouTube Downloader Toolbar\SearchSettings.dll Win32/Adware.Toolbar.Dealio application cleaned by deleting (after the next restart) - quarantined C:\Program Files\YouTube Downloader Toolbar\SearchSettings.exe Win32/Adware.Toolbar.Dealio application cleaned by deleting - quarantined C:\Program Files\YouTube Downloader Toolbar\WidgiHelper.exe Win32/Adware.Toolbar.Dealio application cleaned by deleting - quarantined C:\Program Files\YouTube Downloader Toolbar\IE\1.0\youtubedownloaderToolbarIE.dll Win32/Adware.Toolbar.Dealio application cleaned by deleting - quarantined C:\Users\Yves\AppData\Local\Temp\NOD349B.tmp Win32/Adware.Toolbar.Dealio application cleaned by deleting (after the next restart) - quarantined C:\Windows\Installer\6bcc6a.msi Win32/Adware.Toolbar.Dealio application deleted - quarantined Regards, YvesHow's your computer running now?. Any issues?Hi! Dave, My PC seem to be O.K, but how can i make sure there is nothing left from that" Think Point" on it? There is still some names of files on the "Windows Task Manager", how can i get rid of them? See additional. atiedxx.exe, csrss.exe, winlogon.exe Regards, Yveshere is the additional [recovering disk space - old attachment deleted by admin] Quote atiedxx.exeThis is a file for your video card. Quote csrss.exeThe Microsoft Client Server Runtime Server subsystem utilizes the process csrss.exe for managing the majority of the graphical instruction sets under the Microsoft Windows operating system. Quote winlogon.exewinlogon.exe is a process belonging to the Windows login manager. It handles the login and logout procedures on your system. This program is important for the stable and secure running of your computer and should not be terminated. You can google all those files to find out what are their functions . Let's see if you can run ComboFix again as OUTLINED in Reply #9 Hi! Dave, O.K , i run the ComboFix and here is the results: ComboFix 10-11-09.01 - Yves 10/11/2010 5:47.1.2 - x86 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.61.1033.18.3070.2010 [GMT 10:00] Running from: c:\users\Yves\Desktop\commy.exe Command switches used :: /stepdel . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\arp.exe G:\Autorun.inf c:\windows\system32\userinit.exe . . . is infected!! . ((((((((((((((((((((((((( Files Created from 2010-10-09 to 2010-11-09 ))))))))))))))))))))))))))))))) . 2010-11-09 20:47 . 2010-11-09 20:47 -------- d-----w- c:\users\Default\AppData\Local\temp 2010-11-09 08:06 . 2010-10-07 23:21 6146896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{44CDFD57-B753-47D5-9915-893F16DBC98A}\mpengine.dll 2010-11-09 04:26 . 2010-11-09 04:26 -------- d-----w- c:\program files\Vodafone 2010-11-03 04:36 . 2010-11-03 04:36 -------- d-----w- c:\program files\Common Files\Java 2010-11-03 04:35 . 2010-11-03 04:35 -------- d-----w- c:\program files\Sun 2010-11-03 04:32 . 2010-11-03 04:34 -------- d-----w- c:\program files\Java 2010-11-03 02:59 . 2010-11-03 02:59 -------- d-----w- c:\users\Yves\AppData\Roaming\Malwarebytes 2010-11-03 02:59 . 2010-11-08 23:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-11-03 02:59 . 2010-11-03 02:59 -------- d-----w- c:\programdata\Malwarebytes 2010-11-02 23:16 . 2010-11-02 23:16 -------- d-----w- c:\programdata\SUPERAntiSpyware.com 2010-10-26 20:45 . 2010-08-04 06:18 641536 ----a-w- c:\windows\system32\CPFilters.dll 2010-10-26 20:45 . 2010-08-04 06:17 417792 ----a-w- c:\windows\system32\msdri.dll 2010-10-26 20:45 . 2010-08-04 06:15 204288 ----a-w- c:\windows\system32\MSNP.ax 2010-10-26 20:45 . 2010-08-04 06:15 199680 ----a-w- c:\windows\system32\mpg2splt.ax 2010-10-26 20:39 . 2010-07-13 05:22 26504 ----a-w- c:\windows\system32\drivers\Diskdump.sys 2010-10-23 11:36 . 2010-10-23 11:36 -------- d-----w- c:\programdata\5D 2010-10-23 10:25 . 2010-10-23 11:28 -------- d-----w- c:\users\Yves\AppData\Local\BearShare 2010-10-23 10:18 . 2010-10-23 20:49 -------- dc-h--w- c:\programdata\~0 2010-10-23 10:18 . 2010-10-23 10:18 -------- d-----w- c:\users\Yves\AppData\Local\PackageAware 2010-10-20 14:18 . 2010-10-20 14:18 -------- d-----w- c:\windows\en 2010-10-20 14:18 . 2010-10-20 14:18 -------- dc----w- c:\windows\system32\DRVSTORE 2010-10-20 14:18 . 2010-09-22 14:21 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys 2010-10-20 14:13 . 2010-10-20 14:13 -------- d-----w- c:\program files\MSN Toolbar 2010-10-20 14:13 . 2010-10-20 14:14 -------- d-----w- c:\program files\Bing Bar Installer 2010-10-20 14:13 . 2009-09-04 07:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll 2010-10-20 14:13 . 2009-09-04 07:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll 2010-10-20 14:13 . 2009-09-04 07:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll 2010-10-20 14:12 . 2010-10-20 14:12 469256 ----a-w- c:\program files\Common Files\Windows Live\.cache\c76b1f1e1cb70602b\InstallManager_WLE_WLE.exe 2010-10-20 14:11 . 2010-10-20 14:11 15712 ----a-w- c:\program files\Common Files\Windows Live\.cache\b5d373971cb706020\MeshBetaRemover.exe 2010-10-20 14:11 . 2010-10-20 14:11 94040 ----a-w- c:\program files\Common Files\Windows Live\.cache\a5a337da1cb706018\DSETUP.dll 2010-10-20 14:11 . 2010-10-20 14:11 525656 ----a-w- c:\program files\Common Files\Windows Live\.cache\a5a337da1cb706018\DXSETUP.exe 2010-10-20 14:11 . 2010-10-20 14:11 1691480 ----a-w- c:\program files\Common Files\Windows Live\.cache\a5a337da1cb706018\dsetup32.dll 2010-10-20 14:11 . 2010-10-20 14:11 525656 ----a-w- c:\program files\Common Files\Windows Live\.cache\a40e8dec1cb706017\DXSETUP.exe 2010-10-20 14:11 . 2010-10-20 14:11 1691480 ----a-w- c:\program files\Common Files\Windows Live\.cache\a40e8dec1cb706017\dsetup32.dll 2010-10-20 14:11 . 2010-10-20 14:11 94040 ----a-w- c:\program files\Common Files\Windows Live\.cache\a40e8dec1cb706017\DSETUP.dll 2010-10-20 14:09 . 2010-11-06 03:26 -------- d-----w- c:\users\Yves\AppData\Local\Windows Live 2010-10-20 14:09 . 2010-05-23 10:15 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL 2010-10-20 14:09 . 2010-05-23 10:11 196608 ----a-w- c:\windows\system32\mfreadwrite.dll 2010-10-20 14:09 . 2010-05-23 10:11 3181568 ----a-w- c:\windows\system32\mf.dll 2010-10-15 21:34 . 2010-05-05 06:46 363520 ----a-w- c:\windows\system32\StructuredQuery.dll 2010-10-15 21:03 . 2010-08-21 05:36 738816 ----a-w- c:\windows\system32\wmpmde.dll 2010-10-15 21:01 . 2010-09-01 04:26 164864 ----a-w- c:\program files\Windows Media Player\wmplayer.exe 2010-10-15 21:01 . 2010-09-01 04:23 12625408 ----a-w- c:\windows\system32\wmploc.DLL 2010-10-15 21:01 . 2010-09-01 02:34 2327552 ----a-w- c:\windows\system32\win32k.sys 2010-10-15 21:01 . 2010-08-27 05:46 168448 ----a-w- c:\windows\system32\srvsvc.dll 2010-10-15 21:01 . 2010-08-27 03:31 310784 ----a-w- c:\windows\system32\drivers\srv.sys 2010-10-15 21:01 . 2010-08-27 03:30 308736 ----a-w- c:\windows\system32\drivers\srv2.sys 2010-10-15 21:01 . 2010-08-27 03:30 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-11-03 04:35 . 2010-07-27 22:47 472808 ----a-w- c:\windows\system32\deployJava1.dll 2010-10-19 01:41 . 2010-07-26 23:48 222080 ------w- c:\windows\system32\MpSigStub.exe 2010-09-22 14:47 . 2010-09-22 14:47 49016 ----a-w- c:\windows\system32\sirenacm.dll 2010-09-22 14:32 . 2010-09-22 14:32 301936 ----a-w- c:\windows\WLXPGSS.SCR 2010-09-21 04:03 . 2010-09-21 04:03 208768 ----a-w- c:\windows\system32\LIVESSP.DLL 2010-08-25 20:48 . 2010-08-25 20:48 53248 ----a-r- c:\users\Yves\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe 2010-08-21 05:32 . 2010-09-15 06:16 316928 ----a-w- c:\windows\system32\spoolsv.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2010-09-29 2942856] "AnyTime Organizer"="c:\program files\AnyTime Organizer Premier\AtDem.exe" [2007-11-21 29696] "E09AXLRD_2727443"="c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE" [2008-06-03 351000] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-07-20 1038848] "MobileBroadband"="c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" [2010-06-25 253952] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux2"=wdmaud.drv [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup backupExtension=.CommonStartup [HKLM\~\startupfolder\C:^Users^Yves^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^AnyTime.lnk] path=c:\users\Yves\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AnyTime.lnk backup=c:\windows\pss\AnyTime.lnk.Startup backupExtension=.Startup [HKLM\~\startupfolder\C:^Users^Yves^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^FastStone Capture.lnk] path=c:\users\Yves\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FastStone Capture.lnk backup=c:\windows\pss\FastStone Capture.lnk.Startup backupExtension=.Startup [HKLM\~\startupfolder\C:^Users^Yves^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Product Registration.lnk] path=c:\users\Yves\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Product Registration.lnk backup=c:\windows\pss\Logitech . Product Registration.lnk.Startup backupExtension=.Startup [HKLM\~\startupfolder\C:^Users^Yves^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk] path=c:\users\Yves\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk backup=c:\windows\pss\OpenOffice.org 3.2.lnk.Startup backupExtension=.Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service] 2010-03-27 06:07 362232 ----a-w- c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\adm_tray.exe] 2010-06-04 08:49 530768 ----a-w- c:\program files\Acronis\DriveMonitor\adm_tray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2010-09-20 13:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2010-09-22 18:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0] 2010-03-05 17:44 500208 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager] 2010-07-22 12:10 402432 ----a-w- c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyTime Organizer] 2007-11-21 03:45 29696 ----a-w- c:\progra~1\ANYTIM~1\AtDem.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DU Meter] 2010-09-29 05:30 2942856 ----a-w- c:\program files\DU Meter\DUMeter.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_15580131] 2008-06-03 10:05 351000 ----a-w- c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_2163780] 2008-06-03 10:05 351000 ----a-w- c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_2494237] 2008-06-03 10:05 351000 ----a-w- c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_2519946] 2008-06-03 10:05 351000 ----a-w- c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_25437101] 2008-06-03 10:05 351000 ----a-w- c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_31464294] 2008-06-03 10:05 351000 ----a-w- c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_5542044] 2008-06-03 10:05 351000 ----a-w- c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_5633040] 2008-06-03 10:05 351000 ----a-w- c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_582850] 2008-06-03 10:05 351000 ----a-w- c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_6173833] 2008-06-03 10:05 351000 ----a-w- c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_6696436] 2008-06-03 10:05 351000 ----a-w- c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_738477] 2008-06-03 10:05 351000 ----a-w- c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_8550430] 2008-06-03 10:05 351000 ----a-w- c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_9218411] 2008-06-03 10:05 351000 ----a-w- c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_969171] 2008-06-03 10:05 351000 ----a-w- c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2009-11-18 06:13 54576 ----a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail] 2010-10-22 20:47 353736 ----a-w- c:\program files\IncrediMail\Bin\IncMail.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint] 2010-07-21 06:52 1797008 ----a-w- c:\program files\Microsoft IntelliPoint\ipoint.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\itype] 2010-07-21 07:07 1778064 ----a-w- c:\program files\Microsoft IntelliType Pro\itype.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Vid] 2010-05-11 06:43 6061400 ----a-w- c:\program files\Logitech\Vid\Vid.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Vid HD] 2010-05-11 06:43 6061400 ----a-w- c:\program files\Logitech\Vid\Vid.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWS] 2010-05-07 08:35 165208 ----a-w- c:\program files\Logitech\LWS\Webcam Software\LWS.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)] 2010-06-01 00:17 5252408 ----a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileBroadband] 2010-06-25 02:57 253952 ----a-w- c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RESTART_STICKY_NOTES] 2009-07-14 01:14 354304 ----a-w- c:\windows\System32\StikyNot.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2010-05-14 01:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard] 2010-02-19 03:37 517096 ----a-w- c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe] 2010-03-27 06:06 5107232 ----a-w- c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WorldTime2006] 2007-10-21 07:17 1486848 ----a-w- c:\program files\AnyTime Organizer Premier\WorldTime.exe R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 DUMeterDrv;Hagel Technologies DU Meter traffic accounting driver;c:\program files\DU Meter\DUMETR32.SYS [2010-09-29 18576] R3 icsak;icsak;c:\program files\CheckPoint\ZAForceField\AK\icsak.sys [2010-06-15 35568] R3 massfilter;MBB Mass Storage Filter Driver;c:\windows\system32\DRIVERS\massfilter.sys [2010-06-10 9216] R3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776] R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-27 1343400] R3 zgwhsdiag;ZTE WCDMA Handset Diagnostic Port;c:\windows\system32\DRIVERS\zgwhsdiag.sys [2009-10-28 105216] R3 zgwhsmdm;ZTE WCDMA Handset USB Modem;c:\windows\system32\DRIVERS\zgwhsmdm.sys [2009-10-28 105216] R3 zgwhsnmea;WCDMA Handset NMEA Port;c:\windows\system32\DRIVERS\zgwhsnmea.sys [2009-10-28 105216] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040] S0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\DRIVERS\tdrpm258.sys [2010-07-27 911680] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [2010-07-27 2480048] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-08-03 176128] S2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-02-19 380928] S2 DUMeterSvc;DU Meter Service;c:\program files\DU Meter\DUMeterSvc.exe [2010-09-29 1412488] S2 ISWKL;ZoneAlarm ForceField ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [2010-06-15 26352] S2 IswSvc;ZoneAlarm ForceField IswSvc;c:\program files\CheckPoint\ZAForceField\IswSvc.exe [2010-06-15 493032] S2 VmbService;Vodafone Mobile Broadband Service;c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2010-06-25 9216] S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [2010-07-27 160704] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-08-03 6096384] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-08-03 214016] S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2010-07-07 44432] S3 vodafone_K3805-z_dc_enum;vodafone_K3805-z_dc_enum;c:\windows\system32\DRIVERS\vodafone_K3805-z_dc_enum.sys [2010-03-01 61952] S3 ZTEusbvoice;ZTE VoUSB Port;c:\windows\system32\DRIVERS\ZTEusbvoice.sys [2010-04-30 105856] S3 ZTEusbwwan;ZTE MBN Miniport;c:\windows\system32\DRIVERS\ZTEusbwwan.sys [2010-06-10 194048] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper . . ------- Supplementary Scan ------- . uStart Page = about:blank TCP: {E481D8DE-43C8-4878-B42D-DD2FAEC18884} = 202.124.65.22 202.124.65.18 . - - - - ORPHANS REMOVED - - - - BHO-{0974BA1E-64EC-11DE-B2A5-E43756D89593} - c:\progra~1\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll Toolbar-{0974BA1E-64EC-11DE-B2A5-E43756D89593} - c:\progra~1\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll HKLM-Run-atr.exe - (no file) MSConfigStartUp-DATAMNGR - c:\progra~1\BEARSH~1\MediaBar\Datamngr\DATAMN~1.EXE MSConfigStartUp-SearchSettings - c:\program files\YouTube Downloader Toolbar\SearchSettings.exe AddRemove-Hoadley Options Strategy Evaluation Tool_is1 - c:\program files\HoadleyOptions\unins000.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DUMeterSvc] "ImagePath"="c:\program files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] Denied: (Full) (Everyone) . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'Explorer.exe'(3860) c:\program files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL c:\program files\Common Files\Microsoft Shared\Encarta Search Bar\A\ESBRes.DLL . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\atieclxx.exe c:\program files\Common Files\Acronis\Schedule2\schedul2.exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\windows\system32\taskhost.exe c:\windows\system32\conhost.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\program files\Acronis\DriveMonitor\adm.exe . ************************************************************************** . Completion time: 2010-11-10 07:20:44 - machine was rebooted ComboFix-quarantined-files.txt 2010-11-09 21:20 Pre-Run: 313,216,090,112 bytes free Post-Run: 313,234,837,504 bytes free - - End Of File - - 15DBDB942C9E623E8AA909342BBEF4BF Look a pretty long one and very impressive. Please, explain to me the results! Should i delete "ComboFix" from my PC? Best regards, YvesPlease download SystemLook from one of the links below and save it to your desktop. Link # 1 Link # 2 Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double-click SystemLook.exe to run it. Copy the contents of the following codebox into the main textfield. Code: [Select]:filefind userinit.exe Click the Look button to start the scan. Note: The scan may take some time so please just let it do its work and be patient (or do something else unrelated to the computer). When finished, a notepad window will open with the results of the scan. Please post the log. The log can also be found on your desktop entitled SystemLook.txt ****************************** SysProt Antirootkit Download SysProt Antirootkit from the link below (you will find it at the bottom of the page under attachments, or you can get it from one of the mirrors). http://sites.google.com/site/sysprotantirootkit/ Unzip it into a folder on your desktop.
