Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

351.

Solve : Spy assassin issues with charter internet suite?

Answer»

I recently removed my Charter Security Suite (F-Secure) from my computer and tried to reinstall it.  It ended up going into a loop trying to prepare the computer for installation.  After calling Charter, they said that I had Spy Assassin in my hpkey area in regedit.  I'm wondering how to fix the problem and make it so I can have my ISP's security suite installed.   Please HELP!

Thanks!Stephen Greene.....Go into the registry , use the search feature and search for "Spy Assassin "  remove any entries it FINDS ......( you will probably have to run search more than once as THER are probably multi entries .)

Be SURE to BACK up you registry before removing any entries just in case you foul up .

dl65  Thanks for the tip...I'll try it!

352.

Solve : What is this error message??

Answer»

Running windows ME.  This error message keeps popping up from Microsoft Internet Explorer
Cannot FIND http://www.loadingwebsitecomnormalyyy65.html.  Make sure path or internet address is correct.
            ok
click ok then it goes to web results ( search page)
How do I get rid of this?
THANKS!!! :-/
AVG Free
-- Anti virus scanner
Adaware SE PERSONAL
-- Anti spyware scanner
Microsoft Antispyware
-- Anti spyware scanner. Windows XP Home and Professional only.
Spybot Search & DESTROY
-- Anti spyware scanner
ZoneAlarm Free
-- Free firewall - more user friendly
Sygate Personal
-- Free firewall - more configuration options

353.

Solve : destop backround message?

Answer»

ok i have a message on my backround of my destop it WONT let change my backround its like its stuck there this is what it says

system stopped

system has been stopped due to a serious melfunction.
              sptware activity has been detected.

it is recommed to use spyware removel tool to prevent data loss.
       do not use before all spyware removed.

an behind that i CANT read it cause this blocked it but it something about securtiy alert an it was all blue. but i had a virus on my CPU that i got off just RECENT so i thought that had something to do with it but anyway people told me just run ad-ware an that should get rid of it but it didnt i am just confused an its annoyin sometimes i need help if u need any more info. just ask

thank youbilly.....  If you have win xp as an o/s ...I would suggest D/L M/S Antispyware ..........
http://www.microsoft.com/athome/security/spyware/software/default.mspx  
I would then shut off the system restore feature .
Then I would suggest rebooting into safe mode and do the following ....run a scan with your antivirus scanner then run a scan with antispyware .........and then run a scan with ad-Aware .......... when your done and have removed anything that was found reboot back into normal mode .

dl65  i have that anti spy ware on my cpu an it only has been detection BROWSER hi jacks any other suggestions u guys might have cause this backround message it does get annoyin after a while an every other help site does nt help any they just say the samething so any suggestions

thanks again   Quote

an it only has been detection browser hi jacks


Your spyware scanner should not notify you of such events, because the events in question should not even be there.

Quote
any they just say the samething so any suggestions


They all say the same because you're not looking deep enough into the problem.

AVG Free
-- Anti virus scanner
Adaware SE Personal
-- Anti spyware scanner
Microsoft Antispyware
-- Anti spyware scanner. Windows XP Home and Professional only.
Spybot Search & Destroy
-- Anti spyware scanner
ZoneAlarm Free
-- Free firewall - more user friendly
Sygate Personal
-- Free firewall - more configuration options
354.

Solve : Icons on desktop Change?

Answer»

What would make my Icons on my desktop just change out of no where?Did this happen on a re-boot!Download, install and CONFIGURE the following applications:

AVG Free
-- Anti virus scanner
Adaware SE Personal
-- Anti spyware scanner
Microsoft Antispyware
-- Anti spyware scanner. Windows XP Home and PROFESSIONAL only.
Spybot Search & Destroy
-- Anti spyware scanner
ZoneAlarm Free
-- Free firewall - more user friendly
Sygate Personal
-- Free firewall - more configuration options

355.

Solve : AVG routine scan?

Answer»

Hey Everyone,
I ran a ROUTINE avg virus scan this a.m.....no virus found!
When I looked at the test results, the last five items listed were as follows:

C:WINDOWS/SYSTEM32/kernel32.dll
C:WINDOWS/SYSTEM32/wsock32.dll
C:WINDOWS/SYSTEM32/user32.dll
C:WINDOWS/SYSTEM32/shell32.dll
C:WINDOWS/SYSTEM32/ntoskrnl.exe

At the top of the page under "results" all the way down has "ok" listed, but when it GOT to these last five items, instead of "ok" it says "change" and then under "status" for these last five items it says "changed".  

Is this something to be alarmed about?  I did recently remove the 40gb hdd and replaced it with a new 80gb, and then reloaded os xp-sp2. I was WONDERING if this may be the cause of the "changed" status.?

Any feed back would be greatly appreciated!
Thanks

run a spysweeper......program like adaware/spysweeper etc......these references seem to point to IE.??.... or .some program maybe trying  to alter your registry.......Here are descriptions of those processes... Also, YOU DO HAVE A VIRUS!!!

ntoskrnl.exe --- http://www.processlibrary.com/directory/files/ntoskrnl/index.php

kernel32.dll  --- TROJAN! http://www.processlibrary.com/directory/files/kernel32/index.php

wsock32.dll  --- http://www.processlibrary.com/directory/files/wsock32/index.php

user32.dll  --- http://www.processlibrary.com/directory/files/user32/index.php

shell32.dll  --- TROJAN! http://www.processlibrary.com/directory/files/shell32/index.php

Remove the trojans as soon as possible!

[glb]Flame[/glb]http://www.majorgeeks.com/downloads31.html   Thank-you for your responses....I'm currently have
AVG
Spybot
Ad-Aware SE
CCleaner
CW Shredder

on my pc.  I ran AVG----no virus came up
Spybot--also clean
While I was running Ad-Ware, AVG popped up and said it detected a Trojan HORSE.  I quarantined it and let the scan finish then went into Vault and deleted it.  Re-ran everything and all came up clear.  Is there a specific file to look for in Registry, H-Keys that would determine if it is actually gone?  Seems like thats where I went one other time when I got a virus and deleted the file.

Thanks for your help!your ok.......avg///and the rest have scanned the reg....clean bill of health.....go surfing.......mind the water is hot THANK-YOU MERLIN_2!

I feel much better now!
Really appreciate the help!no problem........we aim to please...the family forum of the net.....You should install a firewall as well. Quote

When the System Areas Test detects a change, the Accept changes button is made available. Click it if you want the amended object to be incorporated in the System Areas Test database. If you do not accept the changes then AVG Free will alert you the next time you run the System Areas Test again.


Does anyone know where the button is?  DO NOT REMOVE
kernel32.dll or shell32.dll, they are not trojans but important windows files.(Marlene should know that becuase of the links)  

[glb]Flame[/glb] Quote
kernel32.dll  --- TROJAN!
shell32.dll  --- TROJAN!

Reading the links is how I found out, I hope Marlene reads them.That's why I put them there!  

[glb]Flame[/glb]But where's the button to accept the changes
356.

Solve : Comp Restore.. ugh?

Answer»

ok.. heres my problem.

my stupid friends downloaded all kinds of crap on my computer, and it installed over 6000 infected files on my computer. spyware, adware.. all that. i deleted and quarantined all infected files, and in about an hour, they would all come back.. so compaq told me my best option was to restore the computer

after restoring the computer, it goes into the "new computer setup" and halfway through that, it FREEZES..

i've tried putting in all the factory cards etc, but it STILL goes to that screen when i restore the pc.. i dont know if this can be fixed.. it might be screwed.

oh, and i already tried restoring it again.. same prob..

any help would be lovely tho..Restore?! LOL  Here's the BEST option.. Go buy a REAL operating system CD, and Fdisk the drive, and install the operating system from the CD... Not from those crap restore CDS...

[glb]Flame[/glb]Take the following steps:

1. Format Hard Disk Drive
2. Reinstall Windows XP
3. Take security measures before connecting to the Internet.

Make use of the following (free) programs:

AVG Free
-- Anti virus scanner
Adaware SE Personal
-- Anti spyware scanner
Microsoft Antispyware
-- Anti spyware scanner. Windows XP HOME and Professional only.
Spybot Search & Destroy
-- Anti spyware scanner
ZoneAlarm Free
-- Free firewall - more user friendly
Sygate Personal
-- Free firewall - more configuration options
But go out and BUY Windows XP. No more of this restore stuff...

[glb]Flame[/glb]Sometimes, the restore DISKS contain a full and legit copy of an operating system. Don't judge a book by it's cover. In this case, the CD.

357.

Solve : Can't delete infect file? help please?

Answer» UM i have windows XP home and installed norton antivirus 2004 on it. for some reason auto protect keeps detecting a downloader.trojan something like that in a file called ms3fs.dll and so i SEARCHED the file but it wont let me delete it manually either ive searched bunch of .dll download sites and cant FIND it need soem help PLEASE having this thing pop up eveyr 5 mins is annoyingYou could shutdown the pc.......disconnect form the net ......restart pc in safe MODE and delete it.....download spysweeper......norton is not that good.....at trojans.........or trojanhunter or swatit
358.

Solve : Conflicting Software??

Answer»

Hello all! I recently saw in the newspaper that having two firewalls OR virus protection applications could be dangerous, becuase they will ocnflict with each other... Is this true, or just the usual crap that they put in the newspapers?

[glb]Flame[/glb]ZoneAlarm firewall asks you wheter it should disable the Windows XP firewall or not. To the user it may be dangerous as they may receive conflicting error reports when SOMETHING has been blocked or is asking for PERMISSION to connect to the Internet but what danger could there be for the actual software?What I mean is this... The new computer cam with McAfee Virus scan... I'm going to install norton, but do not want to UNINSTALL McAfee, becuase it raised *censored* on my old computer... So If I leave Norton and McAfee on at the same TIME, will they conflict? The paper says that they might weaken each other, making you less secure. Will that happen with Norton and McAfee if they are both on at the same time?

[glb]Flame[/glb]You can E-mail both technical support sides to see what they know.

I myself use only one software firewall and a hardware firewall. Bound to be compatible.I would ask Notron support, but those pigs charge you for the chat...    Oh Well, I can always ask Dell and Gateway... I'll keep everyone posted as to the results...

[glb]Flame[/glb] Quote

What I mean is this... The new computer cam with McAfee Virus scan... I'm going to install norton, but do not want to uninstall McAfee, becuase it raised *censored* on my old computer... So If I leave Norton and McAfee on at the same time, will they conflict? The paper says that they might weaken each other, making you less secure. Will that happen with Norton and McAfee if they are both on at the same time?

[glb]Flame[/glb]


Anti-virus programs are loners......so to speak .....They tend to be more effective on their own. Sometimes they do not peacefully co-exist .  
As far as McAfee raising *censored* with your old pc.........I suspect that it was something you removed ... (ie a shared file which was being used by another app ) .
I have removed both McAfee and Norton from a number of machines and have never had any problems .....other than they both leave remnants all over the place .....That is for example why Norton has a separate removal app to cleanup bits and pieces .  
If you go into the registry and do a search for either of these applications ......I'll bet you , you will find a number of entries still left behind.  ( But then that happens with many programs)

As far as Norton charging you to "chat" .......  They do not charge for issues which are directly related to their software .   They will however charge for calls which are just general in nature.....( this is done to attempt to avoid niusense calls) .  I have had occassion to phone Norton re software issues with their products and they are very upfront about what support they will provide . If you have a legit problem with their products .......you WILL NOT be charged .........  
The issue of charging was put in place to attempt to discourage users from simply picking up the phone and tieing up their techs to correct issues which have nothing to do with Norton products.
In case you havent noticed .........people are lazy , instead of doing a bit of research into the problem they simply throw up their hands and reach for the phone .....

Norton , as well as McAfee have websites , which are there to help . Granted they are not always the easiest to navigate but in many instances the info is there ........

So , in conclusion , I would suggest using just one anti- virus .  You decide which one you want and then remove the other. ( completely )

dl65  



yeah. I'll just uninstal McAfee... Hate it LOL ... I like the firewall, but hate the virus protection...    Thanks! I'll give this a quick shot  

[glb]Flame[/glb]You should try the AVG & Sygate combination, I'm sure you'd never go back to Norton or McAfee.
A lot of people swear by ZoneAlarm too but I find it a little confusing to use.Thanks for the replies guys! I asked Dell, and of course, tehy want me to just uninstall McAfee... What I'll do is uninstall The virus scan and keep the firewall. Thanks guys!

[glb]Flame[/glb] Quote
You should try the AVG & Sygate combination, I'm sure you'd never go back to Norton or McAfee.
A lot of people swear by ZoneAlarm too but I find it a little confusing to use.


ZoneAlarm is less comprehensive than Sygate.
359.

Solve : cannnot get rid of this crap!?

Answer»

did a bunch of scans and cant GET rid of this crap. i did virus scans and i got this:
     C:\RECYCLER\S-1-5-21-1808560551-582679745-3550151506-1009\Dc52.zip>setup.exe (Win32.Alcan.C worm)
     C:\RECYCLER\S-1-5-21-92293205-724865188-1590635369-1009\Dc181.zip>setup.exe (Win32.Alcan.A worm)

it SAYS its DELETED but its not cuz when i restart its back.steve t..... Make sure that you have you folder options set to show hidden files ..........You should then be able to rescan and hopefully remove the pests .....


dl65  Operating System? Quote

it says its deleted but its not cuz when i restart its back.


You will have to locate and remove the source that causes the threats to reoccur.

AVG Free
-- Anti virus scanner
Adaware SE Personal
-- Anti spyware scanner
Microsoft Antispyware
-- Anti spyware scanner. Windows XP Home and Professional only.
Spybot Search & Destroy
-- Anti spyware scanner
ZoneAlarm Free
-- Free firewall - more user friendly
Sygate Personal
-- Free firewall - more configuration options
disable system RESTORE and scan again.....or safe mode

info....when you empty the trashcan....a folder called recycler keeps it....just in case you have deleted a file...that winxp may need.....
360.

Solve : Windows xp and norton internet security?

Answer»

I just installed windows XP. An upgrade from ME. I cannot start Norton Internet Security now. Do I need to re-install Norton?You SHOULD, yes.

[glb]Flame[/glb]ThanksSure! Come on back if you have any other questions!

[glb]Flame[/glb]you should stuck with WINME..
my two cents worth!I did not want to buy a new OS. ME was GIVING me problems. I have been told that ME is not a good OS and that I should upgrade. I was not AWARE of any problems with XP and Norton.Don't worry, Merlin's getting old.

Thanks.
I still cannot use Norton IS. I have been in touch with Symantec and they provided some SOLUTIONS, None of which have worked yet. THe next step is to upgrade to Norton IS 2005.I suggest that you reinstall Norton if you have not yet done so. It may be damaged due to the upgrade from ME to XP.

361.

Solve : Active Protection?

Answer»

What active protection are people using and why?
For me it's...

AVG: Free, low overheads, easy updates, no conflicts, simple to use, has a scary virus alert picture.
SYGATE: Free, simple to use, gives GOOD control & information.
WINPATROL: Free, simple to use, the barking dog.

Needless to say I have all the other anti-everything scanners but only the 3 above are active.What is WinPatrol?

I make use of the following:

Kaspersky Anti Virus 5.0 Personal Warez. Would SWITCH to AVG Free. But works too well for the time being.
Sygate Personal Allows for better CONFIGURATION than the free VARIANT of ZoneAlarm. PROGRAM control. Qtec Router filters out everything else.
Windows Antispyware Novelty application.
Qtec Router Firewall Nothing gets through.http://www.winpatrol.com
Make sure your sound is turned up to hear the dog bark.I will look into this application, thank you.

Has it worked succesfully for you?It works fine, easy access to hosts file, lock & unlock hosts file, alert when something tries to change the registry and don't forget the dog barks too.
Plus other stuff.It detects nothing out of the ordinary on my system. Useful tool to manually remove threats should scanners fail.I leave it running, is something tries to write to the registry it alerts you with a screen like spybot does.
You then get a choice to allow or disallow.Does it do so with all changes made in the registry?Only new startup changes I think, now I'm going to have to find out    I shall let you know when it detects change on this system.Right click on the dog to check out the toys.I had it neutered. Woof. Quote

I had it neutered. Woof.


LOL ...... I had mine spayed ........... Doesn't bark as much now .

dl65  
362.

Solve : Mcafee: suspicious script detected.?

Answer»

I use mcafee security and there is a problem with the HELP file HELPCTR.EXE at C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\HELPCTR.EXE

Whenever i go to start/help/search online support
mcafee says a suspicious script has been detected.

And HELPCTR.EXE is causing lots of errors like this:
Whats wrong, should i just delete it?This sould NOT be CONSIDERED a suspicious script... See this link for INFORMATION... http://www.processlibrary.com/directory/files/HELPCTR/index.php ... The link will also give you removal instructions... I hope this helps!

[glb]Flame[/glb]I have just deleted it, if it wasnt realy a bad script it still caused errors...Alright. Happy computing! (Sounds cheezy eh? just trying it on. lol )

[glb]Flame[/glb]C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\HELPCTR.EXE   was a main part of the windows help PROGRAM........and mcfee no comment.....norton use to throw this message up also.......if it in the recycle bin resore it.....its not malicousIts gone now, i dont use it anyway, just wanted to see if it was something like a virus or not.

363.

Solve : Unwanted up keeps opening on my navigators?

Answer»

Hello, I have been having some problems with my navigators recently (safari and chrome). It all started when I downloaded several third-party apps to try to recover some important files I deleted accidentally. The apps were all safe, except for one that Google warned me about (I don't remember its name or where I downloaded it from, I was desperate at the moment).
Google said it could be malware and that it would try to add extensions to Chrome, however, I thought it was the general Google kind of warning.
However, now I am having troubles with an unwanted tab opening up every time, it doesn't lead to anywhere, it just opens and then closes automatically. I deleted and reinstalled Google Chrome, deleted all extensions, reset Chrome, ran Malwarebytes Anti-malware for mac (it found some issues at first, I got rid of them. Now when I run Malwarebytes it says it did not find any malware), none made a difference.
I deleted cookies and cache from Chrome, and now the unwanted tab won't OPEN, but there is always this warning on the top right "This page is trying to load scripts from unauthenticated fonts."
Another THING that worries me is that there are some files on Finder that did not APPEAR before (it looks like their opacity icon is down as if they were not real folders as if they were hidden). For example, when I open my external HD on Finder, there are 4 files like this (.com.apple.timemachine.donotpresent ; .fseventsd ; .Spotlight-V100 ; .Trashes ; this last one, .Trashes, has an arrow icon on the bottom right of the folder icon, as if it said the folder is being downloaded, also it won't let me open the .Trashes file, it says I have no permission to see its content).
I am worried because I work with this computer, I do freelance with video editing, so I am afraid it might damage my mac or storage devices, make me lose important work, or even get hold of important info as account passwords.
If you guys could help me, it would be the best thing ever hehe, I am really desperate about this.You are using a MAC with Apple OS.
As FAR as I know there isn't a nice automated way to provide t System RESTORE as it is in  Windows. Too bad.

So your best option is to restore from a backup you have made earlier.

If you do not have a backup, now is the time to make one. Bedsore you go an further, make a full backup. Hopefully it can be used to help fix the problem later or help if things go from bad to worse.

Hindsight. Anytime you are about to do anything that might make thugs go downhill, you need to have some kind of backup or recovery plan already in place.

If you have the time and resources, try this:
A. Get a new or used hard drive you trust.
B. Install the new drive  with the Mac OS you have.
C. Hook up your old drive as a external slave.
D. Try to get what you need from the  old drive. And do not erase the old drive until you are sure everything is working perfectly.

That is the best I can offer.
The alternative would be to take it to an expert technician who really knows what he is doing.

364.

Solve : Is there an Anti Virus that uses minimal amount of memory??

Answer»

Hello

I have resurrected an old Acer Aspire D255 netbook to take on a trip instead of my laptop.
I am upgrading the memory from 1 to 2 gig ram, installed a 60 gig SSD, loaded WIN 7 32 bit Home Premium.  Everything except the 2 gig ram I had laying around my house collecting dust and with Win 7 it actually runs pretty good.

I am looking for an Antivirus program that uses a minimal amount of memory (2gig is not very much nowadays).  I wont be doing much with the netbook mainly surfing and some word processing, but will be connecting to public WiFi.  Will the new types of Antivirus automatically adjust to the amount of available memory?I recommend MicroSoft Security Essentials. It's lite weight and unobtrusive.

MicroSoft Security Essentials   All versions and all languages.Thank you so much for the app RECOMMENDATION and to this thread!

365.

Solve : What is flash32_29_0_0_171.ocx??

Answer»

Hello,

I was visiting https://www.huggies.com.au, and had a message pop up at the bottom saying this website WANTED to run the following add-on: flash32_29_0_0_171.ocx. I left, and came back to the website, and had a similar message appear, except it says it want to run Adobe Flash Player.

This website should be safe, and I've seen this message asking for Flash Player add-on to run, but not the other. It also seemed odd that the popup changed what it was asking to run.

ThanksThe site opened for me with no problem so it's just SOMETHING program that is missing from your computer.Alright, thanks.You're WELCOME. I will lock this thread. If you need it re-opened, please send me a PM.

366.

Solve : Router, wifi and PC?

Answer»

Hi! I really need to make sure, by tomorrow, that my wired connection and PC are safe when I give out wifi PW(I have to..)

If someone has wifi pass and access directly to network they can only access the wifi transmission part and if I don't send any traffic via wifi and if I disable the router page from wifi connection so they cant make changes, then my PC itself and its traffic is safe, while I'm on wire?

Say my router itself or other devices connected to it or wifi or anything related to the router is compromised, or someone knew default router page PW, the router was reconfig, ath.

So, I'd need to disable the  rotuer config page for no one to be able to make changes via wireless and sth about enabling wireless isolation? Is that the guest network part or is it sth ADDITIONAL? If I cant make a guest network can I still enable wireless isolation to isolate wireless form wired or ath else to protect wired from wireless.

So I did this:
I enabled hide network on SSID 1(my future to be protected network, tho i am on wire now and will use wire) and enabled it;s isolation. Should I have done that to SSID 1 or to SSID2? or both?
https://imgur.com/a/r06K1HM

SSID 2 I enabled. Should I have enabled isolation for it too? Or just it and not SSID 1?
https://imgur.com/a/tycZPsK

Is this a true guest network that would separate my pc and wire from wireless?

I cant really check as I have no other device I trust not compromised to check.
I have a ZTE ZXHN H108n router modem adsl

If I enable no changes to router page by wireless and isolation, my wired is safe? No other ways to get in or see my traffic or hurt my PC itself? If this isn't truly a guest network the multiple SSIDs, can I still isolate wireless from wired and keep wired and PC safe?

Thanks!!Best way to make wired safe is to have a separate wireless router for those using wifi that your giving the wifi password out to from that of the other router that the PC will be connected to. This will give you a hardware firewall between the 2 networks and isolation. This is the setup I use to be able to give people access to my wifi at home and have my stuff SECURE and isolated from the one that is SHARED with others.

Basically you have your modem with a router connected to that. Then have ANOTHER second router connected to a port on the first router. Put people onto this router second one in, if anyone gets onto that network they can only see traffic on that network, they cant see traffic on the first router where your PC is located . Your PC is connected to the first router and as secure as can be if in addition to this your running an up to date version of windows fully patched an firewall enabled without any exceptions that would make for exploits.

367.

Solve : Russians Hacking Routers in the (Failing) News?

Answer» POWERING off and changing my password doesn't SEEM like it's enough, if this is straight-up LEGIT. Any thoughts?

https://www.nytimes.com/2018/05/27/technology/router-fbi-reboot-malware.htmlWell, on the surface it does SOUND legit.
368.

Solve : Random files with pictures I have never seen appearing on my desktop?

Answer»

For about a year now, I have been finding files with photos of people and art. I don’t know if this is a malware from a game with a virus or just from social sites. I FOUND photos of a woman and her son in ONE file and PICTURES of cartoon characters in another. Please help!
what is your OS and AV software?what have you tried so far; scans?, INVESTIGATIONS?, do the folder names or file names bear any resemblance to anything connected to you?
it is interesting. The worst case scenario is that someone has a remote control of your device and messing with you or you have malware that works silently and these are the indicators of its activity.
Use some software for virus termination. Av or anti-malware tools can fully scan your PC and detect, remove threats.
Try itno response from the OP in over a month - reckon he has worked it out.

369.

Solve : I've got some problems with the Firefox browser.?

Answer»

Hi all! I'm Tommy !
So I have Windows 10, 64-bit as the OS. Firefox is v. 33.0. Recently I have had a problem of getting a broken image icon on photos I upload to a certain Web site. I can see other people's, but not my own. Also, I've noticed that when I open the homepage, after a few seconds, it loads again. Here is  my OTL log:

OTL logfile created on: 7/31/2018 11:32:40 PM - Run 8
OTL by OldTimer - Version 3.2.54.0     Folder = C:\Users\Owner\Desktop
64BIT- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17358)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
2.99 Gb Total Physical Memory | 1.86 Gb Available Physical Memory | 62.23% Memory free
5.98 Gb Paging File | 4.68 Gb Available in Paging File | 78.23% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 929.56 Gb Total Space | 748.77 Gb Free Space | 80.55% Space Free | Partition Type: NTFS
Drive D: | 1.95 Gb Total Space | 1.75 Gb Free Space | 89.72% Space Free | Partition Type: NTFS
 
Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot MODE: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/09/25 07:11:20 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe สมัครufabet
PRC - [2014/09/12 05:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/09/11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
PRC - [2012/07/20 15:32:05 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
PRC - [2012/01/19 07:47:20 | 003,027,840 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/09/25 07:10:48 | 003,715,184 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2014/09/18 21:25:49 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2014/08/22 15:14:34 | 000,368,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2014/08/22 15:14:34 | 000,023,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2013/05/27 01:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 21:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2014/09/25 06:58:33 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/09/12 05:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014/03/20 18:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2013/09/11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2012/01/19 07:47:20 | 003,027,840 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014/07/17 18:05:06 | 000,125,584 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 23:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010/11/20 23:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 23:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
DRV:64bit: - [2010/11/20 23:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:64bit: - [2010/11/20 23:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010/11/20 23:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2010/11/20 23:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 23:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2009/09/23 20:23:02 | 006,180,832 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise TECHNOLOGY) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/18 14:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2004/09/23 03:03:00 | 000,026,720 | ---- | M] (Sonic Solutions) [Kernel | Boot | Stopped] -- C:\Windows\SysWOW64\drivers\PxHlpa64.sys -- (PxHlpa64)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page REDIRECT Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 05 D4 5F 2D 44 D1 CC 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE11SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "https://www.google.com/"
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF - HKLM\Software\MozillaPlugins\adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 32.0.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014/09/25 07:10:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 32.0.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2012/01/12 11:33:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2014/10/08 05:59:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\8wi3sbs5.default-1412761564967\extensions
[2014/09/25 07:10:41 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2014/09/25 07:10:41 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2014/09/25 07:10:41 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2014/09/25 07:10:41 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2014/09/25 07:10:40 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/09/25 07:11:21 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
O1 HOSTS File: ([2014/07/05 11:08:39 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: ::1       localhost
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E05E619F-5932-445D-9D21-1FC2630E6BEE}: DhcpNameServer = 209.18.47.61 209.18.47.62
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (systempropertiesperformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [ = exefile] -- "%1" %*
O37 - HKLM\...com [ = comfile] -- "%1" %*
O37 - HKLM\...exe [ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/10/15 06:29:17 | 001,943,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dfshim.dll
[2014/10/15 06:29:17 | 001,131,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dfshim.dll
[2014/10/15 06:29:17 | 000,156,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscorier.dll
[2014/10/15 06:29:17 | 000,156,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscorier.dll
[2014/10/15 06:29:16 | 000,081,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscories.dll
[2014/10/15 06:29:16 | 000,073,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscories.dll
[2014/10/15 06:29:02 | 001,202,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drmv2clt.dll
[2014/10/15 06:29:02 | 000,842,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\blackbox.dll
[2014/10/15 06:29:02 | 000,744,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\blackbox.dll
[2014/10/15 06:29:01 | 000,988,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drmv2clt.dll
[2014/10/15 06:28:58 | 014,632,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll
[2014/10/15 06:28:56 | 004,120,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2014/10/15 06:28:55 | 000,782,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmdrmsdk.dll
[2014/10/15 06:28:55 | 000,617,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmdrmsdk.dll
[2014/10/15 06:28:54 | 011,411,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll
[2014/10/15 06:28:54 | 000,500,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AUDIOKSE.dll
[2014/10/15 06:28:51 | 000,497,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drmmgrtn.dll
[2014/10/15 06:28:50 | 003,208,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2014/10/15 06:28:50 | 000,457,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ci.dll
[2014/10/15 06:28:50 | 000,406,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drmmgrtn.dll
[2014/10/15 06:28:49 | 000,693,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2014/10/15 06:28:49 | 000,616,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi
[2014/10/15 06:28:49 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AUDIOKSE.dll
[2014/10/15 06:28:49 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEng.dll
[2014/10/15 06:28:48 | 001,574,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll
[2014/10/15 06:28:48 | 000,619,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe
[2014/10/15 06:28:47 | 005,551,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2014/10/15 06:28:47 | 003,970,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2014/10/15 06:28:47 | 000,631,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\evr.dll
[2014/10/15 06:28:47 | 000,532,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe
[2014/10/15 06:28:47 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll
[2014/10/15 06:28:46 | 001,480,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2014/10/15 06:28:46 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDump.dll
[2014/10/15 06:28:45 | 003,914,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2014/10/15 06:28:45 | 001,329,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll
[2014/10/15 06:28:45 | 001,069,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptui.dll
[2014/10/15 06:28:45 | 000,489,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\evr.dll
[2014/10/15 06:28:45 | 000,432,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfplat.dll
[2014/10/15 06:28:45 | 000,296,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll
[2014/10/15 06:28:44 | 001,005,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cryptui.dll
[2014/10/15 06:28:44 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll
[2014/10/15 06:28:44 | 000,354,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfplat.dll
[2014/10/15 06:28:44 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptsp.dll
[2014/10/15 06:28:43 | 000,641,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msscp.dll
[2014/10/15 06:28:43 | 000,504,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msscp.dll
[2014/10/15 06:28:43 | 000,325,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msnetobj.dll
[2014/10/15 06:28:43 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rstrui.exe
[2014/10/15 06:28:43 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidapi.dll
[2014/10/15 06:28:42 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msnetobj.dll
[2014/10/15 06:28:42 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2014/10/15 06:28:42 | 000,126,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\audiodg.exe
[2014/10/15 06:28:42 | 000,103,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfps.dll
[2014/10/15 06:28:42 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rrinstaller.exe
[2014/10/15 06:28:42 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rrinstaller.exe
[2014/10/15 06:28:41 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidpolicyconverter.exe
[2014/10/15 06:28:41 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\setbcdlocale.dll
[2014/10/15 06:28:41 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\appidapi.dll
[2014/10/15 06:28:41 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srclient.dll
[2014/10/15 06:28:41 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfpmp.exe
[2014/10/15 06:28:41 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfpmp.exe
[2014/10/15 06:28:41 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidcertstorecheck.exe
[2014/10/15 06:28:40 | 012,625,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL
[2014/10/15 06:28:40 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL
[2014/10/15 06:28:40 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spwmp.dll
[2014/10/15 06:28:40 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spwmp.dll
[2014/10/15 06:28:40 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdxm.ocx
[2014/10/15 06:28:40 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxmasf.dll
[2014/10/15 06:28:40 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msdxm.ocx
[2014/10/15 06:28:40 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxmasf.dll
[2014/10/15 06:28:40 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mferror.dll
[2014/10/15 06:28:40 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mferror.dll
[2014/10/15 06:28:32 | 000,276,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\generaltel.dll
[2014/10/15 06:28:31 | 000,507,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll
[2014/10/15 06:28:31 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll
[2014/10/15 06:28:30 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2014/10/15 06:28:30 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014/10/15 06:28:30 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014/10/15 06:28:29 | 000,710,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014/10/15 06:28:29 | 000,597,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014/10/15 06:28:29 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2014/10/15 06:28:29 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014/10/15 06:28:29 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014/10/15 06:28:28 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2014/10/15 06:28:27 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014/10/15 06:28:26 | 002,017,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014/10/15 06:28:26 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014/10/15 06:28:25 | 000,731,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014/10/15 06:28:25 | 000,446,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2014/10/15 06:28:25 | 000,440,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014/10/15 06:28:25 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014/10/15 06:28:24 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014/10/15 06:28:23 | 002,108,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014/10/15 06:28:23 | 001,068,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2014/10/15 06:28:23 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014/10/15 06:28:22 | 000,678,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014/10/15 06:28:22 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2014/10/15 06:28:21 | 000,595,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014/10/15 06:28:21 | 000,289,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2014/10/15 06:28:21 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014/10/15 06:28:20 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2014/10/15 06:28:19 | 005,829,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014/10/15 06:28:19 | 001,249,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2014/10/15 06:28:19 | 000,758,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014/10/15 06:28:19 | 000,547,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2014/10/15 06:28:19 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014/10/15 06:28:18 | 000,775,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014/10/15 06:28:17 | 000,940,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2014/10/15 06:28:17 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014/10/15 06:28:17 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2014/10/15 06:27:43 | 003,241,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll
[2014/10/15 06:27:37 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rastls.dll
[2014/10/15 06:27:37 | 000,372,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rastls.dll
[2014/10/15 06:27:32 | 003,722,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2014/10/15 06:27:32 | 003,221,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2014/10/15 06:27:31 | 001,118,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstsc.exe
[2014/10/15 06:27:31 | 001,113,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorets.dll
[2014/10/15 06:27:31 | 001,051,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstsc.exe
[2014/10/15 06:27:31 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsta.dll
[2014/10/15 06:27:30 | 000,455,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe
[2014/10/15 06:27:30 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll
[2014/10/15 06:27:30 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\aaclient.dll
[2014/10/15 06:27:19 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\packager.dll
[2014/10/15 06:27:18 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\packager.dll
[2014/10/03 14:09:39 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\Old Firefox Data
[2014/10/01 05:22:58 | 000,519,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
[2014/10/01 05:22:58 | 000,371,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
[2014/09/25 07:10:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
 