extracted to. Open the text file and copy/paste the log here. [/list] Hi! Dave, Here are the results of the scan with " SystemLook". Regards, Yves SystemLook 04.09.10 by jpshortstuff Log created at 09:23 on 11/11/2010 by Yves Administrator - Elevation successful ========== filefind ========== Searching for "userinit.exe " C:\Windows\ERDNT\cache\userinit.exe --a---- 26112 bytes [21:08 09/11/2010] [01:14 14/07/2009] 6DE80F60D7DE9CE6B8C2DDFDF79EF175 C:\Windows\System32\userinit.exe --a---- 26112 bytes [23:34 13/07/2009] [01:14 14/07/2009] 6DE80F60D7DE9CE6B8C2DDFDF79EF175 C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe --a---- 26112 bytes [23:34 13/07/2009] [01:14 14/07/2009] 6DE80F60D7DE9CE6B8C2DDFDF79EF175 -= EOF =-Hi! Dave, Here are the results with the scan SysProtAntirootkit SysProt AntiRootkit v1.0.1.0 by swatkat ****************************************************************************************** ****************************************************************************************** No Hidden Processes found ****************************************************************************************** ****************************************************************************************** No Hidden Kernel Modules found ****************************************************************************************** ****************************************************************************************** No SSDT Hooks found ****************************************************************************************** ****************************************************************************************** No Kernel Hooks found ****************************************************************************************** ****************************************************************************************** No hidden files/folders found I am happy with the results. Regards, YvesOk. Let's see if we can fix that corrupted/infected file. Re-running ComboFix to remove infections:
Here i am not sure.... I got the "commy.exe" and it is this one i have to use and drag "CFScript.txt" in it. Or re-download the original ComboFix? Regards, YvesYes, use the one you have on your desktop. |
|
| 1616. |
Solve : AV8? antimalwarelist pop up while surfing? |
|
Answer» Hi, |
|
| 1617. |
Solve : Please help, being hijacked while web surfing...? |
|
Answer» Hey, I'm starting to get the hang of this computer stuff. I was able to disable StopZilla at startup and tried the ComboFix again. It ran the very first time! This is the log it produced...
Hi SuperDave, I'm think I may have accidentally cured this problem by experimenting with Firefox. I removed it from my computer completely to see if this bug would somehow migrate to another browser (Chrome). I used it for a few days, with no sign of any hijacking. I then loaded Firefox again, and have been using it for several hours without incident, again, knock on wood. Below is the log... GooredFix by jpshortstuff (03.07.10.1) Log created at 02:08 on 21/10/2010 (Wayne) Firefox version 2.0.0.11 (en-US) ========== GooredScan ========== (none) ========== GooredLog ========== C:\Program Files\Mozilla Firefox\extensions\ [email protected] [06:31 21/10/2010] {972ce4c6-7e08-4474-a285-3208198ce6fd} [06:31 21/10/2010] C:\Documents and Settings\Wayne\Application Data\Mozilla\Firefox\Profiles\qddlnzpx.default\extensions\ (none) [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] (Key not found) -=E.O.F=-Well, that's good news. Let's give it a few days. If it's fixed post back again and we'll do whatever cleanup is necessary.Hi SuperDave, well I've given it a week of constant surfing so far, and there is no evidence that the bug is still around. I have used three different browsers and found no problem. Thanks kindly for all your patience. You mentioned something about a cleanup?That's good news. We'll just do some cleanup. * Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box. * Now type Combofix /uninstall in the runbox * Make sure there's a space between Combofix and /Uninstall * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ********************************** To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ***************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|
| 1618. |
Solve : Lost my Post here? Facebook gave me virus.? |
|
Answer» You need to use Notepad.
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download UPDATES for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the CONTENTS of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET ONLINE Scanner\log.txt |
|
| 1619. |
Solve : "your system is infected" virus and also 'windows cannot access specified..'? |
|
Answer» I don't know if it would've actually affected Combofix or not, but I wasn't able to really disable AVG. I tried following the appropriate steps but it wouldn't let me disable anything. So I tried uninstalling it but that just failed multiple times. So I tried just deleting it which didn't quite work either (1 file wasn't able to be deleted). Just thought I'd add that incase it was important.You have Viewpoint installed.
Download Security Check by screen317 from one of the following links and save it to your desktop. Link 1 Link 2 * Unzip SecurityCheck.zip and a folder named Security Check should appear. * Open the Security Check folder and double-click Security Check.bat * Follow the on-screen instructions inside of the BLACK box. * A Notepad document should open automatically called checkup.txt * Post the contents of that document in your next reply. Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so. ********************************** Please try running SuperAntiSpyware and MalwareBytes-Antimalware and post the logs if you're successful.Combo fix log: ComboFix 10-10-21.05 - Ryan 23/10/2010 12:33:02.4.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.64.1033.18.1982.1082 [GMT 13:00] Running from: c:\users\Ryan\Desktop\commy.exe Command switches used :: c:\users\Ryan\Desktop\CFScript.txt AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_DFBCFDBA ((((((((((((((((((((((((( Files Created from 2010-09-22 to 2010-10-22 ))))))))))))))))))))))))))))))) . 2010-10-22 23:47 . 2010-10-22 23:54 -------- d-----w- c:\users\Ryan\AppData\Local\temp 2010-10-22 23:47 . 2010-10-22 23:47 -------- d-----w- c:\users\Public\AppData\Local\temp 2010-10-22 23:47 . 2010-10-22 23:47 -------- d-----w- c:\users\Guest\AppData\Local\temp 2010-10-22 23:47 . 2010-10-22 23:47 -------- d-----w- c:\users\Guest(56)\AppData\Local\temp 2010-10-22 23:47 . 2010-10-22 23:47 -------- d-----w- c:\users\Default\AppData\Local\temp 2010-10-22 23:26 . 2010-10-22 23:29 -------- dc----r- C:\32788R22FWJFW 2010-10-22 08:08 . 2010-10-07 23:21 6146896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A15205D0-8851-4AAD-B675-A6BFC9825264}\mpengine.dll 2010-10-18 02:01 . 2010-04-29 02:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-10-18 02:01 . 2010-04-29 02:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-10-17 08:31 . 2010-10-17 08:41 11952 ----a-w- c:\windows\system32\avgrsstx.dll 2010-10-17 08:31 . 2010-10-17 08:41 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2010-10-17 08:30 . 2010-10-17 08:41 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2010-10-17 08:30 . 2010-10-17 08:43 -------- d-----w- c:\windows\system32\drivers\Avg 2010-10-15 09:47 . 2010-09-13 13:56 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe 2010-10-15 09:47 . 2010-09-13 13:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL 2010-10-15 09:47 . 2010-09-06 16:20 125952 ----a-w- c:\windows\system32\srvsvc.dll 2010-10-15 09:47 . 2010-09-06 13:45 304128 ----a-w- c:\windows\system32\drivers\srv.sys 2010-10-15 09:47 . 2010-09-06 13:45 145408 ----a-w- c:\windows\system32\drivers\srv2.sys 2010-10-15 09:47 . 2010-09-06 13:45 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys 2010-10-15 09:47 . 2010-09-06 16:19 17920 ----a-w- c:\windows\system32\netevent.dll 2010-10-14 10:29 . 2010-10-14 10:29 -------- d-----w- c:\program files\Trend Micro 2010-10-10 02:38 . 2010-10-10 02:38 -------- d-----w- c:\program files\Giant Crocodile 2010-10-08 08:58 . 2010-10-08 08:58 -------- dc----w- C:\$AVG 2010-10-08 06:08 . 2010-10-08 06:08 -------- dc----w- C:\AVG10 2010-10-08 06:06 . 2010-10-08 06:06 -------- d--h--w- c:\programdata\Common Files 2010-10-08 06:03 . 2010-10-14 08:43 -------- d-----w- c:\programdata\AVG10 2010-10-08 05:51 . 2010-10-08 06:01 -------- d-----w- c:\programdata\MFAData 2010-10-08 05:39 . 2010-10-18 19:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-09-30 08:28 . 2010-09-30 08:28 -------- d-----w- c:\windows\Profiles 2010-09-29 07:54 . 2010-06-22 13:30 2048 ----a-w- c:\windows\system32\tzres.dll 2010-09-28 11:31 . 2010-09-28 11:31 -------- d-----w- c:\program files\iPod 2010-09-28 11:24 . 2010-09-28 11:24 -------- d-----w- c:\program files\Bonjour . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-10-18 22:41 . 2010-02-11 13:33 222080 ------w- c:\windows\system32\MpSigStub.exe 2010-09-13 03:27 . 2010-09-13 03:27 25680 ----a-w- c:\windows\system32\drivers\AVGIDSEH.sys 2010-09-07 22:17 . 2010-09-07 22:17 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx 2010-09-07 22:17 . 2010-09-07 22:17 69632 ----a-w- c:\windows\system32\QuickTime.qts 2010-08-17 14:11 . 2010-09-16 08:10 128000 ----a-w- c:\windows\system32\spoolsv.exe 2010-07-27 05:44 . 2010-07-27 05:44 91424 ----a-w- c:\windows\system32\dnssd.dll 2010-07-27 05:44 . 2010-07-27 05:44 107808 ----a-w- c:\windows\system32\dns-sd.exe 2009-01-27 01:34 . 2009-01-27 01:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-01-27 01:34 . 2009-01-27 01:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll 2007-08-25 01:52 . 2008-06-05 11:59 300400 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-07-09 159744] "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-10-01 181544] "QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032] "OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320] "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152] "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560] "WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-16 47392] "VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-01-29 52392] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-23 13601312] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-23 92704] "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-24 202256] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-17 248040] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-07 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-23 421160] "Malwarebytes Anti-Malware (rootkit-scan)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952] c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] ="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] ="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 133104] R2 Nakido;Nakido;c:\program files\Nakido\nakido.exe R3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\DRIVERS\ASPI32.sys [2002-07-17 84832] R3 cxru92a1;Virtual Bus for Microsoft ACPI-Compliant System; R3 iscFlash;iscFlash;c:\swsetup\sp42533\iscflash.sys [2008-08-05 11520] R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys R3 WPFFontCache_v0400;Windows Presentation FOUNDATION Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2008-04-29 717296] S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 25680] S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-10-17 335240] S2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2009-12-16 375296] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 HPService REG_MULTI_SZ HPSLPSVC hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Contents of the 'Scheduled Tasks' folder 2010-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 23:39] 2010-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 23:39] 2010-10-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-753018427-1233051673-1299658189-1003Core.job - c:\users\Ryan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-10 04:59] 2010-10-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-753018427-1233051673-1299658189-1003UA.job - c:\users\Ryan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-10 04:59] . . ------- Supplementary Scan ------- . uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_nz&c=81&bd=Presario&pf=laptop mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_nz&c=81&bd=Presario&pf=laptop uInternet Settings,ProxyServer = proxy.student.otago.ac.nz:3128 uInternet Settings,ProxyOverride = IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} - hxxp://static.ak.facebook.com/fbplugin/win32/axfbootloader.cab FF - ProfilePath - c:\users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\ FF - component: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll FF - component: c:\users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'Explorer.exe'(6024) c:\program files\Nokia\Nokia PC Suite 6\phonebrowser.dll c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng-us.nlr c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\nvvsvc.exe c:\windows\system32\WLANExt.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\CyberLink\Shared Files\RichVideo.exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\windows\system32\DRIVERS\xaudio.exe c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\windows\system32\rundll32.exe c:\windows\System32\rundll32.exe c:\program files\Windows Media Player\wmpnscfg.exe c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe c:\program files\Apoint2K\ApMsgFwd.exe c:\program files\Apoint2K\Apntex.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\program files\Hewlett-Packard\Shared\HpqToaster.exe c:\program files\iPod\bin\iPodService.exe . ************************************************************************** . Completion time: 2010-10-23 13:02:20 - machine was rebooted ComboFix-quarantined-files.txt 2010-10-23 00:02 ComboFix2.txt 2010-10-22 11:35 Pre-Run: 2,451,070,976 bytes free Post-Run: 2,405,908,480 bytes free - - End Of File - - 07875887ABC7EAB551A8CE336F04D7D3 security check log: Results of screen317's Security Check version 0.99.5 Windows Vista Service Pack 2 (UAC is disabled!) Internet Explorer 7 Out of date! `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Disabled! Antivirus 2010 Antivirus up to date! ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware HijackThis 2.0.2 CCleaner Java(TM) 6 Update 19 Out of date Java installed! Adobe Flash Player 10.0.45.2 Adobe Reader 9.3.4 ```````````````````````````````` Process Check: objlist.exe by Laurent Windows Defender MSASCui.exe Spybot Teatimer.exe is disabled! Microsoft Small Business Business Contact Manager BcmSqlStartupSvc.exe ```````````````````````````````` DNS Vulnerability Check: ``````````End of Log```````````` Update Your Java (JRE) Old versions of Java have vulnerabilities that malware can use to infect your system. First Verify your Java Version If there are any other version(s) installed then update now. Get the new version (if needed) If your version is out of date install the newest version of the Sun Java Runtime Environment. Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update. Be sure to close ALL open web browsers before starting the installation. Remove any old versions 1. Download JavaRa and unzip the file to your Desktop. 2. Open JavaRA.exe and choose Remove Older Versions 3. Once complete exit JavaRA. 4. Run CCleaner. Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer. Were you able to run SAS and MBAM?Ok so I updated Java, and I was indeed able to run SAS and MBAM. Here are the logs: MBAM: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4052 Windows 6.0.6002 Service Pack 2 Internet Explorer 7.0.6002.18005 24/10/2010 5:37:04 p.m. mbam-log-2010-10-24 (17-37-04).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 388506 Time elapsed: 2 hour(s), 3 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Users\Ryan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Antivirus.lnk (Rogue.AntiVirus) -> Quarantined and deleted successfully. SAS: SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 10/25/2010 at 03:32 AM Application Version : 4.44.1000 Core Rules Database Version : 5610 Trace Rules Database Version: 3422 Scan type : Complete Scan Total Scan Time : 04:20:54 Memory items scanned : 694 Memory threats detected : 0 Registry items scanned : 10461 Registry threats detected : 0 File items scanned : 246934 File threats detected : 165 Adware.Tracking Cookie C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][3].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt acvs.mediaonenetwork.net [ C:\Users\Guest(56)\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\4JC7KVSW ] C:\Users\Guest(56)\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Guest(56)\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Guest(56)\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Guest(56)\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt .peertracking.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .peertracking.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .peertracking.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .doubleclick.net [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .atdmt.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .atdmt.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .imrworldwide.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .msnportal.112.2o7.net [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .imrworldwide.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .bs.serving-sys.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .serving-sys.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .serving-sys.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .serving-sys.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .serving-sys.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .serving-sys.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .serving-sys.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] .serving-sys.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ] acvs.mediaonenetwork.net [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] api.firestormmedia.tv [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] banners.securedataimages.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] cdn2.themis-media.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] cdn4.specificclick.net [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] content.oddcast.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] core.insightexpressai.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] i.*adult URL* [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] ia.media-imdb.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] ictv-ic-ec.indieclicktv.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] indieclick.3janecdn.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] media.kyte.tv [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] media.mtvnservices.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] media.scanscout.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] media.socialvibe.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] media1.break.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] movies.hdteenmovs.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] msnbcmedia.msn.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] naiadsystems.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] objects.tremormedia.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] rmd.atdmt.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] s0.2mdn.net [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] secure-us.imrworldwide.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] www.naiadsystems.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ] C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt .warez-bb.org [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .warez-bb.org [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] www.warez-bb.org [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .kontera.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .kontera.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .kontera.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .kontera.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .mediaonenetwork.net [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .collective-media.net [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] d.mediadakine.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .mediadakine.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .clicksor.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .clicksor.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .clicksor.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .clicksor.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .clicksor.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] d.mediadakine.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] imagevenue.advertserve.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] imagevenue.advertserve.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .ero-advertising.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] d.mediadakine.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .microsoftsto.112.2o7.net [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .invitemedia.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .invitemedia.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .interclick.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .interclick.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .interclick.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .invitemedia.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .*adult URL* [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .server.cpmstar.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .server.cpmstar.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .server.cpmstar.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .server.cpmstar.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .content.yieldmanager.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] *Blocked Russian URL* [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] dc.tremormedia.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .adserver.adtechus.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] rts.pgmediaserve.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] rts.pgmediaserve.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] rts.pgmediaserve.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .partypoker.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .partypoker.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .partypoker.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .content.yieldmanager.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] .partypoker.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ] Please download ComboFix from BleepingComputer.com Alternate link: GeeksToGo.com Rename ComboFix.exe to commy.exe before you save it to your Desktop Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here Click Start then copy paste the following command into the search box & hit enter: "%userprofile%\desktop\commy.exe" /stepdel As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. This will not install in Vista. Just continue scanning, and skip the console install. When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply. If you have problems with ComboFix usage, see How to use ComboFixHi, sorry for taking so long to reply, been a bit busy with exams. Heres the new combofix log: ComboFix 10-10-31.04 - Ryan 01/11/2010 23:23:59.5.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.64.1033.18.1982.1020 [GMT 13:00] Running from: c:\users\Ryan\Desktop\commy.exe Command switches used :: /stepdel AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\arp.exe . ((((((((((((((((((((((((( Files Created from 2010-10-01 to 2010-11-01 ))))))))))))))))))))))))))))))) . 2010-11-01 10:33 . 2010-11-01 10:34 -------- d-----w- c:\users\Ryan\AppData\Local\temp 2010-11-01 10:33 . 2010-11-01 10:33 -------- d-----w- c:\users\Public\AppData\Local\temp 2010-11-01 10:33 . 2010-11-01 10:33 -------- d-----w- c:\users\Guest\AppData\Local\temp 2010-11-01 10:33 . 2010-11-01 10:33 -------- d-----w- c:\users\Guest(56)\AppData\Local\temp 2010-11-01 10:33 . 2010-11-01 10:33 -------- d-----w- c:\users\Default\AppData\Local\temp 2010-10-31 08:11 . 2010-08-26 16:34 1696256 ----a-w- c:\windows\system32\gameux.dll 2010-10-31 08:11 . 2010-08-26 16:33 28672 ----a-w- c:\windows\system32\Apphlpdm.dll 2010-10-31 08:11 . 2010-08-26 14:23 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2010-10-31 08:11 . 2010-10-07 23:21 6146896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A68C4A42-4035-43FD-A738-1CF0B1EDD3D0}\mpengine.dll 2010-10-28 05:38 . 2010-10-28 05:38 -------- d-----w- c:\windows\en 2010-10-28 05:38 . 2010-09-22 11:21 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys 2010-10-28 05:28 . 2009-09-04 04:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll 2010-10-28 05:28 . 2009-09-04 04:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll 2010-10-28 05:28 . 2009-09-04 04:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll 2010-10-28 01:18 . 2010-10-28 01:18 469256 ----a-w- c:\program files\Common Files\Windows Live\.cache\e31dd701cb763e2b\InstallManager_WLE_WLE.exe 2010-10-28 01:17 . 2010-10-28 01:17 15712 ----a-w- c:\program files\Common Files\Windows Live\.cache\e6008ef01cb763d1f\MeshBetaRemover.exe 2010-10-28 01:16 . 2010-10-28 01:16 525656 ----a-w- c:\program files\Common Files\Windows Live\.cache\c9252b101cb763d18\DXSETUP.exe 2010-10-28 01:16 . 2010-10-28 01:16 94040 ----a-w- c:\program files\Common Files\Windows Live\.cache\c9252b101cb763d18\DSETUP.dll 2010-10-28 01:16 . 2010-10-28 01:16 1691480 ----a-w- c:\program files\Common Files\Windows Live\.cache\c9252b101cb763d18\dsetup32.dll 2010-10-28 01:16 . 2010-10-28 01:16 94040 ----a-w- c:\program files\Common Files\Windows Live\.cache\c62001601cb763d17\DSETUP.dll 2010-10-28 01:16 . 2010-10-28 01:16 525656 ----a-w- c:\program files\Common Files\Windows Live\.cache\c62001601cb763d17\DXSETUP.exe 2010-10-28 01:16 . 2010-10-28 01:16 1691480 ----a-w- c:\program files\Common Files\Windows Live\.cache\c62001601cb763d17\dsetup32.dll 2010-10-28 01:14 . 2010-11-01 09:57 -------- d-----w- c:\users\Ryan\AppData\Local\Windows Live 2010-10-28 01:12 . 2009-08-04 08:02 754688 ----a-w- c:\windows\system32\webservices.dll 2010-10-25 05:24 . 2010-10-25 05:24 -------- d-----w- c:\program files\Common Files\Java 2010-10-25 05:23 . 2010-09-14 15:50 472808 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll 2010-10-25 05:23 . 2010-09-14 15:50 472808 ----a-w- c:\windows\system32\deployJava1.dll 2010-10-24 10:09 . 2010-10-24 10:09 -------- d-----w- c:\users\Ryan\AppData\Roaming\SUPERAntiSpyware.com 2010-10-18 02:01 . 2010-04-29 02:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-10-18 02:01 . 2010-04-29 02:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-10-17 08:31 . 2010-10-17 08:41 11952 ----a-w- c:\windows\system32\avgrsstx.dll 2010-10-17 08:31 . 2010-10-17 08:41 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2010-10-17 08:30 . 2010-10-17 08:41 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2010-10-17 08:30 . 2010-10-17 08:43 -------- d-----w- c:\windows\system32\drivers\Avg 2010-10-15 09:47 . 2010-09-13 13:56 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe 2010-10-15 09:47 . 2010-09-13 13:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL 2010-10-15 09:47 . 2010-09-06 16:20 125952 ----a-w- c:\windows\system32\srvsvc.dll 2010-10-15 09:47 . 2010-09-06 13:45 304128 ----a-w- c:\windows\system32\drivers\srv.sys 2010-10-15 09:47 . 2010-09-06 13:45 145408 ----a-w- c:\windows\system32\drivers\srv2.sys 2010-10-15 09:47 . 2010-09-06 13:45 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys 2010-10-15 09:47 . 2010-09-06 16:19 17920 ----a-w- c:\windows\system32\netevent.dll 2010-10-14 10:29 . 2010-10-14 10:29 -------- d-----w- c:\program files\Trend Micro 2010-10-10 02:38 . 2010-10-10 02:38 -------- d-----w- c:\program files\Giant Crocodile 2010-10-08 08:58 . 2010-10-08 08:58 -------- dc----w- C:\$AVG 2010-10-08 06:06 . 2010-10-08 06:06 -------- d--h--w- c:\programdata\Common Files 2010-10-08 06:03 . 2010-10-14 08:43 -------- d-----w- c:\programdata\AVG10 2010-10-08 05:51 . 2010-10-08 06:01 -------- d-----w- c:\programdata\MFAData 2010-10-08 05:39 . 2010-10-18 19:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-10-18 22:41 . 2010-02-11 13:33 222080 ------w- c:\windows\system32\MpSigStub.exe 2010-09-22 11:47 . 2010-09-22 11:47 49016 ----a-w- c:\windows\system32\sirenacm.dll 2010-09-22 11:32 . 2010-09-22 11:32 301936 ----a-w- c:\windows\WLXPGSS.SCR 2010-09-13 03:27 . 2010-09-13 03:27 25680 ----a-w- c:\windows\system32\drivers\AVGIDSEH.sys 2010-09-07 22:17 . 2010-09-07 22:17 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx 2010-09-07 22:17 . 2010-09-07 22:17 69632 ----a-w- c:\windows\system32\QuickTime.qts 2010-08-26 16:33 . 2010-10-31 08:11 173056 ----a-w- c:\windows\apppatch\AcXtrnal.dll 2010-08-26 16:33 . 2010-10-31 08:11 2159616 ----a-w- c:\windows\apppatch\AcGenral.dll 2010-08-26 16:33 . 2010-10-31 08:11 458752 ----a-w- c:\windows\apppatch\AcSpecfc.dll 2010-08-26 16:33 . 2010-10-31 08:11 542720 ----a-w- c:\windows\apppatch\AcLayers.dll 2010-08-17 14:11 . 2010-09-16 08:10 128000 ----a-w- c:\windows\system32\spoolsv.exe 2009-01-27 01:34 . 2009-01-27 01:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-01-27 01:34 . 2009-01-27 01:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll 2007-08-25 01:52 . 2008-06-05 11:59 300400 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-09-22 4240760] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-09-28 2424560] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-07-09 159744] "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-10-01 181544] "QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032] "OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320] "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152] "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560] "WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-16 47392] "VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-01-29 52392] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-23 13601312] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-23 92704] "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-24 202256] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-07 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-23 421160] "Malwarebytes Anti-Malware (rootkit-scan)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-13 248552] c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] ="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] ="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 133104] R2 Nakido;Nakido;c:\program files\Nakido\nakido.exe R3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\DRIVERS\ASPI32.sys [2002-07-17 84832] R3 cxru92a1;Virtual Bus for Microsoft ACPI-Compliant System; R3 iscFlash;iscFlash;c:\swsetup\sp42533\iscflash.sys [2008-08-05 11520] R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2008-04-29 717296] S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 25680] S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-10-17 335240] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656] S2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2009-12-16 375296] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 HPService REG_MULTI_SZ HPSLPSVC hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Contents of the 'Scheduled Tasks' folder 2010-11-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 23:39] 2010-11-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 23:39] 2010-10-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-753018427-1233051673-1299658189-1003Core.job - c:\users\Ryan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-10 04:59] 2010-11-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-753018427-1233051673-1299658189-1003UA.job - c:\users\Ryan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-10 04:59] . . ------- Supplementary Scan ------- . uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_nz&c=81&bd=Presario&pf=laptop mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_nz&c=81&bd=Presario&pf=laptop uInternet Settings,ProxyServer = proxy.student.otago.ac.nz:3128 uInternet Settings,ProxyOverride = IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} - hxxp://static.ak.facebook.com/fbplugin/win32/axfbootloader.cab FF - ProfilePath - c:\users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\ FF - prefs.js: network.proxy.ftp - proxy.student.otago.ac.nz FF - prefs.js: network.proxy.ftp_port - 3128 FF - prefs.js: network.proxy.gopher - proxy.student.otago.ac.nz FF - prefs.js: network.proxy.gopher_port - 3128 FF - prefs.js: network.proxy.http - proxy.student.otago.ac.nz FF - prefs.js: network.proxy.http_port - 3128 FF - prefs.js: network.proxy.socks - proxy.student.otago.ac.nz FF - prefs.js: network.proxy.socks_port - 3128 FF - prefs.js: network.proxy.ssl - proxy.student.otago.ac.nz FF - prefs.js: network.proxy.ssl_port - 3128 FF - prefs.js: network.proxy.type - 1 FF - component: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll FF - component: c:\users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-11-01 23:34 Windows 6.0.6002 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2010-11-01 23:36:42 ComboFix-quarantined-files.txt 2010-11-01 10:36 ComboFix2.txt 2010-10-23 00:02 ComboFix3.txt 2010-10-22 11:35 Pre-Run: 1,443,819,520 bytes free Post-Run: 1,573,527,552 bytes free - - End Of File - - 7C743AE4BF11B6BBE5462453976BC3C7 Is your computer working any better? SysProt Antirootkit Download SysProt Antirootkit from the link below (you will find it at the bottom of the page under attachments, or you can get it from one of the mirrors). http://sites.google.com/site/sysprotantirootkit/ Unzip it into a folder on your desktop.