========== Files - Modified Within 30 Days ==========
 
[2014/10/15 06:58:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/10/15 06:52:57 | 000,026,576 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/10/15 06:52:57 | 000,026,576 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/10/15 06:52:25 | 000,782,510 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/10/15 06:52:25 | 000,662,400 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/10/15 06:52:25 | 000,122,268 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/10/15 06:48:12 | 000,000,354 | ---- | M] () -- C:\Windows\tasks\ROC_JAN2013_TB_rmv.job
[2014/10/15 06:47:04 | 000,298,928 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/10/15 06:47:03 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/10/15 06:46:44 | 2409,082,880 | -HS- | M] () -- C:\hiberfil.sys
[2014/10/13 12:46:51 | 001,785,387 | ---- | M] () -- C:\Users\Owner\Documents\George's writings corrected.pdf
[2014/10/13 12:46:37 | 001,771,720 | ---- | M] () -- C:\Users\Owner\Documents\George's writings corrected.odt
[2014/10/13 06:18:54 | 000,016,005 | ---- | M] () -- C:\Users\Owner\Documents\Celebrity Deaths 2014.odt
[2014/10/13 06:07:15 | 000,031,750 | ---- | M] () -- C:\Users\Owner\Documents\Comaprative Analysis of Daniel and Revelation.odt
[2014/10/13 05:55:48 | 017,076,224 | ---- | M] () -- C:\Users\Public\Documents\ESBK.mbb
[2014/10/13 05:55:48 | 011,357,184 | ---- | M] () -- C:\Users\Public\Documents\ESBK.mb
[2014/10/12 05:13:54 | 000,012,849 | ---- | M] () -- C:\Users\Owner\Documents\Weight 2014.ods
[2014/10/09 22:05:59 | 000,276,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\generaltel.dll
[2014/10/09 22:05:42 | 000,507,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll
[2014/10/09 22:00:38 | 000,424,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll
[2014/10/07 08:58:52 | 000,000,142 | ---- | M] () -- C:\Windows\funcrd95.ini
[2014/10/06 14:41:36 | 000,014,472 | ---- | M] () -- C:\Users\Owner\Documents\Columbus Day weekend sale.odt
[2014/09/30 09:29:20 | 000,022,573 | ---- | M] () -- C:\Users\Owner\Documents\George's writings.odt
[2014/09/27 06:20:42 | 000,054,156 | -H-- | M] () -- C:\Windows\QTFont.qfn
[2014/09/25 18:46:19 | 000,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2014/09/25 18:32:04 | 002,017,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014/09/25 18:31:02 | 002,108,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014/09/25 06:58:32 | 000,701,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014/09/25 06:58:32 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2014/09/24 22:08:38 | 000,371,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
[2014/09/24 21:40:50 | 000,519,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
[2014/09/18 21:55:49 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014/09/18 21:40:43 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014/09/18 21:40:03 | 000,547,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2014/09/18 21:39:58 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014/09/18 21:38:27 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2014/09/18 21:36:57 | 005,829,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014/09/18 21:30:58 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014/09/18 21:27:09 | 000,595,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014/09/18 21:26:00 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014/09/18 21:25:49 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014/09/18 21:25:09 | 000,758,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014/09/18 21:18:02 | 000,940,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2014/09/18 21:14:28 | 000,446,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2014/09/18 21:06:47 | 000,072,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2014/09/18 21:01:47 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014/09/18 21:01:46 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014/09/18 21:01:03 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014/09/18 21:00:45 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2014/09/18 20:59:40 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2014/09/18 20:58:03 | 000,289,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2014/09/18 20:53:52 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014/09/18 20:51:24 | 000,440,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014/09/18 20:50:16 | 000,112,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014/09/18 20:49:31 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014/09/18 20:42:57 | 000,731,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014/09/18 20:42:56 | 000,710,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014/09/18 20:40:12 | 001,249,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2014/09/18 20:36:23 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2014/09/18 20:32:50 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014/09/18 20:18:55 | 001,068,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2014/09/18 19:59:26 | 000,775,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014/09/18 19:52:24 | 000,678,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014/09/17 22:00:42 | 003,241,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll
 
========== Files Created - No Company Name ==========
 
[2014/10/13 12:46:47 | 001,785,387 | ---- | C] () -- C:\Users\Owner\Documents\George's writings corrected.pdf
[2014/10/10 05:11:31 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2014/10/02 10:03:05 | 001,771,720 | ---- | C] () -- C:\Users\Owner\Documents\George's writings corrected.odt
[2014/09/30 08:32:47 | 000,022,573 | ---- | C] () -- C:\Users\Owner\Documents\George's writings.odt
[2014/09/18 13:20:12 | 000,031,750 | ---- | C] () -- C:\Users\Owner\Documents\Comaprative Analysis of Daniel and Revelation.odt
[2013/02/03 07:17:16 | 000,000,022 | ---- | C] () -- C:\Windows\kodakpcd.Owner.ini
 
========== Alternate Data Streams ==========
 
Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >

370.

Solve : How to registrer AVG PV tuneup?

Answer»

I have finished my trial PERIOD and now I want to register the program with my key. But where do I enter this licence key ?You should CONTACT AVG.
follow the below steps:
1.Open AVG PC Tuneup icon on your desktop.
2.click on help and then Activate product.
3.Enter the Licence Number and click next.
4.Click on FINISH

371.

Solve : Will extracting a virus infect my computer??

Answer»

Let's say there is a virus called virus.exe in a zip file, extracting it will trigger the antivirus and av will quarantine it. If I disable my antivirus (which somehow also disables windows defender), EXTRACT virus.exe (without double clicking or running the exe) and upload it to virustotal for a scan, will my computer still get infected?

There's no guarantee that your AV will catch it. Windows Defender is your AV. Use this method of scanning that file.
This may not work if the file is zipped.
Why don't you let your AV quarantine it?

Please go to VirSCAN.org FREE on-line scan service
(If more than one file needs scanned they must be done separately and logs POSTED for each one)

1. Copy and paste the following file path into the Suspicious FILES to scan box on the top of the page.

CODE: [SELECT]Insert File Path
2. At the upload site, click once inside the window next to Browse.
3. Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
4. Click on the Upload button.
This will perform a scan across multiple different virus scanning engines.
Your file will possibly be entered into a queue which normally takes less than a minute to clear.
Important: Wait for all of the scanning engines to complete.
5. Once the Scan is completed scroll down and click on the Copy to Clipboard button. This will copy the link of the report into the Clipboard.
6. Paste the contents of the Clipboard in your next reply.Your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help.Superdave.

372.

Solve : Is this a scam.?

Answer»

Hi, this came up while I was looking at the TV guide.
Is this a scam or do I really have a VIRUS?

This is the website they came from.  http://secureservice.onesysutil.live/lp/acsh1/?pxl=WAD4123_WAD4027_RUNT&utm_campaign=wadcsh&utm_pubid=1806387-2919733628-0&utm_source=wadcsh&x-at=Firefox&x-context=15468644150248076099069148262668746

I run my virus protections regularly & have nil results.

Windows 10 with SAS, and I regularly use Superdaves & evilfantasies reference to other virus protection programs.

Thank you. ImnoGuruIt's a scam.Any warnings that come through your browser with a URL are scams and click bait to try to INFECT in many cases. When you see these its best to close the browser and then reopen browser. However some browsers try to bring you back to where you where but give you the option to restore recently closed pages etc. When you see the message to restore or go back to the last page or session select NO and chose to open a new session. One step further is to wipe out the browser history for say the last 2 hours or any amount of time you chose so that the bad URL is flushed from the history so no way you can accidentally go back to it and have it display it again from accidentally going back to it through history.

If browser gets hit with a hijacker though sometimes it removes your ability to close the browser through normal means such as it displays a warning full screen or a pop up that takes control and no ability to close it or minimize it. If you ever see one of these then its best to press CTRL + ALT + DELETE and select to go to task MANAGER and then locate the open browser session and tell it to kill or end that task or ENTIRE process tree for that browser. It then exits the browser and you can then run Malwarebytes on your system and remove any browser hijacker.

One good thing to do is make sure you always have 2 browsers on your system. So that if one browser gets infected you can use the other that is not infected to look up a solution to fixing the problem on the other infected browser. Having Edge or Internet Explorer DEPENDING on Windows version plus another browser of choice such as Firefox which is the browser of my choice, I have had a hijacker take Firefox hostage and by my ability to launch Edge browser I was able to download and install Malwarebytes through edge on that system and then fix the issue with Firefox taken hostage by hijacker. The hijacker my Firefox got hit with I was at facebook just reading what people posted for christmas and then somehow an rogue ad server served up a FBI warning claiming adult content on system and call this number immediately in an audio loop to correct the problem. The method of using Edge to download and install Malwarebytes to this system and then run full scan of malwarebytes caught the problem and fixed the problem with Firefox. Had I not had this Edge browser as an alternate browser I would have had to use another computer and put malwarebytes on a thumb drive and then install it off the thumb drive which if I only have 1 computer like many people do, I would have been in trouble with a lack of means of getting malwarebytes onto my computer to fix it.I knew in my heart it was a scam BC_Programmer because Im very active on running regular scans from other sources that I trust.
Short of the 500 or so gathered from Malwarebytes, nothing of any significance ever shows up, just the trackers. No PUP's, Trojans, hijackers or downloaded files. I did see at one point that Malwarebytes notifications, displayed 1 item added to the start menu, but I couldnt find anything untoward. That was some time ago, say 2 months ago. Everything in the start menu has been there since I got this computer. There are a couple I dont know what they are or do, but they are pretty insignificant. Energy Star & Bonjour by name. Energy Star is just a program that rates products energy comsumption.

That was the other reason I figured it was a virus potential DaveLembke, it came from a browser. Of all things it was my TV guide that it took over. So something advertised on the TV Guide page may have triggered it.

Certainly good advice to clear out the history otherwise it has the potential to continually return & I've seen this on a mates home computer. It was too hard to tell him how to get out of it remotely, so I had to go there to fix his computer. ( Lucky he was fairly local then ). So hard to deal with when the op doesn't have a clue, dinner was nice though. LOL.

All clean now then. Thanks for your confirmation.
ImnoGuru. It's a scam they show you message like this and ask to install some programs. If you install those programs, they might stole  your personal or anythings with your PC.

373.

Solve : Can virus/malware infect offline disks??

Answer»

As per the subject:

Can a disk that's been set to offline in disk management be infected by a virus?

(As far as I know, the disk is not SEEN in PC as a mapped letter drive e.g. D:/
however, it can easily be turned on in disk management)

Current situation:
Host OS running windows 10
Guest OS running windows 8.1 (can be upgraded to 10 if relevant) - Through a windows to go USB

Host OS disks have been deactivated in disk management when booted into Guest OS
Guest OS cannot access Host disks unless I go to disk management and turn the drives online
If guest OS is infected with a virus (testing suspicious files), can the Host OS offline/unmounted disks be infected?

(This process involves no physical detaching of the drives as it is a tedious solution if deemed unnecessary)
(Please also do not SUGGEST SIMPLY not to TEST this at all. I would like to know HYPOTHETICALLY what level of risk this involves)

I have been informed that Evil Fantasy or SuperDave may be able to help with this question.

Thank youMore information about that topic here.

374.

Solve : Anti-trackers?

Answer»

What are they ? Which one(s) should i have ?You can learn more here.Thanks for info, SuperDave. I do have Ad BlockPlus -like it, it does the job.Maybe it's ENOUGH, I don't have annoying ads popping up anymore. Probably could use more protection of some kind. We NEVER can be over protected, can we !Download Security Check by screen317 from the following link and save it to your desktop.

Security Check

* Double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to ACCESS the INTERNET, ALLOW it to do so.

375.

Solve : CHROMIUM Malware - What is it??

Answer»

A Google search goes to web sites that want to give me even more malware.
IMO, any program that will not uninstall is likely malware -Am I right?

Anyway, here is a You Tube Video:
How To Fully Remove CHROMIUM Malware
Quote

This is a tutorial on how to completely remove the "Chromium" malware. This is not the only method, but I found this to be the most effective. ...

I did remove it, but hot that way! 

Question: Why did my AV program not find it?
(I am running Windows 10 pro 32 bit on my Dell 755.)Hello and welcome to GeekPolice.Net My name is Dave. I will be helping you out with your particular problem on your computer. 

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*****************************************************************
Quote
IMO, any program that will not uninstall is likely malware -Am I right?
That's one good indication but not always.
Quote
Question: Why did my AV program not find it?
Because it is not a virus. It is malware.

Please download AdwareCleaner onto your Desktop. AdwCleaner

Before starting AdwCleaner, close all open programs and internet browsers, then double-click on the AdwCleaner icon.



If Windows prompts you as to whether or not you wish to run AdwCleaner, please allow it to run.
When the AdwCleaner program will open, click on the Scan button as shown below.



AdwCleaner will now start to search for malicious files that may be installed on your computer.
To remove the files that were detected in the previous step, please click on the Clean button.



AdwCleaner will now prompt you to save any open files or data as the program will need to reboot the computer. Please do so and then click on the OK button. AdwCleaner will now delete all detected adware from your computer. When it is done it will display an alert that explains what PUPs (Potentially Unwanted Programs) and Adware are. Please read through this information and then press the OK button. You will now be presented with an alert that states AdwCleaner needs to reboot your computer.
Please click on the OK button to allow AdwCleaner reboot your computer.A log will be produced. Please copy and paste this log in your next reply.
*********************************************
Download and install: Please download Malwarebytes' scanner to your desktop.
Double Click mbam-setup.exe to install the application.
  • It should update automatically if the computer is connected to the internet.
  • Click on Threat Scan and click on Scan Now.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete make sure all the infections have "quarantine" selected in the Action box.
  • Click on "Apply actions" You may be asked to Restart your computer to completely remove the infections.
  • When disinfection is completed you can click on "Copy to Clipboard".
  • Paste the log in you next reply (CTRL+ V)
*************************************************
Download Security Check by screen317 from the following link and save it to your desktop.