extracted to. Open the text file and copy/paste the log here. [/list] My computer is definitely working a lot better than it was before, although there a still a few things happening that never really HAPPENED before. Sometimes programs like Internet Explorer or iTunes randomly decide to crash. Also, if I click the button on my mouse that brings up the magnifying glass tool, everything pauses and the screen goes black for about a second before going back to normal. Those small issues are the only ones I'm noticing though. Here's the Sysprot Antirootkit log: SysProt AntiRootkit v1.0.1.0 by swatkat ****************************************************************************************** ****************************************************************************************** No Hidden Processes found ****************************************************************************************** ****************************************************************************************** Kernel Modules: Module Name: \SystemRoot\System32\Drivers\dump_dumpata.sys Service Name: --- Module Base: 8CFBD000 Module End: 8CFC8000 Hidden: Yes Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys Service Name: --- Module Base: 8CFC8000 Module End: 8CFD0000 Hidden: Yes ****************************************************************************************** ****************************************************************************************** SSDT: Function Name: ZwTerminateProcess Address: 8CED9620 Driver Base: 8CECF000 Driver End: 8CEF1000 Driver Name: \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS ****************************************************************************************** ****************************************************************************************** No Kernel Hooks found ****************************************************************************************** ****************************************************************************************** Hidden files/folders: Object: C:\Qoobox\BackEnv\AppData.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Cache.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Cookies.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Desktop.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Favorites.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\History.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Music.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\NetHood.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Personal.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Pictures.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\PrintHood.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Profiles.Folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Programs.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Recent.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\SendTo.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\SetPath.bat Status: Access denied Object: C:\Qoobox\BackEnv\StartMenu.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\StartUp.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\SysPath.dat Status: Access denied Object: C:\Qoobox\BackEnv\Templates.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\VikPev00 Status: Access denied Object: C:\Users\Ryan\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{DAC71EAD-ED09-F966-DCD5-DFD0F8DB3CC1}\01\10-{DAC71EAD-ED09-F966-DCD5-DFD0F8DB3CC1}-v1-{DB34C54A-12AB-43EE-B476-02BEB35A910F Status: Hidden Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl Status: Access denied Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl Status: Access denied Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl Status: Access denied Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl Status: Access denied Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMsMpPsSession.etl Status: Access denied Quote Sometimes programs like Internet Explorer or iTunes randomly decide to crash. Also, if I click the button on my mouse that brings up the magnifying glass tool, everything pauses and the screen goes black for about a second before going back to normal. Those small issues are the only ones I'm noticing though.Those sound like hardware or software problems. Let's continue. I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Here is the log from the ESET online scan: C:\Qoobox\Quarantine\C\Windows\PRAGMAyrtxnwrcjt\PRAGMAc.dll.vir a variant of Win32/Kryptik.EXT trojan cleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Windows\System32\drivers\agp440.sys.vir a variant of Win32/Rootkit.Kryptik.BS trojan cleaned by deleting - quarantined C:\SWSetup\AOLIMS\setup.exe probably a variant of Win32/Agent.HZHBURL trojan cleaned by deleting - quarantined C:\Users\Ryan\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\30cd253-2667789e multiple threats deleted - quarantined C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3G8ZRRT0\INSTALL[1] Win32/Adware.Antivirus2010 application cleaned by deleting - quarantined C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3G8ZRRT0\script[1] Win32/Adware.Antivirus2010 application cleaned by deleting - quarantined C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P4APQ21N\dialog_alert[1] Win32/Adware.Antivirus2010 application cleaned by deleting - quarantined That looks good. If there are no other issues, let's do some cleanup. * Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box. * Now type commy /uninstall in the runbox * Make sure there's a space between commy and /Uninstall * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ********************************* Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ************************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. ************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|
| 1620. |
Solve : Due to this scan my PC is safe?? |
|
Answer» Glad it GOT resolved. |
|
| 1621. |
Solve : I hope I did this correct? |
|
Answer» Before doing this, could we try and understand what all this will be doing to the computer? Like those 3 things you say to put a checkmark by. We want to make sure this will not cause me to not be able to do certain things anymore with any of my accounts. Those are my useraccounts I use on Funtrivia. Funtrivia is a website that I make quizzes on. So, I want to make sure I wont be accidently removing any of my quizzes I've made. # N3 - Netscape 7: user_pref(\"browser.startup.homepage\", \"http://www.funtrivia.com\"); (C:\Documents and Settings\AMYR\Application Data\Mozilla\Profiles\default\3c1q6q2g.slt\prefs.js) I have never seen an entry in a HJT log like this. You can skip that part if you are sure it is needed but you do need to be sure to fix the other entry. Quote Fix This! -> F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,SKEYS /IQuote from: evilfantasy on May 16, 2009, 07:10:39 PM Everyones computer is set up different so if I am asking you to do something that does not sound right then I don't mind you making sure I'm not going the wrong direction Is funtrivia.com the default homepage you have set your FIREFOX browser to? That's what it looks like to me ... when i saw that funtrivia.com thing. You sure that's a good site? But in all honesty, evilfantasy's one of the masters of malware on ths board as far as I've seen I should have researched first before requesting that you fix it. You never can think you have learned all there is to know with HijackThis... It's definitely legitimate. The prefs.js made me think it was a iFrame infection. OOPS Quote HijackThis N1, N2, N3, N4 SectionsSorry if I'm asking too much. Also, thank you again for all the help you all are giving too. Before continuing on with things, just want to double check that I'm understanding the steps to do and do you still need the other logs 2. SUPERAntiSpyware Log The only problem I'm having with the above is I did get the SuperAntiSpyware thing to work but only thing on that one is there are 2 logs I have for that one because noticed that I missed something on the Scanning Control tab thing the options, I accidently messed up with that one and had other things checked too. So, should I POST both logs? I noticed that one of the logs it found something that I'm now wondering if that is half my problems some program called- Adware.eXactAdvertising-Installer I typed that in on my mom's computer to see if I could figure more out about what exactly it is. It mentioned something about CPU usage going up, and that is one of my problems I keep having problems with my CPU usage going up to 100% ever since switching from Earthlink Dialup to Bellsouth DSL. 3. Malwarebytes' Anti-Malware Log I can't even get the Malwarebytes program to install at all on the computer. It keeps looking for the disc when I take it out. Yes, funtrivia is what I have for my start page. I thought that we could put in anything we want? Looks like it's a good thing I haven't done anything yet either since now looking like I don't need to do anything at all with those pref.js things. I noticed you said you need to be sure though on the other one? I just asked my mom and she doesn't understand it either. Also, thought we would mention that our computers are hooked up together. So, making sure some of what is being detected is stuff from her computer? Since my computer keeps getting infected with viruses and spyware so much, is one of the things my mom is afraid of that it can harm her computer somehow? See before with dialup internet we didn't have our computers hooked together. The other thing, I'm trying to understand what all the Combofix does. One of the things I noticed it says Windows Vista, and I don't have Windows Vista. So, will it even work? I'm looking at the page to see if I understand what all it even is, and looks a little scary. Do I need to back anything up before doing this? Like save things to a disc in case it erases something important? We just get so worried about this happening especially since it has happend on so many occasions in the past with us not understanding things all the way. The very first time something happend was when a technician at Compaq had us do an FDisk and before doing it we asked if I need to back anything up? They said no. Which was wrong because it erased everything. Then when I talked to a friend in Michigan who knows alot on computers because he even builds computers said that is what an FDisk does. It reformats things. Which we didn't know that. Also, have had problems with other programs in the past like Ccleaner erasing important stuff because we didn't understand what exactly the files are. Go back to This Post and follow through with those instructions. Quote The other thing, I'm trying to understand what all the Combofix does. One of the things I noticed it says Windows Vista, and I don't have Windows Vista. So, will it even work? Read the instructions. It says "Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it) You are not a Vista user so it doesn't apply. Just follow the instructions. Everything you need to do will always be there. Quote Also, have had problems with other programs in the past like Ccleaner erasing important stuff because we didn't understand what exactly the files are. Again, just follow the instructions in This Post. That's all I need for now. sorry for all the questions too. but due to my health and disabilities is hard for me to understand and do things in life. I get confused really easily. I'm reading back over things. Could you explain to me though what exactly that thing is? F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,SKEYS /I We did a search on the internet about it and sounds like it's a bug in the new HJT and someone says not to worry about it. Looking at the word REG sounds like it has something to do with the Registry, which we are a bit worried about doing things to the Registry since we don't understand it at all and the repairmen we have used in the past have all warned us too about not messing with the Registry. We are also wondering, why did the last repairman we had work on the computer right before Christmas not do anything about this file if it is something bad? Quote Looking at the word REG sounds like it has something to do with the Registry, which we are a bit worried about doing things to the Registry since we don't understand it at all and the repairmen we have used in the past have all warned us too about not messing with the Registry. HijackThis is a registry information and repair tool. You are going to have to trust that I know what I'm doing F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,SKEYS /I <- This is a Serial Key Utility and it is a big security risk. I hope you're alright ... just take things slowly one step at a time and you'll be good soon. Just now get up to speed and evil's gonna help you out some more Combofix is a really nice program to have when your pc is really sick once you know what it can do for you, at least it's successfully cured my pc of issues when I last used it Sorry that we are asking so many questions but we would like to understand all these computer stuff better and all. I hope you can understand why we want to understand everything going on due to all the problems over the years and technicians we have tried in the past who have told us things to do that cause worse problems, and then if you need to know everything that has been done on the computer so that you can give the next technicians all the details of what all has been done to the computer that may have caused the problems. Also, thought you said it was ok to ask too since especially the one thing too you didn't know about the default start pages for Mozilla and Netscape. Only thing about the Serial Key thing is we do have to enter in a serial key for some of the products we use. Oh HijackThis does have to do with the registry? Wasn't sure. See, this one repairman we used right before the one we used right before Christmas blamed us for doing something wrong when we called him after he was working on the computer and caused my scanner to BREAK and ever since then have not been able to get it working again. See we were getting him to help us with some of the stuff this other site was having us do to the computer after reading the HijackThis Log. Which we actually didn't do anything they said to do though since didn't know how to do some of the things anyways. He didn't agree on alot of what they said to do. So, we didn't do it. So, anyways, he was going to charge to come back out and help get the scanner working again. First, trust Evilfantasy. He knows what he's doing. Why do you think he is a Malware Removal Specialist? He deals with HijackThis every day on dozens of computers. Second, trust me for telling you to trust him. Third, Everything you do involves the registry in some way. All HijackThis does is scan through the registry to look for potential security threats, which you can choose to eliminate. If it's any consolation, I've used HiJackThis, and I run scans every few weeks to see if anything is out of line. From where I see it, you have two choices. End this topic and keep your computer at risk of attack, or end your fussing and eliminate the security risk.Quote from: Carbon Dudeoxide on May 17, 2009, 01:17:46 AM First, trust Evilfantasy. He knows what he's doing. Why do you think he is a Malware Removal Specialist? He deals with HijackThis every day on dozens of computers. I suggest you should follow the instructions, get the problems solved then afterwards you can go find out the reasons behind what you have done (unless you find something fishy while fixing then that's something else). At least your computer will be happier quicker which is what you want in the end anyway. Quote from: Carbon Dudeoxide on May 17, 2009, 01:17:46 AM From where I see it, you have two choices. End this topic and keep your computer at risk of attack, or end your fussing and eliminate the security risk. Agreed. I don't mind answering questions but I learned everything I know the hard way and I'm not going to start teaching a class here. There comes a point when I have to ask the user. Are you going to post the logs or not? If not then that's fine. If so then please do so. Although we volunteer our time it is work for me having to read all of these long questions and they are not helping in a resolution. Quote from: evilfantasy on May 16, 2009, 03:35:00 PM Only report to me what problems you are having at this immediate moment, things that were happening does me no good. Honestly, we could most likely have been done with this yesterday! With all due respect, it's beginning to be a waste of my time. P.S. You need to move away from using Netscape. It is no longer supported and very vulnerable to malware attack. It's a Java based browser and that is very insecure.This is Amy's mom writing. Sorry for all the questions and for misunderstanding anything here, Yes, we understand that he is a Malware Removal Specialist. But due to mistakes others have made in the past on our computers, that is why we want to make sure it is the right thing to do before doing it so that it doesn't cause any wore problems. I don't understand why you are now SAYING that you don't need to know everything that is happening with the computer. From what we learned, whenever dealing with techs, they want to know the history in case it has to do with what is going on. Plus since the stuff is still happening, isn't that important to know what all has been tried so far. Also, my computer is hooked up with Amy's, where it wasn't in the past, and my Grandson who knows way more about computers than I do, has mentioned to be careful what people tell us to do because could mess mine up. Yes, we know that Netscape isn't out there anymore, but have used it for years with no problems. Her Internet Explorer stopped working though years ago due to being attacked when downloading the AOL Instant Messanger for her class she had just signed up for and some MBKWBar Toolbar came through with the download and started causing popup ads to keep flooding and crash the computer. Which that is the first time we learned about spyware, adware, all that. We did know about viruses, but not the other. So, the repairman we used then said not to use IE anymore and never bothered to fix it. He did put Mozilla on. But now that is not on her computer anymore due to virus messing it up to where everything becomes distorted when trying to use it. So, it seems every browser out there is vulnerable. We also try and read all articles and stuff out there on computer stuff, and understand that its very complicated. Again, sorry if we have caused any problems for you. Sounds like maybe this isn't the best place for us to get help. We understand this is alot of work for you and every other computer techs out there. See everytime we have called for tech support, they always want to know what all has been done so far on computer. Isn't that helpful so that you don't waste your time doing something again that has already been tried? If we are now understanding this right, HiJackThis just has to do with security? Does it not find viruses or spyware? Sounds like maybe this isn't the best place for us to get help. your the first iv'e seen saying that on here , i think you should keep paying the REPAIRMEN because it looks like you do not trust what you are being told on here , harry 48 |