Security Check

* Double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
Wow! Van not believe how much stuff there was!   
Reports:
Ad Cleaner: +++++++++++++++
# -------------------------------
# Malwarebytes AdwCleaner 7.3.0.0
# -------------------------------
# Build:    04-04-2019
# Database: 2019-04-05.4 (Cloud)
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    04-07-2019
# Duration: 00:00:09
# OS:       Windows 10 Pro
# Cleaned:  31
# Failed:   2


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted       C:\Program Files\Reimage
Deleted       C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reimage repair
Deleted       C:\ProgramData\Reimage Protector
Deleted       C:\Windows\System32\config\systemprofile\AppData\Local\WebDiscoverBrowser
Deleted       C:\rei

***** [ Files ] *****

Deleted       C:\Users\geek9\AppData\Roaming\Mozilla\Firefox\Profiles\i8sbflim.default\searchplugins\avg-secure-search.xml
Deleted       C:\Windows\Reimage.ini
Deleted       C:\Windows\Temp\reimage.log

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
Deleted       HKCU\Software\PRODUCTSETUP
Deleted       HKCU\Software\ProductSetup\Uninstall\0B2U2Z1P0F1P1G1R1P1V0A1Q1Q0O1G
Deleted       HKCU\Software\ProductSetup\Uninstall\0S1P1T1C1R1MtT0P1C1F2X1L1Q1P1QtT1S2UtT0Y1T1M1F1F
Deleted       HKCU\Software\Reimage
Deleted       HKCU\Software\WebDiscoverBrowser
Deleted       HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
Deleted       HKLM\Software\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
Deleted       HKLM\Software\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
Deleted       HKLM\Software\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
Deleted       HKLM\Software\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Deleted       HKLM\Software\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Deleted       HKLM\Software\Classes\REI_AxControl.ReiEngine
Deleted       HKLM\Software\Classes\REI_AxControl.ReiEngine.1
Deleted       HKLM\Software\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Codec Settings UAC Manager
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Codec Settings UAC Manager
Deleted       HKLM\Software\Reimage
Deleted       HKLM\Software\WebDiscoverBrowser
Deleted       HKU\.DEFAULT\Software\WebDiscoverBrowser
Deleted       HKU\S-1-5-18\Software\WebDiscoverBrowser

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

Deleted       https://mysearch.avg.com/?rvt=1&pid=bcu
Deleted       https://mysearch.avg.com/?rvt=1&pid=bcu
Not Deleted   webtuneup.avg.com
Not Deleted   webtuneup.avg.com


*************************

  • Delete Tracing Keys
  • Reset Winsock


*************************

AdwCleaner[S00].txt - [1569 octets] - [07/03/2019 12:07:14]
AdwCleaner[C00].txt - [1661 octets] - [07/03/2019 12:09:32]
AdwCleaner[S01].txt - [4021 octets] - [07/04/2019 12:05:12]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########

Malwarebyres: ========================
Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 4/7/19
Scan Time: 12:22 PM
Log File: 8aa0a846-596a-11e9-9a9c-00219b6a717e.json

-Software Information-
Version: 3.7.1.2839
Components Version: 1.0.563
Update Package Version: 1.0.10038
License: Expired

-System Information-
OS: Windows 10 (Build 18356.1)
CPU: x86
File System: NTFS
User: DESKTOP-T35LOPR\geek9

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 181231
Threats Detected: 15
Threats Quarantined: 15
Time Elapsed: 3 min, 15 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 4
PUP.Optional.SearchManager, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\NAHHMPBCKPGDIDFNMFKFGIFLPJIJILCE, Quarantined, [2063], [440037],1.0.10038
PUP.Optional.SearchManager, HKU\S-1-5-21-1999882772-3128741223-438591315-1001\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\nahhmpbckpgdidfnmfkfgiflpjijilce, Quarantined, [2063], [440037],1.0.10038
PUP.Optional.SearchManager, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\PILPLLOABDEDFMIALNFCHJOMJMPJCOEJ, Quarantined, [2063], [183362],1.0.10038
PUP.Optional.SearchManager, HKU\S-1-5-21-1999882772-3128741223-438591315-1001\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\pilplloabdedfmialnfchjomjmpjcoej, Quarantined, [2063], [183362],1.0.10038

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 2
PUP.Optional.Reimage, C:\ProgramData\ReimageRepair\Results, Quarantined, [340], [651074],1.0.10038
PUP.Optional.Reimage, C:\PROGRAMDATA\REIMAGEREPAIR, Quarantined, [340], [651074],1.0.10038

File: 9
PUP.Optional.SearchManager, C:\USERS\GEEK9\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\chrome-extension_pilplloabdedfmialnfchjomjmpjcoej_0.localstorage, Quarantined, [2063], [453138],1.0.10038
PUP.Optional.SearchModule, C:\USERS\GEEK9\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\chrome-extension_nahhmpbckpgdidfnmfkfgiflpjijilce_0.localstorage, Quarantined, [275], [453492],1.0.10038
PUP.Optional.SearchManager, C:\USERS\GEEK9\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [2063], [183362],1.0.10038
PUP.Optional.Reimage, C:\ProgramData\ReimageRepair\Results\ProtectorPackage.log, Quarantined, [340], [651074],1.0.10038
PUP.Optional.Reimage, C:\ProgramData\ReimageRepair\active_protection.txt, Quarantined, [340], [651074],1.0.10038
PUP.Optional.Reimage, C:\ProgramData\ReimageRepair\cfl.rei, Quarantined, [340], [651074],1.0.10038
PUP.Optional.Reimage, C:\ProgramData\ReimageRepair\scan_agent_result_log.txt, Quarantined, [340], [651074],1.0.10038
PUP.Optional.Reimage, C:\ProgramData\ReimageRepair\url_setting_definitions.txt, Quarantined, [340], [651074],1.0.10038
PUP.Optional.WinYahoo.Generic, C:\USERS\GEEK9\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I8SBFLIM.DEFAULT\SEARCHPLUGINS\SADARAMA.XML, Quarantined, [223], [643052],1.0.10038

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)
Security Check --------------------------
 Results of screen317's Security Check version 1.014 --- 12/23/15 
   x86 (UAC is enabled) 
 Internet Explorer 11 
``````````````Antivirus/Firewall Check:``````````````[/u]
 Windows Firewall Enabled! 
Windows Defender   
AVG Antivirus     
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:`````````[/u]
 Adobe Flash Player    32.0.0.156 
 Mozilla Firefox (66.0.2)
 Google Chrome (73.0.3683.86)
 Google Chrome (SetupMetrics...)
````````Process Check: objlist.exe by Laurent````````[/u] 
 Malwarebytes Anti-Malware mbamservice.exe 
 AVG Antivirus AVGSvc.exe 
 AVG Antivirus aswidsagent.exe 
 AVG Antivirus AVGUI.exe 
 Malwarebytes Anti-Malware mbamtray.exe 
`````````````````System Health check`````````````````[/u]
 Total Fragmentation on Drive C:  %
````````````````````End of Log``````````````````````[/u]

That's all  ;D



The Security log show you have two AV's active on your computer. Windows Defender is the resident AV that comes with Windows 10. I would advise you to uninstall AVG. It is not needed. You should only have one AV active on your computer at any time.

ESET Online Scanner
Note : If you use Internet Explorer to get the ESET Online Scanner, you won't have to download, nor install the tool, as everything will be ran in a contextual (pop-up) window of Internet Explorer. However, for every other browsers, you will have to download and install ESET Online Scanner. In this set of instruction, I'll use Google Chrome to download it and run it (since a lot of people will do it), however, except for the download and installation procedure, the same instructions applies if you use Internet Explorer. Please note that two or three prompts will appear if you use Internet Explorer asking you to reload the page, authorize the application, execute it, ETC. Accept all of them in order to run ESET Online Scanner.

    Download and execute ESET OnlineScan (on this window, click on ESET Smart Installer to trigger the download). People accessing this URL via Internet Explorer will start the integration process of ESET Online Scanner in their browser;
    Once the installation is done (it requires Admin Rights), check the following settings (two of them are under Advanced Settings, click on it to display them) :

        Enable detection of potentially unwanted applications;
        Scan archives;
        Scan for potentially unsafe applications;
        Optional : If you want to scan more drives, click on CHANGE... and select the drives you want to include in the scan;

   

    After you're done CHECKING these options, click on Start and ESET Online Scanner will download it's virus signature database before starting the scan;
   

    Once done, the scan will start automatically. Detections will appear at the bottom of the window. ESET Online Scanner can have an EXTREMELY long scan time that can last between 2 or 3 hours. So if you start the scan, do not interrupt it, let it complete until the end;
   

    After the scan is finished, a summary window will appear to give you the information about the scan. Then you'll have to the option to see what threads were found and to manage the threats that were quarantined;
   


    Click on List of found threats, it'll display every threat identified during that scan, their type and what action was taken against them. Click on Copy to clipboard to copy these results on our clipboard and post them in your next reply;
   


    Once you're done, click on the Back button;
    Check both checkboxes at the bottom: Uninstall application on close and Delete quarantined files before CLICKING on the Finish button;
376.

Solve : I need help I think I am been hacked?

Answer»

The reason I think I am being hacked is my phone has been changing settings on it's own apps that i never downloaded got downloaded and some can't be removed my battery dies way to quick it burns up when I only playing music or using maps. I tried to change my settings back to normal but they just change back when i not looking at my phone another strange thing is my resume that I made from scratch had someone else number on it I no longer receive texts or calls from certain people at certain days and TIMES even email has been ACTING up my passwords have been changing and I am just fed up I NEED advice to counter this. I think they got in thru my home internet I have spectrum and I change my Passwords and the SSI Name ID but my sister and brother give away my PASSWORD to my neighbors which makes me mad

Quote from: Tovino77 on June 27, 2019, 06:07:13 AM

The reason I think I am being hacked is my phone has been changing settings on it's own apps that i never downloaded got downloaded and some can't be removed my battery dies way to quick it burns up when I only playing music or using maps. I tried to change my settings back to normal but they just change back when i not looking at my phone another strange thing is my resume that I made from scratch had someone else number on it I no longer receive texts or calls from certain people at certain days and times even email has been acting up my passwords have been changing and I am just fed up I need advice to counter this. I think they got in thru my home internet I have spectrum and I change my Passwords and the SSI Name ID but my sister and brother give away my password to my neighbors which makes me madhttps://solitaire.onl/ 9apps.ooo/ https://bluestacks.vip/



my issue got solved!!Good for you.
377.

Solve : .chk file?

Answer»

recently my friend TOLD me about his file was....deleted but the capacity of its USB device remain constant. but he CANT see his old files all of his files. then i noticed when i check his USB Flashdrive i noticed there is "found.. named folder and " all files listed as .chk file format.

Please need help... my conclusion.. is could it be possible to RECOVER all files deleted or.. moved to a c ertain file format .chk?

please... my friends... is an office clerk he need to recover all files
are there enough possible method? to recover those fiiles?


THank you in ADVANCE...


  This may help:
http://www.ericphelps.com/uncheck/
Basically the files on his USB drive were corrupted and SCANDISK ATTEMPTS to recover all existing file fragments.

378.

Solve : Received a eMail FROM "Here my own eMail Yahoo"?

Answer»

Received an email from "here my own email Yahoo", and ACTIVE when you pass the MOUSE over, to "here my own email yahoo, as from"
After READING the email, i went to my acc. yahoo, and changed my PASSWORD.
I ALSO did a scan with my ZoneAlarm and Malwarebytes Anti-Malw. and SuperAntispyware, and all was clear.
What happened for someone to be able to use my Yahoo email address to sent to me an email? Did he/she was able to open my Yahoo email Account?
What should i do now ?
Help, help 
Best regards, Your E-mail account was hacked and you did the correct thing in changing your password. Just make you have a strong password. It should include numbers and letters.

379.

Solve : resource:///components/nsSessionStore.js:402?

Answer»

Hi! My laptop is becoming increasingly slow as if there is a virus. Firefox keeps asking me whether I can to stop a script, GOOGLE chrom says about a PLUGIN that has crashed but in general sometimes I think it has frozen all together.

I just for that on a screen a while ago

resource:///components/nsSessionStore.js:402

Any idea as to what it is and above all what I can do for my computer to run properly?

thanks,
 Hello and welcome to GeekPolice.Net My name is Dave. I will be helping you out with your particular problem on your computer. 

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and TRANSFER any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*****************************************************************
SUPERAntiSpyware

If you already have SUPERAntiSpyware be sure to check for updates before scanning!

Download SuperAntispyware Free Edition (SAS)
* Double-click the icon on your desktop to run the installer.
* When asked to Update the program definitions, click Yes
* If you encounter any problems while downloading the updates, manually download and unzip them from here
* Next click the Preferences button.

•Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
* Click the Scanning Control tab.
* Under Scanner Options make sure only the following are checked:

•Close browsers before scanning
•Scan for tracking cookies
•Terminate memory threats before quarantining
Please leave the others unchecked

•Click the Close button to leave the control center screen.

* On the main screen click Scan your computer
* On the left check the box for the drive you are scanning.
* On the right choose Perform Complete Scan
* Click Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete a summary box will appear. Click OK
* Make sure everything in the white box has a check next to it, then click Next
* It will quarantine what it found and if it asks if you want to reboot, click Yes

•To retrieve the removal information please do the following:
•After reboot, double-click the SUPERAntiSpyware icon on your desktop.
•Click Preferences. Click the Statistics/Logs tab.

•Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

•It will open in your default text editor (preferably Notepad).
•Save the notepad file to your desktop by clicking (in notepad) File > Save As...

* Save the log somewhere you can easily find it. (normally the desktop)
* Click close and close again to exit the program.
*Copy and Paste the log in your post.
*********************************************
Please download Malwarebytes Anti-Malware from here.
Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and LAUNCH Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
************************************************************************
Download DDS from HERE or HERE and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.
* Save both reports to your desktop.
* The instructions here ask you to attach the Attach.txt.



1) DDS.txt
2) Attach.txt
Instead of attaching, please copy/past both logs into your Thread

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copying and pasting it into the reply.

•Close the program window, and delete the program from your desktop.

Please note: You may have to disable any script protection running if the scan fails to run.
After downloading the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control HERE .Then post your DDS logs. (DDS.txt and Attach.txt )
Thanks. This is the SUPERAntiSpyware Scan Log

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/26/2012 at 04:52 PM

Application Version : 5.0.1144

Core RULES Database Version : 8279
Trace Rules Database Version: 6091

Scan type       : Complete Scan
Total Scan Time : 09:59:07

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 576
Memory threats detected   : 0
Registry items scanned    : 66358
Registry threats detected : 4
File items scanned        : 261118
File threats detected     : 556

Browser Hijacker.Deskbar
   (x86) HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
   (x86) HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid32
   (x86) HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib
   (x86) HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib#Version

Adware.Tracking Cookie
   C:\Users\marina\AppData\Roaming\Microsoft\Windows\Cookies\YVRJ2FYS.txt [ /c.atdmt.com ]
   C:\Users\marina\AppData\Roaming\Microsoft\Windows\Cookies\V5NB1UG9.txt [ /mywebsearch.com ]
   C:\Users\marina\AppData\Roaming\Microsoft\Windows\Cookies\CT0ZAN1V.txt [ /atdmt.com ]
   C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\1I6Y6E7X.txt [ Cookie:[email protected]/ ]
   C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\WA530UF2.txt [ Cookie:[email protected]/adServe/banners ]
   C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\H48NWYV4.txt [ Cookie:[email protected]/cgi-bin ]
   C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\LWOTI6EC.txt [ Cookie:[email protected]/ ]
   C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZJYAWTEW.txt [ Cookie:[email protected]/ ]
   C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\YEP7UH7S.txt [ Cookie:[email protected]/ ]
   C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\XES36DXK.txt [ Cookie:[email protected]/ ]
   C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\JAILEL10.txt [ Cookie:[email protected]/ ]
   C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\TM2QR2BS.txt [ Cookie:[email protected]/ ]
   C:\USERS\MARINA\Cookies\YVRJ2FYS.txt [ Cookie:[email protected]/ ]
   C:\USERS\MARINA\Cookies\V5NB1UG9.txt [ Cookie:[email protected]/ ]
   C:\USERS\MARINA\Cookies\CT0ZAN1V.txt [ Cookie:[email protected]/ ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .atdmt.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .atdmt.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .imrworldwide.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .imrworldwide.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .apmebf.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .mediaplex.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adbrite.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   rotator.adjuggler.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   rotator.adjuggler.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   rotator.adjuggler.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   track.adform.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ru4.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .specificclick.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adviva.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .doubleclick.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .apmebf.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adxvalue.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .fastclick.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adinterax.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .zanox.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.zanox.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tradedoubler.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tradedoubler.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tradedoubler.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .uk.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tacoda.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tacoda.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tacoda.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tacoda.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tacoda.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tacoda.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ar.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tribalfusion.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .pro-market.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adxpose.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adbrite.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .wpni.112.2o7.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   statse.webtrendslive.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .chitika.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .mm.chitika.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .histats.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .weborama.fr [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .baa.solution.weborama.fr [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .baa.solution.weborama.fr [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .baa.solution.weborama.fr [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .baa.solution.weborama.fr [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .histats.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .lucidmedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .yieldmanager.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adinterax.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   eas.apm.emediate.eu [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   eas.apm.emediate.eu [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .questionmarket.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   accounts.google.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   server.adformdsp.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adformdsp.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adform.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .bs.serving-sys.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   track.adform.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adform.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .247realmedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ads.audience2media.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ads.audience2media.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .audience2media.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .doubleclick.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .247realmedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .247realmedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ru4.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .mediaplex.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.insightexpressai.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   cdn2.baronsmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   cloud.video.unrulymedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   cloudfront.mediamatters.org [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   content.oddcast.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   content.yieldmanager.edgesuite.net [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   ds.serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   ec.atdmt.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   ia.media-imdb.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   media.buto.tv [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   media.kyte.tv [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   media.mtvnservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   media.npr.org [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   media.scanscout.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   media.socialvibe.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   media1.break.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   media3.break.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   msnbcmedia.msn.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   s0.2mdn.net [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   secure-uk.imrworldwide.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   secure-us.imrworldwide.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   spe.atdmt.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   stat.easydate.biz [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   tracking.onefeed.co.uk [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   www.99counters.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   www.al-anon.alateen.org [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .getclicky.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .static.getclicky.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   in.getclicky.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   track.solocpm.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   track.solocpm.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   track.solocpm.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adviva.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   eas.apm.emediate.eu [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   eas4.emediate.eu [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .indoormedia.co.uk [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   max.bannermanager.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .tradedoubler.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .tradedoubler.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .tradedoubler.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   openx1.overadmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .accounts.google.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .accounts.google.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   accounts.google.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   accounts.google.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .mjtracking.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .mjtracking.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   islamicinsights.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .islamicinsights.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .islamicinsights.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .richmedia.yahoo.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .apmebf.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .apmebf.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .mediafire.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .mediafire.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .mediafire.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   server.adformdsp.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adformdsp.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   stats.e-go.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   *Blocked Russian URL* [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .game-advertising-online.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   track.adform.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adform.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .statcounter.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   cdmedia.rotator.hadj7.adjuggler.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   cdmedia.rotator.hadj7.adjuggler.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   vidasco.rotator.hadj7.adjuggler.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   vidasco.rotator.hadj7.adjuggler.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adjuggler.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adinterax.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adinterax.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .amazon-adsystem.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .amazon-adsystem.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   uk.sitestat.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   uk.sitestat.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .harrenmedianetwork.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .fastclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .fastclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ad-emea.doubleclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ad-emea.doubleclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .doubleclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .doubleclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .www.cdmediallc.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   statse.webtrendslive.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   tracking.hostgator.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ox.mediabistro.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .find-me-a-gift.co.uk [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .find-me-a-gift.co.uk [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .e-2dj6wjlyundpgeo.stats.esomniture.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .imrworldwide.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .imrworldwide.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   wstat.wibiya.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .atdmt.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .atdmt.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .yieldmanager.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .histats.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .histats.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .legolas-media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .legolas-media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .legolas-media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .tripod.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .tripod.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   leads.383media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   leads.383media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .mm.chitika.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ads.24media.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ads.24media.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .service.24media.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .service.24media.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ads.audience2media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .audience2media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ads.audience2media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .audience2media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .clickfuse.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .clickfuse.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .clickfuse.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   findnsave.sacbee.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .c.gigcount.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .247realmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .247realmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .247realmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .collective-media.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .collective-media.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .collective-media.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .collective-media.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   doublespeed.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   doublespeed.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   help.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   help.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   my.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adbrite.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adbrite.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adbrite.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adbrite.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adbrite.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   dc.tremormedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .nextag.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .nextag.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .nextag.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .nextag.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .womanmediagroup.es [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.zanox.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .zanox.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adxpose.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ads.saymedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ads.saymedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   clickztrax.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   clickztrax.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .clicksor.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .clicksor.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .smartadserver.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www4.smartadserver.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .unrulymedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .eyewonder.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .eyewonder.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .technoratimedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .lucidmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   publishers.clickbooth.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.findaproperty.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .findaproperty.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .findaproperty.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .findaproperty.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad2.adfarm1.adition.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .specificclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revenuemantra.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .xm.xtendmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   accounts.youtube.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .lfstmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .lfstmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .lfstmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .lfstmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .pro-market.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .overture.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .overture.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .perf.overture.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   network.clickbanner.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .kantarmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .kantarmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .files.bannersnack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .files.bannersnack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adxvalue.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .interclick.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .interclick.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .a1.interclick.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .a1.interclick.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .interclick.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .interclick.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ru4.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ru4.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .mediaplex.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .mediaplex.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   *Blocked Russian URL* [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   *Blocked Russian URL* [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtechus.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adserver.adtechus.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.burstnet.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .www.burstnet.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .burstnet.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.burstnet.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .at.atwola.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .uk.at.atwola.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .uk.at.atwola.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .uk.at.atwola.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .bs.serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .hearstmagazines.112.2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .wpni.112.2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .highbeam.122.2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .112.2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .opodo.122.2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .traveladvertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .traveladvertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .questionmarket.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .questionmarket.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adfarm1.adition.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adfarm1.adition.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   adfarm1.adition.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   eas.apm.emediate.eu [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   eas.apm.emediate.eu [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .tribalfusion.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adinterax.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .mediaplex.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
Malwarebytes Anti-Malware (Trial) 1.60.1.1000
www.malwarebytes.org

Database version: v2012.02.26.04

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
marina :: SAMMADHITTI [administrator]

Protection: Enabled

26/02/2012 17:54:58
mbam-log-2012-02-26 (17-54-58).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 535028
Time elapsed: 5 hour(s), 8 minute(s), 7 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
C:\Program Files (x86)\27res.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Users\marina\AppData\LocalLow\OurBabyMaker_27EI\Installr\Cache\023EC878.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.

(end)
I will need to see the DDS logs; both of them.Thanks. Here is the first (the DDS)