|
| 1622. |
Solve : Privacy Center malware!!! =/? |
|
Answer» ComboFix 09-06-26.02 - XP User 06/27/2009 19:01.5 - NTFSx86
How is the computer running? ---------- ---------- Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. The computer seems to be running fine the only thing thats really irratating is that it keeps shutting off randomly! it's quite often too!Quote computer keeps shutting off randomly This could be any number of things causing that. Have you INSTALLED any new hardware recently?Nopee no new software installed!Was it happening before the malware problems? Quote c:\program files\Windows Doctor Is Windows Doctor still installed? It wasnt happening before! and yes Windows Doctor is still installed! is that bad?If it isn't paid for then yes I would uninstall Windows Doctor. I've never heard of it and what I researched was conflicting information on it's trustworthiness. Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop. Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it) * XP users Double click on dds to run it. * If your antivirus or firewall try to block DDS then please allow it to run. * When finished DDS will OPEN two (2) logs. 1) DDS.txt 2) Attach.txt * Save both logs to your desktop. * Please copy and paste the entire contents of both logs in your next reply. Note: DDS will instruct you to post the Attach.txt log as an attachment. Please just post it as you would any other log by copy and pasting it into the reply. DDS (Ver_09-06-26.01) - NTFSx86 Run by XP User at 2:35:17.00 on Mon 06/29/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.162 [GMT -4:00] AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\McAfee\SiteAdvisor\McSACore.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Apoint2K\Apoint.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Apoint2K\Apntex.exe C:\Program Files\McAfee.com\Agent\mcagent.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\WINDOWS\system32\ctfmon.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Program Files\McAfee\MSK\MskSrver.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\XP User\Desktop\dds.pif ============== Pseudo HJT Report =============== uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\progra~1\mcafee\viruss~1\scriptsn.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe" mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe mRun: [AGRSMMSG] AGRSMMSG.exe mRun: [Apoint] c:\program files\apoint2k\Apoint.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [McENUI] c:\progra~1\mcafee\mhn\McENUI.exe /hide IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {9E265649-6E0E-4EEA-9F49-DAE0801440CF} - hxxp://70.46.125.59/WebDiginet.CAB DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Notify: igfxcui - igfxsrvc.dll LSA: Authentication Packages = msv1_0 nwprovau ============= SERVICES / DRIVERS =============== R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2008-6-27 214024] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-6-25 210216] R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-6-25 359952] R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-6-25 144704] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-6-25 79816] R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-6-25 35272] S3 DCamUSBTP10;Cam IV;c:\windows\system32\drivers\TP6810.SYS [2008-7-24 240584] S3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-6-25 606736] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-6-25 34248] S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-6-25 40552] =============== Created Last 30 ================ 2009-06-27 20:00--ds----C:\ComboFix 2009-06-27 19:20--d-----C:\e3061928c59c400685fca2c6 2009-06-26 22:41--d-----c:\documents and settings\xp user\WINDOWS 2009-06-26 20:3113,712a-------c:\windows\system32\wpa.bak 2009-06-25 22:25--d-----c:\program files\Windows Doctor 2009-06-25 22:175,169a-------c:\windows\system32\Config.MPF 2009-06-25 21:39--d-----c:\program files\SiteAdvisor 2009-06-25 21:31--d-----c:\program files\McAfee.com 2009-06-25 21:14-cd-----c:\windows\system32\dllcache\cache 2009-06-25 20:51a-dshr--C:\cmdcons 2009-06-25 19:48--d-----c:\windows\system32\appmgmt 2009-06-25 19:26--d-----c:\windows\system32\CatRoot2 2009-06-25 18:2840,552a-------c:\windows\system32\drivers\mfesmfk.sys 2009-06-25 18:2879,816a-------c:\windows\system32\drivers\mfeavfk.sys 2009-06-25 18:2835,272a-------c:\windows\system32\drivers\mfebopk.sys 2009-06-25 18:28120,136a-------c:\windows\system32\drivers\Mpfp.sys 2009-06-25 18:26--d-----c:\program files\common files\McAfee 2009-06-25 18:25--d-----c:\program files\McAfee 2009-06-25 18:2434,248a-------c:\windows\system32\drivers\mferkdk.sys 2009-06-25 18:09--d-----c:\docume~1\alluse~1\applic~1\Geek Squad ==================== Find3M ==================== 2009-05-13 23:25214,024a-------c:\windows\system32\drivers\mfehidk.sys 2009-05-07 11:44344,064a-------c:\windows\system32\localspl.dll 2009-04-29 00:56827,392a-------c:\windows\system32\wininet.dll 2009-04-29 00:5578,336a-------c:\windows\system32\ieencode.dll 2009-04-17 05:581,846,656a-------c:\windows\system32\win32k.sys 2009-04-15 11:11584,192a-------c:\windows\system32\rpcrt4.dll 2009-04-06 00:0790,112a-------c:\windows\DUMP62e0.tmp ============= FINISH: 2:36:57.28 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 7/12/2008 9:32:29 PM System Uptime: 6/29/2009 2:32:49 AM (0 hours ago) Motherboard: Hewlett-Packard | | 309D Processor: Intel(R) Celeron(R) M processor 1.50GHz | U1 | 1496/400mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 75 GiB total, 63.419 GiB free. D: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP1: 6/27/2009 10:26:18 PM - System Checkpoint ==== Installed Programs ====================== Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742) Adobe Flash Player 10 ActiveX Adobe Reader 8.1.2 Adobe Reader 8.1.2 Security Update 1 (KB403742) Agere Systems AC'97 Modem ALPS Touch Pad Driver Apple Mobile Device Support Apple Software Update Broadcom 802.11 Wireless LAN Adapter Cam IV GTOneCare Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB952287) Intel(R) Graphics Media Accelerator Driver for Mobile iTunes Java(TM) 6 Update 3 Java(TM) 6 Update 7 LimeWire 4.16.6 LiveUpdate 3.1 (Symantec Corporation) McAfee SecurityCenter Microsoft .NET FRAMEWORK 1.0 Hotfix (KB930494) Microsoft Application Error Reporting Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Professional Edition 2003 PowerDVD QuickTime Safari Security Update for CAPICOM (KB931906) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893066) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944338) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB950749) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) SoundMAX Texas Instruments PCIxx21/x515/xx12 drivers. TIPCI Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB932823-v3) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update for Windows XP (KB951072-v2) Update for Windows XP (KB955839) Update for Windows XP (KB967715) WebFldrs XP Windows Doctor 2.0 Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Live installer Windows Live Messenger Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893086 ==== Event Viewer Messages From Past Week ======== 6/27/2009 6:54:43 PM, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 0014A57A06C4 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 6/27/2009 4:04:03 PM, error: DCOM [10005] - DCOM got error "%1450" attempting to start the service COMSysApp with arguments "" in ORDER to run the server: {ECABAFBC-7F19-11D2-978E-0000F8757E2A} 6/26/2009 7:54:58 PM, error: Service Control Manager [7034] - The McAfee Services service terminated unexpectedly. It has done this 3 time(s). 6/26/2009 7:54:58 PM, error: Service Control Manager [7034] - The McAfee Real-time Scanner service terminated unexpectedly. It has done this 3 time(s). 6/26/2009 7:54:58 PM, error: Service Control Manager [7034] - The McAfee Network Agent service terminated unexpectedly. It has done this 3 time(s). 6/26/2009 7:53:27 PM, error: Service Control Manager [7031] - The McAfee Services service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 6/26/2009 7:53:27 PM, error: Service Control Manager [7031] - The McAfee Real-time Scanner service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 6/26/2009 7:53:27 PM, error: Service Control Manager [7031] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 5000 milliseconds: Run the configured recovery program. 6/26/2009 7:47:11 PM, error: Service Control Manager [7034] - The McAfee Anti-Spam Service service terminated unexpectedly. It has done this 1 time(s). 6/26/2009 7:47:11 PM, error: Service Control Manager [7031] - The McAfee Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 6/26/2009 7:47:11 PM, error: Service Control Manager [7031] - The McAfee Real-time Scanner service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 6/26/2009 7:47:11 PM, error: Service Control Manager [7031] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Run the configured recovery program. 6/26/2009 7:47:11 PM, error: Service Control Manager [7031] - The McAfee Network Agent service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 6/26/2009 5:21:23 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 81ec16e8, parameter3 81ec185c, parameter4 805c77ca. 6/25/2009 9:08:36 PM, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: The specified module could not be found. 6/25/2009 8:54:25 PM, error: Service Control Manager [7034] - The McAfee Proxy Service service terminated unexpectedly. It has done this 3 time(s). 6/25/2009 8:53:08 PM, error: Service Control Manager [7031] - The McAfee Proxy Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 6/25/2009 8:52:44 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect. 6/25/2009 8:50:29 PM, error: Service Control Manager [7031] - The McAfee Proxy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 6/25/2009 8:17:50 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 6/25/2009 7:47:44 PM, error: Service Control Manager [7024] - The Symantec SPBBCSvc service terminated with service-specific error 4294967295 (0xFFFFFFFF). 6/25/2009 7:19:31 PM, error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 6/25/2009 7:18:06 PM, error: Service Control Manager [7034] - The Media Center Scheduler Service service terminated unexpectedly. It has done this 1 time(s). 6/25/2009 7:18:00 PM, error: Service Control Manager [7034] - The Media Center Receiver Service service terminated unexpectedly. It has done this 1 time(s). 6/25/2009 7:17:42 PM, error: Service Control Manager [7034] - The Symantec Event Manager service terminated unexpectedly. It has done this 1 time(s). 6/25/2009 7:17:36 PM, error: Service Control Manager [7034] - The Symantec Settings Manager service terminated unexpectedly. It has done this 1 time(s). 6/25/2009 7:17:20 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s). 6/25/2009 7:17:16 PM, error: Service Control Manager [7034] - The Symantec AntiVirus Definition Watcher service terminated unexpectedly. It has done this 1 time(s). 6/25/2009 7:17:04 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s). 6/25/2009 6:42:06 PM, error: Service Control Manager [7031] - The McAfee Network Agent service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 6/25/2009 6:41:42 PM, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running. 6/25/2009 6:32:00 PM, error: Service Control Manager [7031] - The Symantec AntiVirus service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. 6/25/2009 6:13:42 PM, error: Service Control Manager [7034] - The Windows Image Acquisition (WIA) service terminated unexpectedly. It has done this 1 time(s). 6/25/2009 4:40:58 PM, error: Service Control Manager [7031] - The Symantec AntiVirus service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. ==== End Of File =========================== Download Disable/Remove Windows Messenger to the Desktop to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups. Unzip the file on the Desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply. Exit out of MessengerDisable then delete the two files that were put on the Desktop. ---------- Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to infect your system. First install the new Sun Java Runtime Environment Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update. Be sure to close all browser windows before beginning the install. Remove the old version(s) Download JavaRa * Unzip the file and open the JavaRa.exe * Click Remove Older Versions * JavaRa will search for and remove any outdated version of Java and remove any that are found. * Click Additional Tasks * Place a check next to Remove Useless JRE Files and click Go * Exit JavaRa * Delete the JavaRa files from the Desktop Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer. ---------- Download the Norton Removal Tool (SymNRT) to your desktop. Once downloaded please close ALL open browsers, also save any work because this may require a restart.
---------- How is the computer running now? . |
|
| 1623. |
Solve : WARNING New scam targets User Forums.. activationlink.co? |
|
Answer» WARNING New scam targets User Forums.. activationlink.co It's just a generic search provider Thanks for checking it out. for some reason my ISP or browser blocks that site. My limited research indicated that is was part of a PHP ATTACK. Because no harm was done, that does no PROVE lack of malicious intent. The attack is very widespread and seeks out user forums. Yea I saw it in my Google search. It's definitely not to be trusted!I recently found this site: http://www.tkafeestekene.be/index.php?option=com_akobook&Itemid=29 The link will take you to their guestbook where you can see MANY of these messages spammed. The website is for a German cafe but you can see all the messages in the guestbook. The links are broken.Great, so these people come here and post links in (a href=) with a bogus description. Is there a way to set up description tags like slashdot has? |
|
| 1624. |
Solve : Help needed! CPU freezing. Inexpericenced user.? |
|
Answer» Ok I have a Dell Desktop that I've owned for 2, maybe 3 years. Always worked fine no major problems until recently. My cpu started freezing up during startup. I WOULD log on and it would start to load my desktop and programs and halfway through it would freeze. I ran a few programs in safe mode and now can start the CPU but if i plug in my wireless adapter and try to connect to the internet my cpu will freeze. I use Mozilla firefox. I can run firefox in "safemode with networking" which I am doing now. |
|
| 1625. |
Solve : Malwarebytes problems!! need help!? |
|
Answer» So i downloaded Malwarebytes Malware remover and its on my desktop, and all of the files appear to be present, but every time i click the icon or try to open the file, nothing happens...at all.. i believe that it may be because of some kind of virus affecting my registry or something im not EXACTLY sure.... I also cannot run Disk Defragmenter (every time i click analyze or defrag it pops up a window saying "Disk Defragmenter could not start") and cannot go to certain websites such as malwarebytes.org.....many of them simply say "Internet Explorer cannot display the webpage."
Hey, does anyone have problems with malwarebytes DESTROYING the drivers for your cd rom or dvd rom? Or keeps you from connecting to the internet with on one of your users? Please don't hijack someone else's post. Start a new one. |
|
| 1626. |
Solve : Completed Evilfantasy's directions - here are my posts.? |
|
Answer» I was unsure where I needed to post this, but here it is. |
|
| 1627. |
Solve : Possibly Conficker, logs included? |
|
Answer» Ok...a couple days ago I had to format my C and reinstall windows xp pro. One of the first things I did was install windows update and get sp2. Then reinstalled AVG Malwarebytes and Opera. Last night I discovered I needed to get the .net frame for another program I run. |
|
| 1628. |
Solve : Hii geeks two probs cant find solution? |
|
Answer» hiii geeks i have 2 probs one is trojan virus and another is no POST or no BOOT sound. Avast, Avira, MCAfee, Kaspersky Do you have all of those programs on your computer at once?Quote no POST It won't post at all? I assume that it won't start up either?hii all thks for the replies but i tried all the ways.....i have installed CA antivirus, MCAfee, etc....all at once but its not reoving ....i want to remove the word file that is being created in each and every folder....pls help out..!You only want one antivirus program at one time. If you have more than one antivirus program on your computer they will bump HEADS. This will cause major problems with your computer. Go into Add/Remove Programs and uninstall all but one of your antivirus programs. |
|
| 1629. |
Solve : file msnmgnr.exe is missing flashes after start up? |
|
Answer» 2 weeks ago i was having time/date reset to september 2020 everytime i boot my PC. back then i thought it was a virus/malware problem but my avg antivirus cannot see it. this week i started to have the error missing file msnmgnr.exe after my pc starts. then i started reading about that file and realized its in fact a virus. i found out that the file msnmgnr.exe in fact causes the date reset i experienced 2 weeks ago. however, i wasnt able to find a clear fix over the net for my problem. i need help. the necessary logs are found below. thanks.
ComboFix 09-06-09.06 - Jared 06/11/2009 9:23.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1590 [GMT 8:00] Running from: c:\documents and settings\Jared\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Jared\Desktop\CFScript.txt AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\messenger\msmsgs.exe c:\program files\Need2Find c:\program files\Need2Find\bar\Cache\00255494 c:\windows\system32\rrqWxGgh.ini c:\windows\system32\rrqWxGgh.ini2 . ((((((((((((((((((((((((( Files Created from 2009-05-11 to 2009-06-11 ))))))))))))))))))))))))))))))) . 2009-06-11 00:47 . 2009-06-11 00:47--------d-----w-c:\program files\Java 2009-06-10 04:39 . 2009-06-10 04:39--------d-----w-c:\program files\Trend Micro 2009-06-09 17:49 . 2009-06-09 17:49--------d-----w-c:\documents and settings\Jared\Application Data\Malwarebytes 2009-06-09 17:49 . 2009-05-26 05:2040160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-09 17:49 . 2009-06-09 17:49--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes 2009-06-09 17:49 . 2009-05-26 05:1919096----a-w-c:\windows\system32\drivers\mbam.sys 2009-06-09 17:49 . 2009-06-09 17:49--------d-----w-c:\program files\Malwarebytes' Anti-Malware 2009-06-09 16:53 . 2009-06-11 00:47410984----a-w-c:\windows\system32\deploytk.dll 2009-06-09 16:52 . 2009-06-09 16:52152576----a-w-c:\documents and settings\Jared\Application Data\Sun\Java\jre1.6.0_13\lzma.dll 2009-06-09 16:24 . 2009-06-09 17:45117760----a-w-c:\documents and settings\Jared\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-06-09 16:22 . 2009-06-09 16:22--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-06-09 16:22 . 2009-06-09 16:22--------d-----w-c:\program files\SUPERAntiSpyware 2009-06-09 16:22 . 2009-06-09 16:22--------d-----w-c:\documents and settings\Jared\Application Data\SUPERAntiSpyware.com 2009-06-09 15:52 . 2009-06-09 15:52--------d-----w-c:\program files\CCleaner 2009-06-09 01:26 . 2009-06-09 01:26--------d-sh--w-c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357} 2009-06-09 01:22 . 2009-06-09 01:22--------d-----w-c:\documents and settings\All Users\Application Data\Uniblue 2009-06-09 01:07 . 2009-06-09 01:21--------d-----w-c:\program files\Uniblue 2009-06-09 00:44 . 2009-06-09 01:22--------d-----w-c:\documents and settings\Jared\Application Data\Uniblue 2009-06-09 00:43 . 2009-03-13 15:052567647-c----w-c:\documents and settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}\Uniblue RegistryBooster.exe 2009-06-09 00:43 . 2009-06-09 00:54--------dc-h--w-c:\documents and settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81} 2009-05-29 07:44 . 2009-05-29 07:44--------d-----w-c:\program files\MSECache 2009-05-28 14:55 . 2009-06-08 14:30--------d-----w-c:\documents and settings\Jared\Local Settings\Application Data\S2 2009-05-28 14:52 . 2009-05-28 14:5298304----a-w-c:\windows\system32\CmdLineExt.dll 2009-05-28 14:52 . 2009-05-28 14:52--------d--h--r-c:\documents and settings\Jared\Application Data\SecuROM 2009-05-28 14:45 . 2009-05-28 14:45--------d-----w-c:\program files\Ubisoft . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-09 16:22 . 2007-09-11 08:11--------d-----w-c:\program files\Common Files\Wise Installation Wizard 2009-06-09 15:31 . 2008-01-23 13:45--------d-----w-c:\program files\GameHouse 2009-06-09 02:20 . 2007-12-23 05:30--------d-----w-c:\program files\YouTube Downloader 2009-06-09 01:17 . 2008-09-28 19:06--------d-----w-c:\documents and settings\Jared\Application Data\uTorrent 2009-06-08 12:41 . 2007-09-07 08:12900--sha-w-c:\windows\system32\KGyGaAvL.sys 2009-06-08 04:42 . 2009-04-04 16:21--------d-----w-c:\program files\Windows Media Connect 2 2009-06-08 04:00 . 2009-04-03 01:03--------d-----w-c:\documents and settings\Jared\Application Data\FMZilla 2009-05-29 07:45 . 2008-08-31 13:0465600----a-w-c:\documents and settings\Jared\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-05-22 13:17 . 2008-10-24 02:22--------d-----w-c:\documents and settings\Jared\Application Data\LimeWire 2009-05-21 23:42 . 2008-12-16 01:03--------d-----w-c:\documents and settings\Jared\Application Data\AVGTOOLBAR 2009-05-17 08:39 . 2009-05-10 07:43--------d-----w-c:\program files\Garena 2009-05-10 06:29 . 2009-05-10 06:29--------d-----w-c:\documents and settings\Jared\Application Data\InstallShield 2009-05-09 01:54 . 2008-12-16 01:0311952----a-w-c:\windows\system32\avgrsstx.dll 2009-05-09 01:54 . 2008-12-16 01:03325896----a-w-c:\windows\system32\drivers\avgldx86.sys 2009-05-09 01:54 . 2008-12-16 01:0327784----a-w-c:\windows\system32\drivers\avgmfx86.sys 2009-05-09 01:54 . 2008-12-16 01:03108552----a-w-c:\windows\system32\drivers\avgtdix.sys 2009-04-17 05:49 . 2008-11-08 06:22--------d-----w-c:\documents and settings\Jared\Application Data\Skype 2007-10-25 03:28 . 2007-10-25 03:2818895728----a-w-c:\program files\Install_Messenger.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{038cb5c7-48ea-4af9-94e0-a1646542e62b}] 2009-02-16 07:441882136----a-w-c:\program files\ToggleEN\tbTogg.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Gainward"="c:\program files\VDOTool\TBPanel.exe" [2007-06-26 2165272] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-11 148888] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-23 8466432] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-07-23 1626112] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-12-20 16860672] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-11 68856] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 04:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-05-09 01:5411952----a-w-c:\windows\system32\avgrsstx.dll [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" -quiet "Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized "swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" "KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k "Alcmtr"=ALCMTR.EXE "QuickFix"=c:\program files\QuickFix\QuickFix.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Ubisoft\\Funatics\\The Settlers II - 10th Anniversary\\bin\\S2DNG.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "6112:TCP"= 6112:TCP:Blizzard Downloader: 6112 "6881:TCP"= 6881:TCP:Blizzard Downloader: 6881 "6999:TCP"= 6999:TCP:Blizzard Downloader: 6999 "6990:TCP"= 6990:TCP:Blizzard Downloader: 6990 "6885:TCP"= 6885:TCP:Blizzard Downloader: 6885 "3724:TCP"= 3724:TCP:Blizzard Downloader: 3724 "443:TCP"= 443:TCP:https "21:TCP"= 21:TCP:ftp [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings] "AllowInboundEchoRequest"= 0 (0x0) "AllowInboundTimestampRequest"= 0 (0x0) "AllowInboundMaskRequest"= 0 (0x0) "AllowInboundRouterRequest"= 0 (0x0) "AllowOutboundDestinationUnreachable"= 0 (0x0) "AllowOutboundSourceQuench"= 0 (0x0) "AllowOutboundParameterProblem"= 0 (0x0) "AllowOutboundTimeExceeded"= 0 (0x0) "AllowRedirect"= 0 (0x0) "AllowOutboundPacketTooBig"= 0 (0x0) R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/16/2008 9:03 AM 325896] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/16/2008 9:03 AM 108552] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 10:05 AM 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 10:05 AM 72944] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [12/16/2008 9:03 AM 908568] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [12/16/2008 9:03 AM 298776] R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [9/7/2007 2:26 PM 38656] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 10:05 AM 7408] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{28ABC5C0-4FCB-11CF-AAX5-81CX1C635618}] c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\msnmgnr.exe . Contents of the 'Scheduled Tasks' folder 2009-06-03 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 09:57] 2009-06-09 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job - c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2009-06-09 01:42] 2009-06-09 c:\windows\Tasks\Uniblue SpeedUpMyPC.job - c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2009-06-09 01:42] 2009-06-09 c:\windows\Tasks\Uniblue SpyEraser.job - c:\program files\Uniblue\SpyEraser\SpyEraser.exe [2009-06-09 01:14] 2009-06-11 c:\windows\Tasks\WGASetup.job - c:\windows\system32\KB905474\wgasetup.exe [2009-05-07 14:18] . - - - - ORPHANS REMOVED - - - - Notify-xxyXOhFX - xxyXOhFX.dll . ------- Supplementary Scan ------- . uStart Page = hxxp://fmz.qiwa.com mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html IE: &Search IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\Jared\Application Data\Mozilla\Firefox\Profiles\rfcjzjrh.default\ FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/ FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npkimi.dll ---- FIREFOX POLICIES ---- FF - user.js: network.http.max-persistent-connections-per-server - 3 FF - user.js: content.max.tokenizing.time - 2250000 FF - user.js: content.notify.interval - 750000 FF - user.js: content.switch.threshold - 750000 FF - user.js: nglayout.initialpaint.delay - 750 FF - user.js: network.http.max-connections-per-server - 6 FF - user.js: google.toolbar.linkdoctor.enabled - false FF - user.js: browser.search.defaultenginename - Yoog Search FF - user.js: keyword.enabled - true . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-11 09:27 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-1547161642-1637723038-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:17,6d,cf,8a,bc,c6,12,a1,65,fd,49,de,73,33,23,08,b0,ba,36,dd,0b,cc,85, e8,09,5a,97,46,ab,6e,9d,d4,0d,a6,98,eb,a6,7a,22,eb,50,e7,00,14,15,c5,8e,11,\ "??"=hex:dc,bc,25,01,99,f9,4d,24,96,0e,32,50,c4,b1,f9,22 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\ProgID] @DACL=(02 0000) @="dc_ads.ads.1" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\Programmable] @DACL=(02 0000) [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\TypeLib] @DACL=(02 0000) @="{E94C3AF8-D32C-4389-AC9A-BE17471EDC42}" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\VersionIndependentProgID] @DACL=(02 0000) @="dc_ads.ads" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(700) c:\program files\SUPERAntiSpyware\SASWINLO.dll - - - - - - - > 'explorer.exe'(1476) c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll c:\program files\VDOTool\TBPanelExt.dll c:\windows\system32\nvcpl.dll c:\windows\system32\nvapi.dll c:\windows\system32\nvshell.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\WgaTray.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\nvsvc32.exe c:\program files\AVG\AVG8\avgrsx.exe c:\progra~1\AVG\AVG8\avgnsx.exe c:\program files\AVG\AVG8\avgcsrvx.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Completion time: 2009-06-11 9:29 - machine was rebooted ComboFix-quarantined-files.txt 2009-06-11 01:29 Pre-Run: 128,982,495,232 bytes free Post-Run: 129,051,725,824 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer 233--- E O F ---2009-06-09 03:00 Not there yet... Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: DDS:: FF - user.js: browser.search.defaultenginename - Yoog Search Firefox:: FF - user.js: browser.search.defaultenginename - Yoog Search Registry:: [-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{28ABC5C0-4FCB-11CF-AAX5-81CX1C635618}] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "iTunesHelper"=- "KernelFaultCheck"=- "Alcmtr"=- "QuickFix"=- 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezethe next CF log below. ComboFix 09-06-09.06 - Jared 06/11/2009 10:17.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1539 [GMT 8:00] Running from: c:\documents and settings\Jared\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Jared\Desktop\CFScript.txt AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ((((((((((((((((((((((((( Files Created from 2009-05-11 to 2009-06-11 ))))))))))))))))))))))))))))))) . 2009-06-11 00:47 . 2009-06-11 00:47--------d-----w-c:\program files\Java 2009-06-10 04:39 . 2009-06-10 04:39--------d-----w-c:\program files\Trend Micro 2009-06-09 17:49 . 2009-06-09 17:49--------d-----w-c:\documents and settings\Jared\Application Data\Malwarebytes 2009-06-09 17:49 . 2009-05-26 05:2040160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-09 17:49 . 2009-06-09 17:49--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes 2009-06-09 17:49 . 2009-05-26 05:1919096----a-w-c:\windows\system32\drivers\mbam.sys 2009-06-09 17:49 . 2009-06-09 17:49--------d-----w-c:\program files\Malwarebytes' Anti-Malware 2009-06-09 16:53 . 2009-06-11 00:47410984----a-w-c:\windows\system32\deploytk.dll 2009-06-09 16:52 . 2009-06-09 16:52152576----a-w-c:\documents and settings\Jared\Application Data\Sun\Java\jre1.6.0_13\lzma.dll 2009-06-09 16:24 . 2009-06-09 17:45117760----a-w-c:\documents and settings\Jared\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-06-09 16:22 . 2009-06-09 16:22--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-06-09 16:22 . 2009-06-09 16:22--------d-----w-c:\program files\SUPERAntiSpyware 2009-06-09 16:22 . 2009-06-09 16:22--------d-----w-c:\documents and settings\Jared\Application Data\SUPERAntiSpyware.com 2009-06-09 15:52 . 2009-06-09 15:52--------d-----w-c:\program files\CCleaner 2009-06-09 01:26 . 2009-06-09 01:26--------d-sh--w-c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357} 2009-06-09 01:22 . 2009-06-09 01:22--------d-----w-c:\documents and settings\All Users\Application Data\Uniblue 2009-06-09 01:07 . 2009-06-09 01:21--------d-----w-c:\program files\Uniblue 2009-06-09 00:44 . 2009-06-09 01:22--------d-----w-c:\documents and settings\Jared\Application Data\Uniblue 2009-06-09 00:43 . 2009-03-13 15:052567647-c----w-c:\documents and settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}\Uniblue RegistryBooster.exe 2009-06-09 00:43 . 2009-06-09 00:54--------dc-h--w-c:\documents and settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81} 2009-05-29 07:44 . 2009-05-29 07:44--------d-----w-c:\program files\MSECache 2009-05-28 14:55 . 2009-06-08 14:30--------d-----w-c:\documents and settings\Jared\Local Settings\Application Data\S2 2009-05-28 14:52 . 2009-05-28 14:5298304----a-w-c:\windows\system32\CmdLineExt.dll 2009-05-28 14:52 . 2009-05-28 14:52--------d--h--r-c:\documents and settings\Jared\Application Data\SecuROM 2009-05-28 14:45 . 2009-05-28 14:45--------d-----w-c:\program files\Ubisoft . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-09 16:22 . 2007-09-11 08:11--------d-----w-c:\program files\Common Files\Wise Installation Wizard 2009-06-09 15:31 . 2008-01-23 13:45--------d-----w-c:\program files\GameHouse 2009-06-09 02:20 . 2007-12-23 05:30--------d-----w-c:\program files\YouTube Downloader 2009-06-09 01:17 . 2008-09-28 19:06--------d-----w-c:\documents and settings\Jared\Application Data\uTorrent 2009-06-08 12:41 . 2007-09-07 08:12900--sha-w-c:\windows\system32\KGyGaAvL.sys 2009-06-08 04:42 . 2009-04-04 16:21--------d-----w-c:\program files\Windows Media Connect 2 2009-06-08 04:00 . 2009-04-03 01:03--------d-----w-c:\documents and settings\Jared\Application Data\FMZilla 2009-05-29 07:45 . 2008-08-31 13:0465600----a-w-c:\documents and settings\Jared\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-05-22 13:17 . 2008-10-24 02:22--------d-----w-c:\documents and settings\Jared\Application Data\LimeWire 2009-05-21 23:42 . 2008-12-16 01:03--------d-----w-c:\documents and settings\Jared\Application Data\AVGTOOLBAR 2009-05-17 08:39 . 2009-05-10 07:43--------d-----w-c:\program files\Garena 2009-05-10 06:29 . 