.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421  BrowserJavaVersion: 1.6.0_31
Run by marina at 3:49:45 on 2012-02-27
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.44.1033.18.3999.1335 [GMT 0:00]
.
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Windows\SysWOW64\svchost.exe -k Akamai
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\SysWOW64\svchost.exe -k netsvcs
C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files (x86)\Giraffic\Veoh_Giraffic.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\marina\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Users\marina\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\SecureW2\sw2_tray.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVH.EXE
C:\Users\marina\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
C:\Program Files (x86)\real\realplayer\Update\realsched.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\NOTEPAD.EXE
Q:\140062.enu\Office14\ONENOTEM.EXE
C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\splwow64.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
Q:\140062.enu\Office14\WINWORD.EXE
C:\Windows\system32\svchost.exe -k defragsvc
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://start.facemoods.com/?a=axl
uInternet Settings,ProxyOverride = 127.0.0.1:9421;*.local
mSearchAssistant = hxxp://start.facemoods.com/?a=axl&s={searchTerms}&f=4
BHO: Shopping Assistant Plugin: {1631550f-191d-4826-b069-d9439253d926} - C:\Program Files (x86)\PriceGong\2.5.2\PriceGongIE.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Babylon toolbar helper: {2eecd738-5844-4a99-b4b6-146bf802613b} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO: Norton Identity Protection: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll
BHO: CescrtHlpr Object: {64182481-4f71-486b-a045-b233bd0da8fc} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll
BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\IPS\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - C:\Program Files (x86)\WOT\WOT.dll
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: TBLA06779 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - C:\Program Files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll
TB: ListenArabic Toolbar: {f569cf08-edf6-4fab-8c8a-eec184358372} - C:\Program Files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll
TB: C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll
TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - C:\Program Files (x86)\WOT\WOT.dll
TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarTlbr.dll
TB: facemoods Toolbar: {db4e9724-f518-4dfd-9c7c-78b52103cab9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
uRun: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
uRun: [VeohPlugin] "C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
uRun: [Akamai NetSession Interface] "C:\Users\marina\AppData\Local\Akamai\netsession_win.exe"
mRun: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
mRun: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [SecureW2 Tray] C:\Program Files (x86)\SecureW2\sw2_tray.exe
mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [NBAgent] "C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" /WinStart
mRun: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
mRun: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe" /md I
mRun: [TkBellExe] "C:\Program Files (x86)\real\realplayer\update\realsched.exe"  -osboot
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: []
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
StartupFolder: C:\Users\marina\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\BBCIPL~1.LNK -
StartupFolder: C:\Users\marina\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\marina\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\marina\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
StartupFolder: C:\Users\marina\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\FLIPTO~1.LNK - C:\Program Files (x86)\Fliptoast\fliptoast.exe
StartupFolder: C:\Users\marina\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVH.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: HideFastUserSwitching = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {F569CF08-EDF6-4FAB-8C8A-EEC184358372} - {F569CF08-EDF6-4FAB-8C8A-EEC184358372} - C:\Program Files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{6BA18F65-FA7D-4561-B466-FF1BDBAC958E} : DhcpNameServer = 193.63.73.32
TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B} : DhcpNameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B}\249627B6265636B6D27514D4 : DhcpNameServer = 193.61.1.250
TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B}\24F646C6569616E6D2C49626271627965637 : DhcpNameServer = 163.1.2.1 129.67.1.1 129.67.1.180
TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B}\36F6374716 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B}\478656169627C696E656 : DhcpNameServer = 10.81.93.254 10.81.93.254
TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B}\9435D434D214B455 : DhcpNameServer = 217.13.1.28 83.218.143.36
TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B}\B49405F4350234146454 : DhcpNameServer = 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll
SEH: EasyBits ShellExecute Hook: {e54729e8-bb3d-4270-9d49-7389ea579090} - C:\Windows\SysWow64\EZUPBH~1.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
BHO-X64: Shopping Assistant Plugin: {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.5.2\PriceGongIE.dll
BHO-X64:     PriceGong - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64:     AcroIEHelperStub - No File
BHO-X64: Babylon toolbar helper: {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll
BHO-X64:     Babylon toolbar helper - No File
BHO-X64: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO-X64: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll
BHO-X64:     Norton Identity Protection - No File
BHO-X64: CescrtHlpr Object: {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll
BHO-X64:     facemoods Helper - No File
BHO-X64: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\IPS\IPSBHO.DLL
BHO-X64:     Norton Vulnerability Protection - No File
BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO-X64:     Search Helper - No File
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
BHO-X64:     URLRedirectionBHO - No File
BHO-X64: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll
BHO-X64: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: TBLA06779 Class: {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll
BHO-X64:     TBLA06779 - No File
TB-X64: ListenArabic Toolbar: {F569CF08-EDF6-4FAB-8C8A-EEC184358372} - C:\Program Files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll
TB-X64: C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll
TB-X64: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll
TB-X64: Babylon Toolbar: {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarTlbr.dll
TB-X64: facemoods Toolbar: {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll
mRun-x64: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun-x64: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
mRun-x64: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun-x64: [SecureW2 Tray] C:\Program Files (x86)\SecureW2\sw2_tray.exe
mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [NBAgent] "C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" /WinStart
mRun-x64: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
mRun-x64: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe" /md I
mRun-x64: [TkBellExe] "C:\Program Files (x86)\real\realplayer\update\realsched.exe"  -osboot
mRun-x64: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun-x64: [(Default)]
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
SEH-X64: EasyBits ShellExecute Hook: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWow64\EZUPBH~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\marina\AppData\Roaming\Mozilla\Firefox\Profiles\2y9b2iki.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.soas.ac.uk/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=2&q=
FF - prefs.js: network.proxy.gopher -
FF - prefs.js: network.proxy.type - 4
FF - plugin: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\npBrowserPlugin.dll
FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Users\marina\AppData\Roaming\Move Networks\plugins\npqmp071700000016.dll
FF - plugin: C:\Users\marina\AppData\Roaming\Mozilla\Firefox\Profiles\2y9b2iki.default\extensions\[email protected]\plugins\NPLoaderFF.dll
FF - plugin: C:\Users\marina\AppData\Roaming\Mozilla\plugins\np-mswmp.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true
.
============= SERVICES / DRIVERS ===============
.
R0 NBVol;Nero Backup Volume Filter Driver;C:\Windows\system32\DRIVERS\NBVol.sys --> C:\Windows\system32\DRIVERS\NBVol.sys [?]
R0 NBVolUp;Nero Backup Volume Upper Filter Driver;C:\Windows\system32\DRIVERS\NBVolUp.sys --> C:\Windows\system32\DRIVERS\NBVolUp.sys [?]
R0 SymDS;Symantec Data Store;C:\Windows\system32\drivers\NISx64\1305000.091\SYMDS64.SYS --> C:\Windows\system32\drivers\NISx64\1305000.091\SYMDS64.SYS [?]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\system32\drivers\NISx64\1305000.091\SYMEFA64.SYS --> C:\Windows\system32\drivers\NISx64\1305000.091\SYMEFA64.SYS [?]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\BASHDefs\20120215.001\BHDrvx64.sys [2012-2-16 1157240]
R1 ccSet_NIS;Norton Internet Security Settings Manager;C:\Windows\system32\drivers\NISx64\1305000.091\ccSetx64.sys --> C:\Windows\system32\drivers\NISx64\1305000.091\ccSetx64.sys [?]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\IPSDefs\20120224.002\IDSviA64.sys [2012-2-24 488568]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 SymIRON;Symantec Iron Driver;C:\Windows\system32\drivers\NISx64\1305000.091\Ironx64.SYS --> C:\Windows\system32\drivers\NISx64\1305000.091\Ironx64.SYS [?]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\system32\Drivers\NISx64\1305000.091\SYMNETS.SYS --> C:\Windows\system32\Drivers\NISx64\1305000.091\SYMNETS.SYS [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2010-6-30 89600]
R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-13 20992]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624]
R2 ezSharedSvc;Easybits Shared Services for Windows;C:\Windows\system32\svchost.exe -k netsvcs [2009-7-13 20992]
R2 Giraffic;Veoh Giraffic Video Accelerator;C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe --service --> C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe --service [?]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-3-28 94264]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-5-4 652360]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-9-23 641832]
R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\ccsvchst.exe [2012-1-31 138248]
R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2011-10-12 4700824]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776]
R3 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-11-7 227896]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-2-7 138360]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;C:\Windows\system32\drivers\IntcHdmi.sys --> C:\Windows\system32\drivers\IntcHdmi.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys --> C:\Windows\system32\DRIVERS\Sftfslh.sys [?]
R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys --> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?]
R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys --> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?]
R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys --> C:\Windows\system32\DRIVERS\Sftvollh.sys [?]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-31 136176]
S2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-9-9 86072]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-31 136176]
S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys --> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS --> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS --> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS --> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
.
=============== Created Last 30 ================
.
2012-02-26 17:00:58   --------   d-----w-   C:\Users\marina\AppData\Local\{D99E6408-6589-41E0-BA0D-B098D5082C64}
2012-02-26 17:00:30   --------   d-----w-   C:\Users\marina\AppData\Local\{017CAE32-ABCB-4464-B7BD-71CF6398EBC9}
2012-02-26 06:42:25   --------   d-----w-   C:\Users\marina\AppData\Roaming\SUPERAntiSpyware.com
2012-02-26 06:41:56   --------   d-----w-   C:\Program Files\SUPERAntiSpyware
2012-02-26 06:41:55   --------   d-----w-   C:\ProgramData\SUPERAntiSpyware.com
2012-02-26 00:32:43   --------   d-----w-   C:\Users\marina\AppData\Local\{7B3394B8-F42F-43EC-B37C-0808475E0F16}
2012-02-26 00:32:16   --------   d-----w-   C:\Users\marina\AppData\Local\{9A0DD797-9B50-4819-A68C-C6B440A483E8}
2012-02-23 08:39:58   --------   d-----w-   C:\Users\marina\AppData\Local\{B43DA613-BCA4-40B9-AD3B-188ABD753A68}
2012-02-23 08:39:42   --------   d-----w-   C:\Users\marina\AppData\Local\{D4045162-63B9-4EE8-B67B-8A5461CFD840}
2012-02-22 12:39:28   --------   d-----w-   C:\Users\marina\AppData\Local\{97F142C7-5B8D-4A3E-A2A5-F3E075451A80}
2012-02-22 12:39:12   --------   d-----w-   C:\Users\marina\AppData\Local\{BA3EEA9B-68BC-4BF4-9CF2-5A6ACEE01010}
2012-02-21 22:08:25   --------   d-----w-   C:\Users\marina\AppData\Local\{1AB97308-BA12-4912-B470-90ACD4BF5D01}
2012-02-21 22:08:24   --------   d-----w-   C:\Users\marina\AppData\Local\{C5C365A5-EFDF-4565-B8BC-CC390EF098B3}
2012-02-21 10:07:54   --------   d-----w-   C:\Users\marina\AppData\Local\{12C36157-1412-492B-B45A-CE97FC6F213D}
2012-02-20 22:07:14   --------   d-----w-   C:\Users\marina\AppData\Local\{4E76EBDC-2BA3-485B-ADA7-9850A2986377}
2012-02-20 10:06:37   --------   d-----w-   C:\Users\marina\AppData\Local\{D2663F44-A3B5-49E7-A18C-4584E6E55E7C}
2012-02-20 10:06:26   --------   d-----w-   C:\Users\marina\AppData\Local\{8E61D92A-2012-4E61-92B0-36ED0DD0551B}
2012-02-20 10:06:14   --------   d-----w-   C:\Users\marina\AppData\Local\{C41EBCCA-1024-4F31-A7DE-4182EA5AEE21}
2012-02-19 22:05:36   --------   d-----w-   C:\Users\marina\AppData\Local\{D596DBB8-6166-4F26-A3CC-97BA84205D87}
2012-02-19 10:04:58   --------   d-----w-   C:\Users\marina\AppData\Local\{CE09F457-4120-4A65-A4CA-1330AD011899}
2012-02-19 10:04:35   --------   d-----w-   C:\Users\marina\AppData\Local\{587E0FB2-D6A6-4338-A830-DA39D588B73A}
2012-02-18 22:04:06   --------   d-----w-   C:\Users\marina\AppData\Local\{BD466FBC-807A-4DD3-9FEE-011813B72995}
2012-02-18 22:03:43   --------   d-----w-   C:\Users\marina\AppData\Local\{2618F9A5-29EA-4A4D-84C0-E1567B27660E}
2012-02-18 10:02:48   --------   d-----w-   C:\Users\marina\AppData\Local\{126B6BC5-CA38-4B1B-93A4-963E230286A2}
2012-02-18 10:02:33   --------   d-----w-   C:\Users\marina\AppData\Local\{AC00071A-AF7F-4B73-9953-97B1F8E36CDF}
2012-02-17 20:43:15   --------   d-----w-   C:\Users\marina\AppData\Local\{C3ECA418-0C05-4FF2-8E0D-B129A50FC09B}
2012-02-17 08:42:38   --------   d-----w-   C:\Users\marina\AppData\Local\{C3ADA18E-767E-43C9-A061-A2358AEE4C9E}
2012-02-16 20:36:22   --------   d-----w-   C:\Users\marina\AppData\Local\{924BA057-6F9B-4A3A-A8B1-4D8C90EE447B}
2012-02-16 20:35:59   --------   d-----w-   C:\Users\marina\AppData\Local\{4F9BB7C1-12ED-44B3-B6F0-DE4000F0CB80}
2012-02-16 08:35:11   --------   d-----w-   C:\Users\marina\AppData\Local\{77C03757-398F-4C92-944D-7A8BE2F52026}
2012-02-16 08:34:57   --------   d-----w-   C:\Users\marina\AppData\Local\{052B150C-50F3-4941-B5FE-72B1518C4B10}
2012-02-15 12:20:37   --------   d-----w-   C:\Users\marina\AppData\Local\{74F3AED9-B0F5-4602-B279-BCDAD2BC8E48}
2012-02-15 08:30:29   509952   ----a-w-   C:\Windows\System32\ntshrui.dll
2012-02-15 08:30:29   442880   ----a-w-   C:\Windows\SysWow64\ntshrui.dll
2012-02-15 08:30:28   515584   ----a-w-   C:\Windows\System32\timedate.cpl
2012-02-15 08:30:28   478720   ----a-w-   C:\Windows\SysWow64\timedate.cpl
2012-02-15 08:30:27   3145728   ----a-w-   C:\Windows\System32\win32k.sys
2012-02-15 08:30:25   498688   ----a-w-   C:\Windows\System32\drivers\afd.sys
2012-02-15 08:30:21   690688   ----a-w-   C:\Windows\SysWow64\msvcrt.dll
2012-02-15 08:30:21   634880   ----a-w-   C:\Windows\System32\msvcrt.dll
2012-02-15 00:19:59   --------   d-----w-   C:\Users\marina\AppData\Local\{3BB23024-0975-41F4-984D-02144E1C502E}
2012-02-14 12:19:20   --------   d-----w-   C:\Users\marina\AppData\Local\{B724E541-12D0-4293-9234-3F8811FA1436}
2012-02-14 07:24:00   --------   d-----w-   C:\ProgramData\{A8DA1505-E615-42BB-BB77-74D5CC91FE7E}
2012-02-14 00:18:20   --------   d-----w-   C:\Users\marina\AppData\Local\{D70CBE41-0C86-4C65-B9B0-90EBB3656462}
2012-02-14 00:17:51   --------   d-----w-   C:\Users\marina\AppData\Local\{2DF0ACF9-7C36-4BFC-AB1A-F50144FD263A}
2012-02-13 18:22:30   476904   ----a-w-   C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2012-02-13 12:17:20   --------   d-----w-   C:\Users\marina\AppData\Local\{78709EDC-D9DF-4FAA-B978-4F0C8EECA182}
2012-02-12 23:46:13   --------   d-----w-   C:\Users\marina\AppData\Local\{01E5DAFD-20A9-41A8-8CEB-39D71ADEB301}
2012-02-12 11:45:25   --------   d-----w-   C:\Users\marina\AppData\Local\{0DBEC31D-3AD8-4ACF-9125-35026BEEA5FF}
2012-02-11 23:44:44   --------   d-----w-   C:\Users\marina\AppData\Local\{03A3DD3A-381D-4766-B47F-963AC65A6073}
2012-02-11 11:44:06   --------   d-----w-   C:\Users\marina\AppData\Local\{05DAA6DF-7F93-4CFF-9738-2CA0C9D0F4F1}
2012-02-10 23:43:28   --------   d-----w-   C:\Users\marina\AppData\Local\{995C33D3-81ED-4CE6-BDD1-808493D106FE}
2012-02-10 11:42:50   --------   d-----w-   C:\Users\marina\AppData\Local\{4AE3DEC7-9062-4007-A279-B66B3E8730FF}
2012-02-10 11:42:27   --------   d-----w-   C:\Users\marina\AppData\Local\{3A212164-740A-4E05-917B-A7911CB7F5B3}
2012-02-09 23:41:58   --------   d-----w-   C:\Users\marina\AppData\Local\{D0F2561A-ABB6-49FE-AD44-CCFEE1776D1E}
2012-02-09 23:41:35   --------   d-----w-   C:\Users\marina\AppData\Local\{820FF5C9-CAD9-4878-916E-9A9693222499}
2012-02-09 11:41:03   --------   d-----w-   C:\Users\marina\AppData\Local\{46BB1FD4-FA32-4874-8611-9F03C8ADD4B1}
2012-02-09 11:40:48   --------   d-----w-   C:\Users\marina\AppData\Local\{522FD6FD-35B5-4EFA-8956-3EDBF4FC889B}
2012-02-08 23:20:59   --------   d-----w-   C:\Users\marina\AppData\Local\{A1515CB7-60EC-4EBE-B810-ACDC8335B1C4}
2012-02-08 11:20:20   --------   d-----w-   C:\Users\marina\AppData\Local\{F5B578C9-5CD3-4634-BD10-1748A17622E3}
2012-02-08 11:19:57   --------   d-----w-   C:\Users\marina\AppData\Local\{844A91F3-4EAC-4F93-AB07-90FD02E213DC}
2012-02-07 23:19:39   --------   d-----w-   C:\Users\marina\AppData\Local\{E311FC56-9106-431B-ABBF-541F55441850}
2012-02-07 23:19:38   --------   d-----w-   C:\Users\marina\AppData\Local\{ED473BA8-D36B-4CC6-AF40-E7E825D5E9E0}
2012-02-07 11:14:57   --------   d-----w-   C:\Users\marina\AppData\Local\{2F574A1E-401A-4DC7-8152-AFCB215E36BE}
2012-02-06 23:14:21   --------   d-----w-   C:\Users\marina\AppData\Local\{F11D66AB-3D23-4C4F-AAE6-2CDE923A2BB4}
2012-02-06 11:13:56   --------   d-----w-   C:\Users\marina\AppData\Local\{413950EE-612C-4232-9FE2-54DAD651D1BC}
2012-02-05 23:04:19   --------   d-----w-   C:\Users\marina\AppData\Local\{EC815D95-A1D6-4FB4-8621-5720BC3965F3}
2012-02-05 11:03:53   --------   d-----w-   C:\Users\marina\AppData\Local\{B4A3F3B2-0DEB-429E-A68B-21657163FA17}
2012-02-04 23:03:17   --------   d-----w-   C:\Users\marina\AppData\Local\{72C8D4C3-737F-48F8-BBC9-C124517ABFEC}
2012-02-04 11:02:40   --------   d-----w-   C:\Users\marina\AppData\Local\{21DED89F-1A40-4A58-A0E2-3C12C91921A8}
2012-02-03 23:02:02   --------   d-----w-   C:\Users\marina\AppData\Local\{D9BB0D6C-88D8-4667-A835-8B12002AB044}
2012-02-03 11:01:25   --------   d-----w-   C:\Users\marina\AppData\Local\{DAE1B859-76F7-49A2-B171-7F77C912D2DC}
2012-02-02 22:15:39   --------   d-----w-   C:\Users\marina\AppData\Local\{A08348E7-39C5-4B5A-83F3-FE03786D12A3}
2012-02-02 10:17:37   --------   d-----w-   C:\Program Files\iTunes
2012-02-02 10:14:57   --------   d-----w-   C:\Users\marina\AppData\Local\{38D86300-CED2-4D9E-B700-48EE7B230496}
2012-02-02 10:14:31   --------   d-----w-   C:\Users\marina\AppData\Local\{7ADF098C-749A-4355-BBB2-89940D6641E5}
2012-02-02 10:08:43   --------   d-----w-   C:\Program Files\Bonjour
2012-02-02 10:08:43   --------   d-----w-   C:\Program Files (x86)\Bonjour
2012-02-02 02:37:00   120368   ----a-w-   C:\Windows\SysWow64\ezuninst.exe
2012-02-02 02:37:00   117808   ----a-w-   C:\Windows\SysWow64\ezshellstart.exe
2012-02-01 22:14:01   --------   d-----w-   C:\Users\marina\AppData\Local\{960D9650-F51E-4D72-BEFC-87632EED221A}
2012-02-01 10:13:20   --------   d-----w-   C:\Users\marina\AppData\Local\{9DE140E0-297F-4FBD-A374-A23F604D51D3}
2012-02-01 10:12:56   --------   d-----w-   C:\Users\marina\AppData\Local\{7B3F2776-4D10-4B94-A3A7-A66F73565F63}
2012-01-31 22:13:17   --------   d-----w-   C:\Users\marina\AppData\Local\WiredRed
2012-01-31 22:12:37   --------   d-----w-   C:\Users\marina\AppData\Local\{1C8565F4-D7F5-45C3-A854-ADBD047AF93D}
2012-01-31 22:12:36   --------   d-----w-   C:\Users\marina\AppData\Local\{45514A8E-1666-445B-AB59-B94A6B1EEB21}
2012-01-31 12:52:20   738936   ----a-w-   C:\Windows\System32\drivers\NISx64\1305000.091\srtsp64.sys
2012-01-31 12:52:20   451192   ----a-r-   C:\Windows\System32\drivers\NISx64\1305000.091\symds64.sys
2012-01-31 12:52:20   405624   ----a-w-   C:\Windows\System32\drivers\NISx64\1305000.091\symnets.sys
2012-01-31 12:52:20   37496   ----a-w-   C:\Windows\System32\drivers\NISx64\1305000.091\srtspx64.sys
2012-01-31 12:52:20   190072   ----a-w-   C:\Windows\System32\drivers\NISx64\1305000.091\ironx64.sys
2012-01-31 12:52:20   1092728   ----a-w-   C:\Windows\System32\drivers\NISx64\1305000.091\symefa64.sys
2012-01-31 12:52:19   167048   ----a-w-   C:\Windows\System32\drivers\NISx64\1305000.091\ccsetx64.sys
2012-01-31 12:52:04   --------   d-----w-   C:\Windows\System32\drivers\NISx64\1305000.091
2012-01-31 10:12:09   --------   d-----w-   C:\Users\marina\AppData\Local\{CE0C35F1-DC5D-4FA3-A1F5-2F652B6631D9}
2012-01-30 22:11:30   --------   d-----w-   C:\Users\marina\AppData\Local\{DB1F1FBB-08BB-483D-BA17-96358785683C}
2012-01-30 10:10:54   --------   d-----w-   C:\Users\marina\AppData\Local\{55263DC9-BDC6-40F4-9C9B-6B4998AF84A2}
2012-01-29 22:10:17   --------   d-----w-   C:\Users\marina\AppData\Local\{2EF1D81D-ADE2-469F-84EC-EE9BD5A71825}
2012-01-29 10:09:41   --------   d-----w-   C:\Users\marina\AppData\Local\{A1EB882C-65CE-403B-BB40-45048E796CB6}
2012-01-28 21:26:45   --------   d-----w-   C:\Users\marina\AppData\Local\{E4CC6B2D-86DD-4570-9292-89EAB488CFFD}
2012-01-28 09:26:09   --------   d-----w-   C:\Users\marina\AppData\Local\{66588035-62A9-4C49-970B-F5D68FD54D62}
.
==================== Find3M  ====================
.
2012-02-25 21:15:15   472808   ----a-w-   C:\Windows\SysWow64\deployJava1.dll
2012-02-07 11:43:54   60   ----a-w-   C:\Windows\wpd99.drv
2012-01-31 12:52:30   175736   ----a-w-   C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2012-01-22 21:13:10   414368   ----a-w-   C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-12-14 07:11:03   2308096   ----a-w-   C:\Windows\System32\jscript9.dll
2011-12-14 07:04:30   1390080   ----a-w-   C:\Windows\System32\wininet.dll
2011-12-14 07:03:38   1493504   ----a-w-   C:\Windows\System32\inetcpl.cpl
2011-12-14 06:57:28   2382848   ----a-w-   C:\Windows\System32\mshtml.tlb
2011-12-14 03:04:54   1798656   ----a-w-   C:\Windows\SysWow64\jscript9.dll
2011-12-14 02:57:18   1127424   ----a-w-   C:\Windows\SysWow64\wininet.dll
2011-12-14 02:56:58   1427456   ----a-w-   C:\Windows\SysWow64\inetcpl.cpl
2011-12-14 02:50:04   2382848   ----a-w-   C:\Windows\SysWow64\mshtml.tlb
2011-12-10 15:24:08   23152   ----a-w-   C:\Windows\System32\drivers\mbam.sys
2011-12-01 08:18:06   499712   ----a-w-   C:\Windows\SysWow64\msvcp71.dll
2011-12-01 08:18:06   348160   ----a-w-   C:\Windows\SysWow64\msvcr71.dll
.
============= FINISH:  3:50:48.48 ===============
And the attach