2009-05-10 06:29--------d-----w-c:\documents and settings\Jared\Application Data\InstallShield 2009-05-09 01:54 . 2008-12-16 01:0311952----a-w-c:\windows\system32\avgrsstx.dll 2009-05-09 01:54 . 2008-12-16 01:03325896----a-w-c:\windows\system32\drivers\avgldx86.sys 2009-05-09 01:54 . 2008-12-16 01:0327784----a-w-c:\windows\system32\drivers\avgmfx86.sys 2009-05-09 01:54 . 2008-12-16 01:03108552----a-w-c:\windows\system32\drivers\avgtdix.sys 2009-04-17 05:49 . 2008-11-08 06:22--------d-----w-c:\documents and settings\Jared\Application Data\Skype 2007-10-25 03:28 . 2007-10-25 03:2818895728----a-w-c:\program files\Install_Messenger.exe . ((((((((((((((((((((((((((((( [emailprotected]_01.27.07 ))))))))))))))))))))))))))))))))))))))))) . + 2009-06-11 02:20 . 2009-06-11 02:2016384 c:\windows\temp\Perflib_Perfdata_790.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{038cb5c7-48ea-4af9-94e0-a1646542e62b}] 2009-02-16 07:441882136----a-w-c:\program files\ToggleEN\tbTogg.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-11 148888] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-09 1947928] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-23 8466432] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-12-20 16860672] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-11 68856] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 04:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-05-09 01:5411952----a-w-c:\windows\system32\avgrsstx.dll [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" -quiet "Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized "swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" "KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k "Alcmtr"=ALCMTR.EXE "QuickFix"=c:\program files\QuickFix\QuickFix.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Ubisoft\\Funatics\\The Settlers II - 10th Anniversary\\bin\\S2DNG.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "6112:TCP"= 6112:TCP:Blizzard Downloader: 6112 "6881:TCP"= 6881:TCP:Blizzard Downloader: 6881 "6999:TCP"= 6999:TCP:Blizzard Downloader: 6999 "6990:TCP"= 6990:TCP:Blizzard Downloader: 6990 "6885:TCP"= 6885:TCP:Blizzard Downloader: 6885 "3724:TCP"= 3724:TCP:Blizzard Downloader: 3724 "443:TCP"= 443:TCP:https "21:TCP"= 21:TCP:ftp [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings] "AllowInboundEchoRequest"= 0 (0x0) "AllowInboundTimestampRequest"= 0 (0x0) "AllowInboundMaskRequest"= 0 (0x0) "AllowInboundRouterRequest"= 0 (0x0) "AllowOutboundDestinationUnreachable"= 0 (0x0) "AllowOutboundSourceQuench"= 0 (0x0) "AllowOutboundParameterProblem"= 0 (0x0) "AllowOutboundTimeExceeded"= 0 (0x0) "AllowRedirect"= 0 (0x0) "AllowOutboundPacketTooBig"= 0 (0x0) R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/16/2008 9:03 AM 325896] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/16/2008 9:03 AM 108552] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 10:05 AM 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 10:05 AM 72944] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [12/16/2008 9:03 AM 908568] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [12/16/2008 9:03 AM 298776] R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [9/7/2007 2:26 PM 38656] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 10:05 AM 7408] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder 2009-06-03 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 09:57] 2009-06-09 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job - c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2009-06-09 01:42] 2009-06-09 c:\windows\Tasks\Uniblue SpeedUpMyPC.job - c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2009-06-09 01:42] 2009-06-09 c:\windows\Tasks\Uniblue SpyEraser.job - c:\program files\Uniblue\SpyEraser\SpyEraser.exe [2009-06-09 01:14] 2009-06-11 c:\windows\Tasks\WGASetup.job - c:\windows\system32\KB905474\wgasetup.exe [2009-05-07 14:18] . . ------- Supplementary Scan ------- . uStart Page = hxxp://fmz.qiwa.com mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html IE: &Search IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\Jared\Application Data\Mozilla\Firefox\Profiles\rfcjzjrh.default\ FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/ FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npkimi.dll ---- FIREFOX POLICIES ---- FF - user.js: network.http.max-persistent-connections-per-server - 3 FF - user.js: content.max.tokenizing.time - 2250000 FF - user.js: content.notify.interval - 750000 FF - user.js: content.switch.threshold - 750000 FF - user.js: nglayout.initialpaint.delay - 750 FF - user.js: network.http.max-connections-per-server - 6 FF - user.js: google.toolbar.linkdoctor.enabled - false FF - user.js: browser.search.defaultenginename - Yoog Search FF - user.js: keyword.enabled - true . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-11 10:24 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-1547161642-1637723038-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:17,6d,cf,8a,bc,c6,12,a1,65,fd,49,de,73,33,23,08,b0,ba,36,dd,0b,cc,85, e8,09,5a,97,46,ab,6e,9d,d4,0d,a6,98,eb,a6,7a,22,eb,50,e7,00,14,15,c5,8e,11,\ "??"=hex:dc,bc,25,01,99,f9,4d,24,96,0e,32,50,c4,b1,f9,22 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\ProgID] @DACL=(02 0000) @="dc_ads.ads.1" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\Programmable] @DACL=(02 0000) [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\TypeLib] @DACL=(02 0000) @="{E94C3AF8-D32C-4389-AC9A-BE17471EDC42}" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\VersionIndependentProgID] @DACL=(02 0000) @="dc_ads.ads" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(700) c:\program files\SUPERAntiSpyware\SASWINLO.dll - - - - - - - > 'explorer.exe'(3576) c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\nvsvc32.exe c:\program files\AVG\AVG8\avgrsx.exe c:\progra~1\AVG\AVG8\avgnsx.exe c:\program files\AVG\AVG8\avgcsrvx.exe c:\windows\system32\wscntfy.exe c:\windows\system32\WgaTray.exe . ************************************************************************** . Completion time: 2009-06-11 10:26 - machine was rebooted ComboFix-quarantined-files.txt 2009-06-11 02:26 ComboFix2.txt 2009-06-11 01:29 Pre-Run: 129,100,296,192 bytes free Post-Run: 129,081,024,512 bytes free 212--- E O F ---2009-06-09 03:00 This one file is being stubborn. Download Registry Search by Bobbi Flekman (see the link TITLED RegSearch Download Link)
Windows Registry Editor Version 5.00 ; Registry Search 2.0 by Bobbi Flekman © 2005 ; Version: 2.0.6.0 ; Results at 6/11/2009 11:29:19 AM for strings: ; 'yoog' ; Strings excluded from search: ; (None) ; Search in: ; Registry Keys Registry Values Registry Data ; HKEY_LOCAL_MACHINE HKEY_USERS [HKEY_USERS\S-1-5-21-1547161642-1637723038-839522115-1003\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}] "URL"="http://www2.yoog.com/search.php?q={searchTerms}" "DisplayName"="Yoog Search" ; End Of The Log.Go to Start > Run and type notepad.exe then click OK Copy and paste the below into Notepad and save as fixme.reg to Your Desktop Code: [Select]REGEDIT4 [-HKEY_USERS\S-1-5-21-1547161642-1637723038-839522115-1003\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}] Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry. Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work. Delete the fixme.reg from the Desktop.registry entry was successful.
. ---------- Download Alternate download link Note: Vista users must use Run As Administrator
Note that your system will run slower for a reboot or two after having used this tool so don't panic. Thanks again Evilfantasy. Great great help u did and I appreciate it. My pc is fine now. Your welcome. Safe surfing... too bad no one is helping me.. |
|
| 1630. |
Solve : Spyware apps won't start, browsers redirect? |
|
Answer» he said, Only one Anti-Virus- you can have a NUMBER of anti-spyware/malware apps installed (IE, SUPER anti-spyware and MalwareBytes Anti-Malware)Quote he said, Only one Anti-Virus- you can have a number of anti-spyware/malware apps installed (IE, SUPER anti-spyware and MalwareBytes Anti-Malware)Exactly, because Malwarebytes' is not real-time protection. Quote Antivirus - I'm running Symantec antivirus, which I'm HAPPY with except when it hogs resources when scanning. Do you recommend switching to one of the free ones?Yes, I would recommend removing Symantec and replacing it with avast!. That's my opinion, but many people will agree with me. Quote Antispyware - Only one? It seems like they all catch different things. Is it OKAY to have more than one installed, as long as only one of them is actively monitoring?Like I said above, only one real-time scanner, or as you said - one actively monitoring. Quote Firewall - I just have Windows Firewall.. should I deactivate that and switch to a different one?I'd recommend Comodo. Windows Firewall = scrap. Quote Can I UNINSTALL the programs that I installed in this process and DELETE the logs? My wife's desktop is getting pretty crowded.Yes, all yours. |
|
| 1631. |
Solve : Trojan Horse Injector opening with svchost and iexplorer.exe? |
|
Answer» BASICALLY i think i'm having a malware problem Following the steps now. on the SUPERAntiSpyware step, and doing the full scan. It's been just over an HOUR now, and it APPEARS to be scanning the same few files over and over again... If you reach a point where you think the program is stuck, MAKE a note of it and proceed to the next program. |
|
| 1632. |
Solve : Very odd.? |
|
Answer» Ok, my friend got a virus which killed his computer. (It wouldn't boot up past the "WINDOWS XP" logo. |
|
| 1633. |
Solve : CCleaner how do you see the cookies?? |
|
Answer» I am trying to follow the directions. It SAYS: on the left side you will see the cookies, select this and you will have a list of cookies to keep and cookies to toss out. However many of the boxes contain a green check mark and one of them is "Cookies" I have unchecked the box, double clicked on it and re-checked the box. Please help. |
|
| 1634. |
Solve : autorun.inf on USB and Virus Killing? |
|
Answer» This is my first post, but I am house trained and can generally communicate in a coherent manner. |
|
| 1635. |
Solve : Completed the six steps for malware and still need help...? |
|
Answer» can SOMEONE please HELP me with this? Her are my LOGS: |
|
| 1636. |
Solve : I think my computer is infected with some kinda virus.? |
|
Answer» Okay. My computer has been running very slow as of late. Plus..When I click on a link after doing a google search, I am taken to a PAGE that is totally different than the link I clicked. I ran a few programs such as Spybot, Super anti spyware and Malware bytes. All of which picked up some tracking cookies, but not much more than that. However. When running Spybot, I noticed that the program would freeze while trying to scan Virtumonde.sdn DDS (Ver_09-05-14.01) - NTFSx86 Quote UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.Go to Add or Remove Programs and uninstall: - AutoUpdate - Spybot - Search & Destroy 1.4 <- WAY out of date! - SpywareBlaster 4.0 <- Needs to be updated to Version 4.2 ---------- Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop DO NOT run it yet! Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: Driver:: Tmpmaa8ydhutat bfastfao RootKit:: bfastfao.sys DDS:: mStart Page = about:blank BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - No File IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe AppInit_DLLs: c:\windows\system32\fufoburo,c:\windows\system32\fufoburo.dll LSA: Notification Packages = scecli c:\windows\system32\fufoburo.dll File:: c:\windows\system32\fufoburo.dll 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze ---------- Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to infect your system. Download JavaRa to your Desktop and unzip it to its own folder.
Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update. Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer. I couldn't find anything in add remove programs called AutoUpdate Combofix log Quote ComboFix 09-05-31.02 - johnny 05/31/2009 20:45.1 - NTFSx86 JavaRa.log Quote JavaRa 1.14 Removal Log.
Cleanup steps. Be sure to do these to prevent reinfection. ---------- Download Alternate download link Note: Vista users must use Run As Administrator
Note that your system will run slower for a reboot or two after having used this tool so don't panic. ---------- Download OTCleanIt.exe and save it to your Desktop.
Important: Restart the computer before continuing. Everything seems to be working normally....so far. I've even noticed a difference in speed. Much faster. I can't thank you enough for your time. It is very much appreciated. If I ever have a problem again....I know where I am heading... and will recommend this site to all my friends. Just one question. I'm looking for a solid anti-virus/anti-spyware program. Something that is effective, but doesn't bog down an older PC. Is there such a thing? If so...Please help me out. Thanks in advance. I prefer either Avast or Avira. Remember to only install one antivirus! Avast! Home Free Edition Avira AntiVir Personal Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Again...Thank you very much. |
|
| 1637. |
Solve : Possible spyware on computer? |
|
Answer» Guys |
|
| 1638. |
Solve : Will Avast get rid of a virus?? |
|
Answer» Yes , here's a link |
|
| 1639. |
Solve : Search engines hijacked! Have run...? |
|
Answer» Spybot, ad-aware, malwarebytes, Windows Defender and trend MICRO all say no virui or spyware, even after running them in safe mode. Try doing a Kaspersky Online Scan: I ran the scan and it found one: not-a-virus:AdWare.Win32.Aureate.c in a .zip file from 2005. I don't think that's causing the problem because it just started happening a couple of days ago. Anyone got any more suggestions? Thanks! |
|
| 1640. |
Solve : [Complete] Free License for SUPERAntiSpyware Professional Edition? |
|
Answer» Quote from: 2x3i5x on JUNE 01, 2009, 01:08:06 PM and you were the first to inquire when he's doing the raffle. LOL LOL, I noticed that also. Trust me, I made sure it was completely RANDOM. I do solemnly swear that I faithfully had NOTHING to do with the decision and had no influence what-so-ever on the decision made by evilfantasy or any third parties. I mixed the order of the names that I had LISTED and then randomized them. I wanted to be sure that the first name on the list of diggers wasn't the first name on the random.com list. I figure that's about the best I could do... This is how they went in. naters0913 KingDoomed StarLiteMedia justinlutzfl DeathStalker2 shaly777 JHenderson81 computeruler 2×3i5x Karnac1 DeathStalker2 Fordy101 *Unsticking topic I've already heard from the SAS guys and I should be doing this again in a few weeks. Thanks again everyone!ooooo! I hope I win next time! Can you pm me if I dont reply and dont see the post or anything?I'll probably split a post from this topic so when I reply everyone will get an email.I dont get emails when there are new posts or anything. I use the new reply things but ok. |
|
| 1641. |
Solve : help can't remove trojan horse agent2.fmq virus and its killing me? |
|
Answer» You can use CCleaner to remove Cookies. They aren't dangerous so no need to worry over them.
---------- Go to Microsoft Windows Update and GET all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security ADDON for your browser. It will KEEP you safe from online scams, identity theft, spyware, spam, viruses and UNRELIABLE shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.thank you so much for your help anyone reading this should take his advise, and stick with it. I had 187 trojan horse viruses that all came in one shot and he helped to removal all of them without causing me to lose any info or have a system crash.Your welcome. Safe surfing... |
|
| 1642. |
Solve : Unwanted E-mail? |
|
Answer» I keep getting UNWANTED spam In my E-mail. I tried going to message and block sender In my outlook express but The e-mail changes Its name every time. |
|
| 1643. |
Solve : Computer Acting weird (logs attached)? |
|
Answer» My computer has been acting really slow lately. It has really been acting up lately. ALSO, my internet has been acting SLOWER than usual. Please HELP! |
|
| 1644. |
Solve : Malware Help Needed (AVG won't update / websites redirecting)? |
|
Answer» Trying to fix a family member's computer, DEFINITELY have some sort of virus. First noticed that certain websites were randomly redirecting to odd pages, and AVG would not be allowed access to the update server. Tried to install some anti-malware programs (SuperAntiSpyware, Malwarebytes, etc) but have not yet been able to eliminate the problem. Was hoping that I could get some help. |
|
| 1645. |
Solve : Tommypauly-Malware Removal-(Logs)? |
|
Answer» I followed the steps in the "Read here before..." thread and here are my logs:
Important: Close all windows except for HijackThis and then click Fix CHECKED. Exit HijackThis. ---------- You have Viewpoint installed. Viewpoint Media Player/Manager/Toolbar is considered as Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". More information: . It is suggested to remove the program now. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.
---------- Malwarebytes and SUPERAntispyware are way out of date on the version numbers. Open Malwarebytes' Anti-Malware.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. ---------- You are way out of date with your version of SUPERAntiSpyware. * Please uninstall your current version. <- This is important! * Download and install SUPERAntiSpyware Free for Home Users * After installing the new version, it may tell you that you need to reboot to complete the installation. You must reboot at this time! * After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get any available updates. * Now run a new full scan of your system. * Post the log in your next reply. |
|
| 1646. |
Solve : malware smartbizsearch-com help- DNS change, pop up, spybot & mbam doesnt work? |
|
Answer» Hello. im really tired trying to clean this redirect. I really need help. |
|
| 1647. |
Solve : Trojans wont let me go to anti-malware web addresses!!? |
|
Answer» Hello y'all, newb here with first post.
--> FIL\\\?\C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\TEMP\AVSCAN-20090531-094504-7F1BF2A5\AVSCAN-00000005.dll [DETECTION] Contains a recognition pattern of the (harmful) BDS/TDSS.JW back-door program C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\TEMP\AVSCAN-20090531-094504-7F1BF2A5\AVSCAN-0000000A.sys
--> FIL\\\?\C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\TEMP\AVSCAN-20090531-094504-7F1BF2A5\AVSCAN-0000000A.sys [DETECTION] Is the TR/Rootkit.Gen Trojan The repair notes were written to the file 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\AVSCAN-20090531-094623-9003C82F.avp'. c:\windows\system32\tdsscfub.dll [INFO] The file is not visible. [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] The file was deleted! c:\windows\system32\drivers\tdsspaxt.sys [DETECTION] [NOTE] The file was deleted! c:\windows\system32\tdssfpmp.dll [INFO] The file is not visible. c:\windows\system32\tdssnrsr.dll [INFO] The file is not visible. [DETECTION] Contains a recognition pattern of the (harmful) BDS/TDSS.adb back-door program [INFO] No SpecVir entry was found! c:\windows\system32\tdssoeqh.dll [DETECTION] [INFO] No SpecVir entry was found! c:\windows\system32\tdssosvn.dat [INFO] The file is not visible. c:\windows\system32\tdssrhym.log [INFO] The file is not visible. c:\windows\system32\tdssriqp.dll [INFO] The file is not visible. [DETECTION] Contains a recognition pattern of the (harmful) BDS/TDSS.acs back-door program [INFO] No SpecVir entry was found! c:\windows\system32\tdsstkdv.log [INFO] The file is not visible. c:\documents and settings\chaka\local settings\temp\tdss8d6f.tmp [INFO] The file is not visible (shell). [DETECTION] Is the TR/Patched.CL Trojan [INFO] No SpecVir entry was found! End of the scan: Sunday, May 31, 2009 09:46 Used time: 01:23 Minute(s) The scan has been done completely. 0 Scanning directories 10 Files were scanned 6 viruses and/or unwanted programs were found 0 Files were classified as suspicious: 2 files were deleted 0 files were repaired 0 files were moved to quarantine 0 files were renamed 0 Files cannot be scanned 4 Files not concerned 0 Archives were scanned 0 Warnings 2 Notes 51894 Objects were scanned with rootkit scan 15 Hidden objects were found The issue I am having is ANY web browser I use (Firefox 3.0.10, IE 8, or Opera) will not let me connect to ANY anti malware sites. I get a 'could not connect to.....' prompt. I had AVG, but trojan would not let me update definitions. I have MaxPC cd with Superantispyware and MALWAREBYTES, but cannot install, says files are corrupt (only these 2 of course!). ALL Google inquires are redirected to malware sites or Apartmentfinder on all browsers. I deleted and/or Quarantine through the anti virus but they come back upon reboot. I suspect AV is compromisedjavascript:replaceText('%20>',%20document.forms.postmodify.message); I am at wits end and out of options EXCEPT format, but do not have XP cd so this is my only hope! [attachment deleted by admin]update Was able to run hijack this Logfile of HijackThis v1.97.7 Scan saved at 12:23:20 PM, on 5/31/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe e:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe E:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe C:\WINDOWS\system32\nvsvc32.exe F:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe E:\apps\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = cdn O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.6.14.dll O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O11 - Options group: [INTERNATIONAL] International O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20070711/qtinstall.info.apple.com/qtactivex/qtplugin.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/ActiveX/VMRCActiveXClient1.cab O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - O17 - HKLM\System\CCS\Services\Tcpip\..\{C9F18C6A-744A-4A9B-A644-74ADAA6E8121}: NameServer = 208.67.222.222,208.67.220.220 O17 - HKLM\System\CCS\Services\Tcpip\..\{EF2FA76B-F1B8-49B8-B1D0-A18671B3A868}: NameServer = 208.67.222.222,208.67.220.220 Was able to download malwarebytes but freezes on install. adaware and spybot will not let mu update. |
|
| 1648. |
Solve : Please review logs (recommended by forum members)? |
|
Answer» HERE is the thread where I was told to POST in the Malware section. |
|
| 1649. |
Solve : How about a game of nine-ball ?? |
|
Answer» Nine Ball, a recent multi-layered Web browser ATTACK that, combined with Gumblar and Beladen, have already infected approximately 140,000 sites collectively. |
|
| 1650. |
Solve : I have no clue what im doing? |
|
Answer» Do this first.
* Copy and paste that log in the next replysorry this has taken so long..new hours at work! 11074468.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11094796.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11095406.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11096000.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11096312.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11097015.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11098234.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11098328.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11098421.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11099890.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11099953.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11100156.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11100234.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11100343.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11100437.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11100562.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11100703.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11100765.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11100796.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11100859.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11100906.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11100953.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11101031.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11101078.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11101109.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11101156.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11101203.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11101281.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11101437.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11101531.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11101609.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11101703.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11101765.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11101828.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11101875.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102062.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102218.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102265.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102296.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102343.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102390.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102437.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102484.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102515.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102562.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102593.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102640.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102671.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102718.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102781.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102843.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102875.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102921.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11102968.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11103984.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11104156.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11104281.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11105031.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11106062.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11106328.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11107390.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11107531.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11125140.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11126156.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11132500.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11132687.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11132921.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11133093.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11133328.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11133375.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11133421.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11133468.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11133500.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11133546.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11133593.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11133640.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11133703.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11133750.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11133796.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11133843.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11133875.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11133937.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11134078.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11134109.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11134156.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11134218.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11134250.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11134296.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11134343.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11134437.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11134515.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11134562.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11134609.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11134656.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11134703.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11134750.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11134796.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11134859.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11134890.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11134953.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11135078.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11135140.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11135187.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11135250.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11135312.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11135390.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11135453.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11135546.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11135609.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11135687.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11135750.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11135828.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11135953.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11136000.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11136140.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11136218.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11136250.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11136296.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11136359.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11136406.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11136453.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11136515.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11136578.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11136625.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11136703.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11136750.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11136796.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11136890.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11136968.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11137046.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11137218.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11137281.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11137328.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11137390.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11137453.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11137500.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11137578.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11137625.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11137671.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11137718.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11137843.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11137953.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11138000.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11138093.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11138140.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11138218.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11138265.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11138312.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11138359.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11138406.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11138453.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11138515.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11138562.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11138625.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11138734.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11138781.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11138828.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11138906.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11138953.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11139015.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11139203.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11139296.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11139343.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11139406.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11139453.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11139515.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11139562.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11139625.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11139750.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11139796.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11139859.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11139921.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11139984.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11140046.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11140125.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11140187.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11140265.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11140375.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11140500.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11140562.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11140656.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11140750.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11140812.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11140859.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11140953.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11141171.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 11141281.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.; 06990266.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.52774;Deleted.; 09420408.FIL;D:\$VAULT$.AVG;Adware.ClickSpring;; 15784188.FIL;D:\$VAULT$.AVG;Modification of BackDoor.Generic.1699;; 15784829.FIL;D:\$VAULT$.AVG;Modification of BackDoor.Generic.1699;; 29400078.FIL\data003;D:\$VAULT$.AVG\29400078.FIL;Adware.Sonetads.1;; 29400078.FIL;D:\$VAULT$.AVG;Archive contains infected objects;; 29400421.FIL;D:\$VAULT$.AVG;Trojan.DownLoad.1015;Deleted.; 29400593.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.56730;Deleted.; 76061671.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.; 76061906.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.; 76061968.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.; 76331203.FIL;D:\$VAULT$.AVG;Adware.Maxifiles;; 86893687.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.; 86893906.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.; 86893968.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.; 86919571.FIL;D:\$VAULT$.AVG;Trojan.MulDrop.5530;Deleted.; 86920243.FIL;D:\$VAULT$.AVG;Win32.HLLW.Pytica;Deleted.; 86920368.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.; 86920680.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.; 86920774.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.; 86920821.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.; ComboFix.exe/data002\32788R22FWJFW\psexec.cfexe;D:\Documents and Settings\Linda\Desktop\ComboFix.exe/data002;Program.PsExec.171;; data002;D:\Documents and Settings\Linda\Desktop;Archive contains infected objects;; ComboFix.exe;D:\Documents and Settings\Linda\Desktop;Container contains infected objects;; SDFix.exe\SDFix\apps\Process.exe;D:\Documents and Settings\Linda\Desktop\SDFix.exe;Tool.Prockill;; SDFix.exe;D:\Documents and Settings\Linda\Desktop;Archive contains infected objects;; alisha keys superwoman.mp3;D:\Documents and Settings\Linda\My Documents\LimeWire\Saved;Trojan.WMALoader;Cured.; system.dll.vir;D:\Qoobox\Quarantine\D\Program Files\COMMON~1\{10B7B~1;Trojan.DownLoader.18142;Deleted.; system.dll.vir;D:\Qoobox\Quarantine\D\Program Files\COMMON~1\{10B7B~2;Trojan.DownLoader.18142;Deleted.; Process.exe;D:\SDFix\apps;Tool.Prockill;; A0000824.exe;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP14;Tool.Prockill;; A0000928.exe;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP14;Tool.Prockill;; A0001043.exe;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP14;Adware.Maxifiles;; A0001145.dll;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP17;Trojan.DownLoader.18142;Deleted.; A0001146.dll;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP17;Trojan.DownLoader.18142;Deleted.; A0001160.EXE;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP17;Program.PsExec.170;; A0001161.dll;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP17;Trojan.DownLoader.18142;Deleted.; A0001162.dll;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP17;Trojan.DownLoader.18142;Deleted.; A0001163.dll;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP17;Trojan.DownLoader.18142;Deleted.; A0001164.dll;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP17;Trojan.DownLoader.18142;Deleted.; OK how is the computer running now?rediculously slowI don't think it's malware. Try doing a disk cleanup and defrag to see what that does.dno what that is or how to do itDelete temporary files Go to:
Check the boxes for:
Click OK or Enter Restart the computer. ---------- You can use the built in Windows Defrag by clicking Start > Run and then type in dfrg.msc then click OK. Or use a faster FREE program. Defraggler is very effective and easy to use. the choices i got were recycle bin, system restore: obsolete data stores and catalog files for the content indexer do those?Here, this is automated. Download ATF Cleaner by Atribune and save it to your Desktop. Alternate Download link Windows Vista users:ATF-Cleaner must be Run as an Administrator Double click ATF-Cleaner.exe to run the program. Check the boxes to the left of:
Now click Empty Selected When you get the Done Cleaning message, click OK Firefox users click Firefox on the menu bar Click on Select All, then click Empty Note: If you want to keep your saved Passwords click No on the prompt. Opera users click Opera on the menu bar Click on Select All, then click Empty Note: If you want to keep your saved Passwords click No on the prompt Note that your system will run slower for a reboot or two after having used this tool so don't panicMy wife's computer lost sound about 2 years ago. I worked with a Windows XP Escalation Engineer who took me under his wing so to speak. Her system is a Systemax with licensed software for their proprietary systems: no windows disc came with the system. If you go to controll panel > sounds > and it is grayed out and defaults to a modem that you may not have installed, the issue is a dropped Windows driver. To fix the problem get a "clean" windows disc. If you don't have one Microsoft will send you a replacement. The Utilities disc manufacuters send with their systems ~ will not work! In save mode insert the disc and check "Repair"; be sure and check your BIOS to see if it is set to auto start [yes]. The disc will reload all the drivers necessary. Be sure to down load new audio drivers [Audio 97 or disc prompt] to a folder on your desktop - it's easy to find there. While the repair is patching files, for each file that it requests a disc to be inserted to load a specific dynamic link library .dll file, make note and download those as well. After you are prompted - reboot, and download those files that the Windows disc asked for during repair. Once you have downloaded and installed the requested file updates, reboot and your problem will be solved. Just a note: systems with factory installed Windows are problematic and without a legit version of Windows XP, your problem is there to stay. My only problem now is keeping my wife's volume turned down....If I can be of further assistance let me know. That problem was persitant. |
|