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 01/04/2010 11:52:49
System Uptime: 27/02/2012 00:17:23 (3 hours ago)
.
Motherboard: Hewlett-Packard |  | 3069
Processor: Pentium(R) Dual-Core CPU       T4300  2.10GHz | CPU | 2100/800mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 285 GiB total, 161.411 GiB free.
D: is FIXED (NTFS) - 12 GiB total, 2.048 GiB free.
E: is CDROM (CDFS)
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP229: 13/02/2012 18:20:55 - Installed Java(TM) 6 Update 30
RP230: 14/02/2012 07:24:16 - Installed HP Support Assistant
RP231: 14/02/2012 07:28:34 - Windows Modules Installer
RP232: 14/02/2012 07:29:44 - Windows Modules Installer
RP233: 14/02/2012 18:08:47 - HPSF Applying updates
RP234: 16/02/2012 08:35:27 - Windows Update
RP235: 16/02/2012 16:30:43 - Windows Update
RP236: 18/02/2012 16:48:22 - Windows Update
RP237: 25/02/2012 21:02:52 - Installed Java(TM) 6 Update 31
.
==== Installed Programs ======================
.
7-Zip 9.20
Acrobat.com
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Reader X (10.1.2)
Adobe Shockwave Player
Akamai NetSession Interface
Akamai NetSession Interface Service
Apple Application Support
Apple Software Update
Babylon toolbar on IE
BBC iPlayer Desktop
Bing Bar
Bing Bar Platform
Camera Access Library
Camera Support Core Library
Camera Window DS
Camera Window DVC
Camera Window MC
Canon Camera Access Library
Canon Camera Support Core Library
Canon Camera Window DC_DV 5 for ZoomBrowser EX
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window DSLR 5 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
CANON iMAGE GATEWAY Task
CANON iMAGE GATEWAY Task for ZoomBrowser EX
Canon Internet Library for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon Utilities PhotoStitch 3.1
Canon ZoomBrowser EX (E)
Compatibility Pack for the 2007 Office system
CyberLink DVD Suite
CyberLink MediaShow
CyberLink PowerDVD 8
CyberLink YouCam
D3DX10
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Dropbox
Dudeism.com Relaxer
Easy Burner
EndNote
ERUNT 1.1j
ESET Online Scanner v3
Facemoods Toolbar
FreeMind
FYZip 1.00
GamePlayLabs Plugin
Google Chrome
Google Update Helper
Hewlett-Packard ACLM.NET v1.1.2.0
High-Definition Video Playback
HP Advisor
HP Customer Experience Enhancements
HP Games
HP Quick Launch Buttons
HP Setup
HP Support Assistant
HP Update
HP User Guides 0148
HP Wireless Assistant
Huawei modem
IDT Audio
Internet Library
ISI ResearchSoft - Export Helper
Java Auto Updater
Java(TM) 6 Update 31
Junk Mail filter update
KeePass Password Safe 1.19b
LabelPrint
LightScribe System Software
ListenArabic Toolbar
Magic Desktop
Malwarebytes Anti-Malware version 1.60.1.1000
McAfee Security Scan Plus
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Click-to-Run 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Home and Business 2010 - English
Microsoft Office Home and Student 2010
Microsoft Office Live Add-in 1.5
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Single Image 2010
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2010
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
Microsoft Works
Moozy
Move Media Player
MovieEdit Task
Mozilla Firefox 10.0.2 (x86 en-US)
MSVCRT
MSVCRT_amd64
muvee Reveal
Nero 11
Nero 11 Disc Menus Basic
Nero 11 Effects Basic
Nero 11 Image Samples
Nero 11 Kwik Themes Basic
Nero 11 PiP Effects Basic
Nero Audio Pack 1
Nero BackItUp 11
Nero BackItUp 11 Help (CHM)
Nero Burning ROM 11
Nero Burning ROM 11 Help (CHM)
Nero ControlCenter 11
Nero ControlCenter 11 Help (CHM)
Nero Core Components 11
Nero CoverDesigner 11
Nero CoverDesigner 11 Help (CHM)
Nero Express 11
Nero Express 11 Help (CHM)
Nero Kwik Media
Nero Kwik Media Help (CHM)
Nero Recode 11
Nero Recode 11 Help (CHM)
Nero RescueAgent 11
Nero RescueAgent 11 Help (CHM)
Nero SoundTrax 11
Nero SoundTrax 11 Help (CHM)
Nero Update
Nero Video 11
Nero Video 11 Help (CHM)
Nero WaveEditor 11
Nero WaveEditor 11 Help (CHM)
nero.prerequisites.msi
Norton Internet Security
Norton Online Backup
Pdf995
PhotoStitch
Power2Go
PowerDirector
PriceGong 2.5.2
QLBCASL
QuickTime
RAW Image Task 2.2
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek 8136 8168 8169 Ethernet Driver
Realtek USB 2.0 Card Reader
RealUpgrade 1.1
Recovery Manager
Safari
SecureW2 Enterprise Client 3.4.6
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft Office 2010 (KB2553091)
Security Update for Microsoft Office 2010 (KB2553096)
Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition
Security Update for Microsoft SharePoint Workspace 2010 (KB2566445)
Security Update for Microsoft Visio Viewer 2010 (KB2597170) 32-Bit Edition
Signature995
Skype™ 5.5
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft Excel 2010 (KB2553439) 32-Bit Edition
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553385) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2597091) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2553323) 32-Bit Edition
Update for Microsoft Outlook Social Connector (KB2583935)
Veoh Giraffic Video Accelerator
Veoh Web Player
welcome
Windows iLivid Toolbar
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WOT for Internet Explorer
.
==== Event Viewer Messages From Past Week ========
.
27/02/2012 03:44:51, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the NIS service.
26/02/2012 23:18:35, Error: Service Control Manager [7022]  - The Windows Update service hung on starting.
26/02/2012 23:13:58, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the HP Support Assistant Service service to connect.
26/02/2012 23:13:58, Error: Service Control Manager [7000]  - The HP Support Assistant Service service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
26/02/2012 06:05:24, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the iphlpsvc service.
26/02/2012 06:04:54, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the RasMan service.
26/02/2012 00:31:37, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Windows Presentation Foundation Font Cache 3.0.0.0 service to connect.
26/02/2012 00:31:37, Error: Service Control Manager [7000]  - The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
26/02/2012 00:27:43, Error: Service Control Manager [7001]  - The Client Virtualization Handler service depends on the Application Virtualization Client service which failed to start because of the following error:  The service did not respond to the start or control request in a timely fashion.
26/02/2012 00:27:40, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Application Virtualization Client service to connect.
26/02/2012 00:27:40, Error: Service Control Manager [7000]  - The Application Virtualization Client service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
24/02/2012 09:46:38, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Windows Error Reporting Service service to connect.
24/02/2012 04:25:31, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Browser service.
24/02/2012 04:25:31, Error: Service Control Manager [7000]  - The Computer Browser service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
.
==== End Of File ===========================
One thing that might be of significance is that I did not disable Norton Internet security while I was running the DDSs. If you think this will affect the result please let me know and I will do it again with the Norton disabled Download OTL to your desktop.

* Open OTL
* Copy and Paste the following text in the codebox into the Custom Scans/Fixes window.

Code: [Select]:OTL

BHO: Shopping Assistant Plugin: {1631550f-191d-4826-b069-d9439253d926} - C:\Program Files (x86)\PriceGong\2.5.2\PriceGongIE.dll
BHO: Babylon toolbar helper: {2eecd738-5844-4a99-b4b6-146bf802613b} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll
BHO: CescrtHlpr Object: {64182481-4f71-486b-a045-b233bd0da8fc} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll
TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarTlbr.dll
TB: facemoods Toolbar: {db4e9724-f518-4dfd-9c7c-78b52103cab9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll
mRun: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe" /md I
BHO-X64:     PriceGong - No File
BHO-X64:     AcroIEHelperStub - No File
BHO-X64: Babylon toolbar helper: {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll
BHO-X64:     Babylon toolbar helper - No File
BHO-X64: CescrtHlpr Object: {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll
BHO-X64:     facemoods Helper - No File
BHO-X64:     Search Helper - No File
BHO-X64:     URLRedirectionBHO - No File
BHO-X64:     TBLA06779 - No File
TB-X64: facemoods Toolbar: {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll
mRun-x64: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe" /md I

:folders
C:\Program Files (x86)\PriceGong
C:\Program Files (x86)\BabylonToolbar\BabylonToolbar
C:\Program Files (x86)\facemoods.com\facemoods

:COMMANDS
[resethosts]
[purity]
[start explorer]

* Click Run Fix
* OTLI2 may ask to reboot the machine. Please do so if asked.
* Click OK
* A report will open. Copy and Paste that report in your next reply.
************************************************************
Download Combofix from any of the links below, and save it to your desktop

Link 1
Link 2
Link 3

To prevent your anti-virus application interfering with  ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.
  • Close any open windows and double click ComboFix.exe to run it.

    You will see the following image:


Click I Agree to start the program.

ComboFix will then extract the necessary files and you will see this:



As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to  have this pre-installed on your machine before doing any malware  removal. This will not occur in Windows Vista and 7

It will allow you to boot up into a special recovery/repair  mode that will allow us to more easily help you should your computer  have a problem after an attempted removal of malware.

If you did not have it installed, you will see the prompt below. Choose YES.



Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.Still problem with the script. While I was trying to talk on Skype the following appeared

A script on this page may be busy, or it may have stopped responding. You can stop the script now, or you can continue to see if the script will complete.

Script: http://mail.yimg.com/zz/combo?nq/3909/yui/yui-min.js&nq/3909/oop/oop-min.js&nq/3909/dom/dom-min.js&nq/3909/event/event-min.js&nq/3909/event-custom/event-custom-min.js&nq/3909/base/base-base-min.js&nq/3909/plugin/plugin-min.js&nq/3909/pluginhost/pluginhost-min.js&nq/3909/node/node-min.js&nq/3909/attribute/attribute-min.js&nq/3909/json/json-min.js&nq/3909/intl/intl-min.js&nq/3909/datatype/lang/datatype-date.js&nq/3909/datatype/datatype-date-min.js&nq/3909/datatype/datatype-xml-min.js&nq/3909/cookie/cookie-min.js&nq/3909/async-queue/async-queue-min.js&nq/3909/collection/array-extras-min.js&nq/3909/querystring/querystring-parse-simple-min.js&nq/3909/querystring/querystring-stringify-simple-min.js&nq/3909/loader/loader-min.js:13OTL did not ask me to reboot. This is the log. Is there something wrong? I will try to do it once again

========== OTL ==========
Error: Unable to interpret <:folders> in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.33.2 log created on 02272012_224127
I tried again. Same message. Hope is fineThat's ok. Please uninstall these programs
Babylon toolbar on IE
Facemoods Toolbar
PriceGong 2.5.2

They are malicious.
Then, please proceed with ComboFix.
Thanks. I deleted the programs you told me and run ComboFix (it took several attempts, quite some time and a reboot)

When I tried to open any of the different browsers so that I could send you the log the following message appeared

"c:\Program Files (x86) Mozilla Firefox/firefox.exe
Illegal Operation attempted on a registry item that has been marked to delete"

The same with IE and Google Chrone

Fortunately it worked OK after another reboot but I just thought I will tell you anyway

Also: while I have been trying to write this the following message appeared

"A script on this page may be busy, or it may have stopped responding. You can stop the script now, or you can continue to see if the script will complete.

Script: http://d3lvr7yuk4uaui.cloudfront.net/items/it/js/itn.js:46"

I get those messages daily sometimes several times. I am tired of them. Any suggestions as to what to do?And the Combo Fix log

ComboFix 12-02-27.02 - marina 28/02/2012  20:50:35.10.2 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.44.1033.18.3999.1950 [GMT 0:00]
Running from: c:\users\marina\Desktop\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\boost_interprocess\20120228140443.359599
c:\programdata\boost_interprocess\20120228140443.359599\Nobu64AgentService
c:\programdata\boost_interprocess\20120228140443.359599\Nobu64TrayIcon
.
.
(((((((((((((((((((((((((   Files Created from 2012-01-28 to 2012-02-28  )))))))))))))))))))))))))))))))
.
.
2012-02-28 21:18 . 2012-02-28 21:18   --------   d-----w-   c:\users\Public\AppData\Local\temp
2012-02-28 21:18 . 2012-02-28 21:18   --------   d-----w-   c:\users\Default\AppData\Local\temp
2012-02-27 22:41 . 2012-02-27 22:41   --------   d-----w-   C:\_OTL
2012-02-26 06:42 . 2012-02-26 06:42   --------   d-----w-   c:\users\marina\AppData\Roaming\SUPERAntiSpyware.com
2012-02-26 06:41 . 2012-02-26 06:44   --------   d-----w-   c:\program files\SUPERAntiSpyware
2012-02-26 06:41 . 2012-02-26 06:41   --------   d-----w-   c:\programdata\SUPERAntiSpyware.com
2012-02-25 21:17 . 2012-02-25 21:17   --------   d-----w-   c:\program files (x86)\Common Files\Java
2012-02-15 08:30 . 2012-01-04 10:44   509952   ----a-w-   c:\windows\system32\ntshrui.dll
2012-02-15 08:30 . 2012-01-04 08:58   442880   ----a-w-   c:\windows\SysWow64\ntshrui.dll
2012-02-15 08:30 . 2011-12-30 06:26   515584   ----a-w-   c:\windows\system32\timedate.cpl
2012-02-15 08:30 . 2011-12-30 05:27   478720   ----a-w-   c:\windows\SysWow64\timedate.cpl
2012-02-15 08:30 . 2012-01-14 04:06   3145728   ----a-w-   c:\windows\system32\win32k.sys
2012-02-15 08:30 . 2011-12-28 03:59   498688   ----a-w-   c:\windows\system32\drivers\afd.sys
2012-02-15 08:30 . 2011-12-16 08:46   634880   ----a-w-   c:\windows\system32\msvcrt.dll
2012-02-15 08:30 . 2011-12-16 07:52   690688   ----a-w-   c:\windows\SysWow64\msvcrt.dll
2012-02-14 07:24 . 2012-02-14 07:24   --------   d-----w-   c:\programdata\{A8DA1505-E615-42BB-BB77-74D5CC91FE7E}
2012-02-13 18:22 . 2012-02-25 21:15   476904   ----a-w-   c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2012-02-02 10:12 . 2012-02-02 10:12   159744   ----a-w-   c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
2012-02-02 10:08 . 2012-02-02 10:08   --------   d-----w-   c:\program files\Bonjour
2012-02-02 10:08 . 2012-02-02 10:08   --------   d-----w-   c:\program files (x86)\Bonjour
2012-02-02 02:37 . 2012-02-02 02:37   120368   ----a-w-   c:\windows\SysWow64\ezuninst.exe
2012-02-02 02:37 . 2012-02-02 02:37   117808   ----a-w-   c:\windows\SysWow64\ezshellstart.exe
2012-01-31 22:13 . 2012-02-22 20:20   --------   d-----w-   c:\users\marina\AppData\Local\WiredRed
2012-01-31 12:52 . 2012-02-01 00:44   --------   d-----w-   c:\windows\system32\drivers\NISx64\1305000.091
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-25 21:15 . 2010-05-02 11:55   472808   ----a-w-   c:\windows\SysWow64\deployJava1.dll
2012-01-31 12:52 . 2011-05-12 15:12   175736   ----a-w-   c:\windows\system32\drivers\SYMEVENT64x86.SYS
2012-01-22 21:13 . 2011-06-12 05:22   414368   ----a-w-   c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-12-10 15:24 . 2011-05-04 13:55   23152   ----a-w-   c:\windows\system32\drivers\mbam.sys
2011-12-01 08:18 . 2011-12-01 08:18   499712   ----a-w-   c:\windows\SysWow64\msvcp71.dll
2011-12-01 08:18 . 2011-12-01 08:18   348160   ----a-w-   c:\windows\SysWow64\msvcr71.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{F569CF08-EDF6-4FAB-8C8A-EEC184358372}"= "c:\program files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll" [2009-06-02 2695168]
.
[HKEY_CLASSES_ROOT\clsid\{f569cf08-edf6-4fab-8c8a-eec184358372}]
[HKEY_CLASSES_ROOT\TBLA06779.TBLA06779.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBLA06779.TBLA06779]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12   94208   ----a-w-   c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12   94208   ----a-w-   c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12   94208   ----a-w-   c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12   94208   ----a-w-   c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2011-03-04 2741616]
"HPADVISOR"="c:\program files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2010-06-30 1689144]
"VeohPlugin"="c:\program files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2011-08-25 2816328]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"Akamai NetSession Interface"="c:\users\marina\AppData\Local\Akamai\netsession_win.exe" [2012-02-02 3329824]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2010-02-25 323640]
"Easybits Recovery"="c:\program files (x86)\EasyBits For Kids\ezRecover.exe" [2009-09-02 60464]
"WirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2010-03-23 500792]
"SecureW2 Tray"="c:\program files (x86)\SecureW2\sw2_tray.exe" [2010-07-28 200584]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-11-02 59240]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"NBAgent"="c:\program files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" [2011-09-20 1493288]
"Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2011-10-12 3151000]
"TkBellExe"="c:\program files (x86)\real\realplayer\update\realsched.exe" [2011-12-01 296056]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-01-16 421736]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-31 460872]
.
c:\users\marina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
BBC iPlayer Desktop.lnk -  [N/A]
Dropbox.lnk - c:\users\marina\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-2-14 24246216]
ERUNT AutoBackup.lnk - c:\program files (x86)\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
fliptoast.lnk - c:\program files (x86)\Fliptoast\fliptoast.exe [N/A]
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVH.EXE [2012-1-4 3208032]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages   REG_MULTI_SZ      kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
="Driver"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-31 136176]
R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-09 86072]
R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-02-25 227896]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-31 136176]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys

R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS

R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS

R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe

R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys

S0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\DRIVERS\NBVol.sys

S0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\DRIVERS\NBVolUp.sys

S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1305000.091\SYMDS64.SYS

S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1305000.091\SYMEFA64.SYS

S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\BASHDefs\20120215.001\BHDrvx64.sys [2012-02-07 1157240]
S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NISx64\1305000.091\ccSetx64.sys

S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\IPSDefs\20120225.004\IDSvia64.sys [2011-12-15 488568]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1305000.091\Ironx64.SYS

S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1305000.091\SYMNETS.SYS

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys

S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2010-06-30 89600]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2009-07-14 27136]
S2 Giraffic;Veoh Giraffic Video Accelerator;c:\program files (x86)\Giraffic\Veoh_GirafficWatchdog.exe [2012-01-22 2230416]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-28 94264]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-31 652360]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-09-23 641832]
S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe [2011-11-30 138248]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE

S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-02-07 138360]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys

S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys

S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys

S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys

S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys

S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys

.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai   REG_MULTI_SZ      Akamai
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-03-04 11:29   451872   ----a-w-   c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-31 15:52]
.
2012-02-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-31 15:52]
.
2012-02-26 c:\windows\Tasks\HPCeeScheduleFormarina.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-13 22:15]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12   97792   ----a-w-   c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12   97792   ----a-w-   c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12   97792   ----a-w-   c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12   97792   ----a-w-   c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-10 165912]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-10 387608]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-10 365592]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-06-30 487424]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.alwaraq.net/Core/index.jsp?option=1
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = 127.0.0.1:9421;*.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105
IE: {{F569CF08-EDF6-4FAB-8C8A-EEC184358372} - {F569CF08-EDF6-4FAB-8C8A-EEC184358372} - c:\program files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll
TCP: DhcpNameServer = 193.63.73.32
FF - ProfilePath - c:\users\marina\AppData\Roaming\Mozilla\Firefox\Profiles\2y9b2iki.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.soas.ac.uk/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=2&q=
FF - prefs.js: network.proxy.gopher -
FF - prefs.js: network.proxy.type - 4
FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe
Toolbar-10 - (no file)
WebBrowser-{F569CF08-EDF6-4FAB-8C8A-EEC184358372} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe
AddRemove-Searchqu 406 MediaBar - c:\program files (x86)\Windows iLivid Toolbar\uninstall.exe
AddRemove-{6F44AF95-3CDE-4513-AD3F-6D45F17BF324} - c:\program files (x86)\InstallShield Installation Information\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\19.5.0.145\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\Akamai]
"ServiceDll"="c:\program files (x86)\common files\akamai/netsession_win_7de0ed9.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
Denied: (A 2) (Everyone)
="FlashBroker"
"LocalizedString"="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
Denied: (A 2) (Everyone)
="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
Denied: (A 2) (Everyone)
="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
Denied: (A 2) (Everyone)
="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\CyberLink\Shared files\RichVideo.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Giraffic\Veoh_Giraffic.exe
c:\program files (x86)\Canon\CAL\CALMAIN.exe
.
**************************************************************************
.
Completion time: 2012-02-28  21:33:45 - machine was rebooted
ComboFix-quarantined-files.txt  2012-02-28 21:33
.
Pre-Run: 174,577,553,408 bytes free
Post-Run: 177,564,450,816 bytes free
.
- - End Of File - - FE017AF54B38363089461AA075AD570E
380.

Solve : Gmail hack, returned and....?

Answer»

I was wondering if you would mind helping me (I am very anxious for my problem)

Today on a COMPUTER (without any especial AntiVirus) which is in a public place for everyone I checked my Gmail account by IE and I received a bunch of strange emails. by opening of one of them I was diverted to another person's email and then when I tried to sign in with my username, gmail said you are trying to use your old password. you password has been changed for 33 days. So I was frustrated because even I did not know the security questions; I could not sign in for around 2-3 hours and after that when I tried my password (This time in my personal Computer with ESET Smart security) I could sin in; once I signed in, I changed my password and now I would like to know whether this email address is safe anymore or not? Can I still use this email address KNOWING I have changed my password? Also I would like to know whether there is a risk of getting a keylogger after being hacked? Is keylogger installed on the system or email? When I got hacked I was with a public computer, so this means that if any keyloggers have been installed, they have been installed in that public computer? Right?and Now that I'm USING the email address in my personal computer there is no risk of having a keylogger? Am I right?

In general, also could you please let me know whether using this email is safe or nor?
Also, could you please confirm whether ESET Smart security is anti keylogger as well or not?
Thank you very much

I look forward to hearing from you. Quote

Today on a computer (without any especial AntiVirus) which is in a public place for everyone I checked my Gmail account by IE and I received a bunch of strange emails. by opening of one of them I was diverted to another person's email and then when I tried to sign in with my username, gmail said you are trying to use your old password. you password has been changed for 33 days. So I was frustrated because even I did not know the security questions; I could not sign in for around 2-3 hours and
Is that what happened?
A. Do not rely on public terminals. A mean kind of malicious software called "DNS changer**" might have been present.
B. If you can sign in later on your own PC, the account was not hacked & the password not changed by some other person.

**DNS Changer often picks on Google, but it does not hurt Google directly, it victimizes the user who want to use Google. Tue infection is local to the PC the user has in front of him.
This may be of some interest. About three months ago
FBI tackles DNSChanger malware scam
Hello

Thank you very much for answering and giving some information.

So do you believe that by clicking on that email my DNS changed and I was diverted to another person's email address?

Yes the story is exactly the same thing I described. When I opened (From a public computer which did not any especially Anti viruses) one of the strange emails , I had received, I was directed to another person's email address and after that when I tried to sign in, Google said "You are trying to use your old password. Your password has been changed for 33 days" and I could not sign in to my account for 2-3 hours and even after that I tried from my PC which has an ESET Smart Security and again I could not sign in. However after awhile again I tried and finally my password worked; once I entered my account, I changed my password and I got an email from Gmail saying that my password has been changed 3 times during that day (One when I was hacked and one when I changed by myself and one in between).

So now my question is, if it had been a DNS changer, I would have been able to sign in to my account (the first times that I tried) when I tried it from my personal PC (because this one was not infected). Right? So it could not be a DNS changer. Am I right?

My another question is how come my password after around 4 hours changed to the first password?

And finally My LAST question: Could you please let me know what you think had happened? Was I hacked? Is my Gmail account safe now? Can I still use it? Was it dangerous? .....

Your help is totally appreciated.The problem described in the article only infects the one  computer. Nothing is done to Google Gmail. This problem has been widely reported. And nothing GOES into n your home computer.

The scam gives people the impression that something is wrong and asks for your password.

But you changed your password. So you are out of danger. Be sure and update your security questions.Oh great! Thank you so much

So only the public computer was infected and my Gmail account is safe? So why even at home I could not log in with my password for around 1-2 hours and then it worked? Also I had two other emails saying that my Gmail password was changed in between (between that time I was infected and the time I accessed to my email)?!

Also, could you please let me know based on what you believe is my information ( I mean emails I received or sent) read by a third party?

I do appreciate your help You get locked out of our account when there are a number of attempts to get in. That is a safety feature.

It is a good idea from time to time to change our password and review your security questions.

Others recommend use of acrostic phrase password. Numbers exceptional.
Example:
My Bad  Dog Has 12  Red Fleas.
would be:
MBDH12RF
Of cause, you have to use another one. That one is mine.
Do not use
qwerty
Which is so obvious. I stopped using it.
381.

Solve : Access is denied.?

Answer»

The problem I'm having pertains to a virus/malware problem, I guess. I used the procedure listed here http://tinyurl.com/5sjq6 by myself. I don't have the patience for forums, sadly. The efforts were in vain, end I eventually ended up messing up my hosts file like an idiot. I reversed it by using a system restore point, but now I can't install any PROGRAMS. The only "error" I RECEIVE is a "Access is Denied." However, I'm sole user of this system (so I use an administrator account), went as FAR as TRYING to take "ownership" of my ENTIRE C:\* Drive. But, the problem persists.

382.

Solve : Remove and Reinstall AVG?

Answer»

The AVG on my netbook suddenly doesn't work this morning. The TRAY icon doesn't show up, and when I click the Start Menu shortcut to the AVG User Interface, nothing happen. Same thing when I try to launch from the installed directory.

So I run the installer and choose for repair, but it shows error message half way and said it couldn't continue. I run the installer again and choose remove instead, still same, error message half way.

How can I manually remove it and REINSTALL?

Thanks.download and run the un-installer utility from here http://www.avg.com/us-en/utilities

Once AVG is un-installed download AVAST or AVIRA as they are better than AVG, not as many false possitives and they use less system resorces.

BB

If the AVG un-install utility does not work use Revo un-installer from here  http://www.revouninstaller.com/revo_uninstaller_free_download.htmlGive your computer a treat and download MSE. It will appreciate it.

Microsoft Security Essentials for Windows Vista\Windows 7 - 64 BIT Download
Microsoft Security Essentials for Windows XP
Everything is good and red posts. But that's a very good BALANCE. Quote from: bacon buttie on January 29, 2012, 03:10:09 AM

download AVAST or AVIRA as they are better than AVG, not as many false possitives and they use less system resorces.
I've been using AVG for more than 5 years without any major issue or infection.
I didn't like AVAST because the scan will pause at every threat detected hence I cannot leave it running scan without attending to it.
Never tried AVIRA.
383.

Solve : How do I use MSE to scan internal and external drives??

Answer»

Hello everyone,

I am using MSE for my AV. My Internet is disconnected right now. I know I am not infected, but just in case I would like to scan all external drives, and my internal drives which are connected via USB. I WENT into the MSE settings, and under Advanced I checked the box for the removable drives. I did a full scan, and I also did a Custom scan, but my result scanning time are coming back way too fast. I even have a lot to scan. I wanted to do a full scan on everything including any devices that are attached. HONESTLY, I don't mind the slow wait until MSE is finished scanning. Maybe MSE is not setup the right way?Go into Setting and chose Advanced. Check the box for external devices. Quote from: SuperDave on February 01, 2012, 05:06:29 PM

Go into Setting and chose Advanced. Check the box for external devices.

Hey Dave,

I sent you a thank. I'm not sure if it went through? Anyway, thank you. I have another question for you below?

I have AVG Tune UP, and I have CC Cleaner. Should I get rid one of them? Or both of them? Or keep them both? I have both in addition to MSE. If I get rid of them, do I need something in replace that would work with MSE without a conflict? My Internet should be back on shortly since a payment was made last week by mail. I could get tools once I'm online again, so I could get the names of some tools, and then download them when I'm online again.

I am on an iPhone 4, but it's not the 4S with Siri, so I can't ask her. I am using my phone for the Internet right now. Lol. Quote
I have AVG Tune UP, and I have CC Cleaner. Should I get rid one of them? Or both of them? Or keep them both?
You can keep AVG Tune Up but don't run the Registry Cleaner for the reasons listed below. Not a problem with CCleaner.

Registry cleaners are extremely powerful applications and their potential for harming your OS far outweighs any small potential for improving your computer's performance.

There are a number of them available and some are more safe than others. Keep in mind that no two registry cleaners work entirely the same way. Each vendor uses different criteria as to what constitutes a "bad" entry. One cleaner may find entries on your SYSTEM that will not cause a problem when removed, another may not find the same entries, and still another may want to remove entries required for a program to work. Without research into what the registry entry selected for deletion is, a registry cleaner can end up being an automated method to cause problems with the registry.

For routine use by those not familiar with the registry, the benefits to your computer are negligible while the potential risks are great.

Further reading: XP Fixes Myth #1: Registry Cleaners
Quote
do I need something in replace that would work with MSE without a conflict?
The only thing that will conflict with MSE is another AV program.
384.

Solve : what else do i need??

Answer»

i have ESET NOD 32 (subscription) and ccleaner (the free one).    i had xoft spy SE for a long time but i have let my subscription lapse.   is that something i need STILL, or do i have enough security coverage?    i RUN the ccleaner about twice a week and the ESET about every 2 weeks.  i use this machine as a toy....games mostly and e-mails occasionally.   what do you recommend for me?ccleaner has nothing to do with system security.

You need a good AV (NOD is FINE I guess) and either MalwaerBytes or SUPERANTISPYWARE (or both - the free versions). I also use SpywareBlaster. And of course the most important facet of security is smart computing (don't open links or attachments in emails unless you are certain you know what they are, don't download anything unless you are 100% certain it is safe, etc).

385.

Solve : Very basic question about securing my fresh old computer?

Answer»

This is probably a super basic question, but I hope that someone can answer for me.

I'm about to reformat my PC and reinstall Vista, which means reinstalling everything. One thing I'm never quite certain about is what order to do everything in. When I finish installing the OS, it prompts me to go online and validate it and update it and all that, but I need to have an antivirus up and running before I do that, don't I?
My assumption is that an unprotected PC shouldn't go online for even one MINUTE, so when do I install the antivirus and update it?

And one last thing: do the folks around here have recommendations for the best set-up of free security measures? We don't have a ton of money and stuff like AVG is what I rely on. What is the minimum stuff I should install on my machine in order to have some hope of surfing safely?

Thanks very much!When I reinstalled Vista I couldn't authenticate my verison of Windows right away.  I had trouble getting the network adaptor working.  But, you have the option to verify Windows later.  Just look at all the options the boxes give you.  And I think connnecting to Microsoft is probably safe.  Also, you will probably have to install updates before you can install your AV.  I use Trend Micro and I had to wait until service pack two was installed before I could install my AV.  But, like I said, I think doing this with microsoft is safe.  Now I wouldn't go looking for coupons online right away to use at L.L. Bean, that might get you into trouble.

Anyone please correct me or post that I'm wrong. Quote

I'm about to reformat my PC and reinstall Vista, which means reinstalling everything. One thing I'm never quite certain about is what order to do everything in. When I finish installing the OS, it prompts me to go online and validate it and update it and all that, but I need to have an antivirus up and running before I do that, don't I?
My assumption is that an unprotected PC shouldn't go online for even one minute, so when do I install the antivirus and update it?

And one last thing: do the folks around here have recommendations for the best set-up of free security measures? We don't have a ton of money and stuff like AVG is what I rely on. What is the minimum stuff I should install on my machine in order to have some hope of surfing safely?
You can download a free AV from the list below and save it on a memory stick or DVD using another computer then install it on your computer. Then get your updates. You should have a good, updated AV, turn on Windows Defender and Windows firewall. If your doing on-line banking you should install a third-party firewall.

Remember to only install one antivirus!
 
1) AVAST! Home Edition
2) AVG Free Edition
3) Avira AntiVir Personal
4) Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download
4-a) Microsoft Security Essentials for Windows XP
5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my DEFAULT search provider" and "Make Comodo Search my homepage" if you choose this one)
6) PC Tools AntiVirus Free Edition

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, SPAM, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.
Thanks again, SuperDave! Why doesn't every PC come with a set of instructions like this? I wish I knew this stuff years ago.
This site is the best! You're welcome.Just signed up a few minutes ago & came about this thread. I noticed that with anti virus, you only mention AVG though I've seen also others. Is this what you really recommend? Do you have any feedbacks or review on AVAST? By the way, I'm using Windows 7. thank you.
386.

Solve : Hackers steal Norton Source Code - What do we do??

Answer»

For those of us who have Norton Antivirus, what would be the best procedure  in view of the recent theft of their source code?  If we decide to download a different antivirus program, do we download it, GO off line, turn off Norton (or delete it), RUN the new program and then go back on line to get the updates for the new program?  Of the free antivirus programs, which one(s) are the most effective?  I am definitely paranoid when it COMES to security.  Thank youWow, paranoid is right .

Relax. I suggest you read the following and then find something ELSE to worry about
http://www.livehacking.com/2012/01/09/hackers-steal-source-code-to-norton-antivirus/Thank you, Allan.  I had read that one and wasn't too, too concerned, until I read this more recent article from Symantec:
http://www.computerworld.com/s/article/9223495/Symantec_backtracks_admits_own_network_hacked
.....and that is when the paranoia set in.   I'm confused. How does the theft of their source code POSE an ISSUE?

It's not the source code that does the detections. It's the various signatures.

387.

Solve : Malware issue (logs here)?

Answer»

I accidentally clicked on some stupid link and have had a fun few hours, I can only use my computer if I consistantly close iexplorer that is being run in the background every minute or so. In short the malware removed by desktop, blocked task manager and cleared all menus on my computer.  I could not update java, so if that matters I apologize.  This will be the second time you guys help me, thank you in advance I really appreciate your programs/knowledge!

here is what you want:

SAS log
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 10/28/2011 at 01:24 AM

Application Version : 5.0.1134

CORE Rules Database Version : 7863
Trace Rules Database Version: 5675

Scan type       : Complete Scan
Total Scan Time : 00:55:20

Operating System Information
Windows 7 Home Premium 64-bit (Build 6.01.7600)
UAC Off - Administrator

Memory items scanned      : 400
Memory threats detected   : 0
Registry items scanned    : 72073
Registry threats detected : 0
File items scanned        : 313939
File threats detected     : 1

Adware.Tracking Cookie
   C:\USERS\DAVID CRAWFORD\APPDATA\ROAMING\MICROSOFT\
WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /BURSTNET ]

Malwarebits
Database version: 8033

Windows 6.1.7600 (Safe Mode)
Internet Explorer 8.0.7600.16385

10/28/2011 1:26:26 AM
mbam-log-2011-10-28 (01-26-26).txt

Scan type: Quick scan
Objects scanned: 198917
Time elapsed: 1 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations\
bak_Application (Hijacker.Application) -> Value: bak_Application -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations\Application (Hijacker.Application) -> Bad: (http://www.helpmeopen.com/?n=app&ext=%s) Good: (http://shell.windows.com/fileassoc/%04x/xml/redir.asp?
Ext=%s) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

DDS1

DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385  BrowserJavaVersion: 1.6.0_27
Run by David Crawford at 1:33:29 on 2011-10-28
Microsoft Windows 7 Home Premium   6.1.7600.0.1252.2.1033.18.6135.4445 [GMT -4:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Program Files (x86)\Windows Live\Toolbar\wltuser.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\taskmgr.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wuauclt.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\SysWOW64\wscript.exe
C:\Windows\system32\REGSVR32.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.ask.com?o=15179&l=dis
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [dellsupportcenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRunOnce: [STToasterLauncher] C:\program files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: {6F6FDB9E-5072-498C-BCB0-2B7F00C49EE7} - hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{4920F6E6-8FA3-454D-B1E3-C581542EF00E} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{4920F6E6-8FA3-454D-B1E3-C581542EF00E}\4656661657C647 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{657A4658-9B4B-42D3-A345-13D5A0769465} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{657A4658-9B4B-42D3-A345-13D5A0769465}\D69777962756C6563737 : DhcpNameServer = 207.164.234.193 67.69.184.135
TCP: Interfaces\{83C22A46-0A97-41D9-A178-1900485BAD99} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{964FC7CA-B89A-4F97-AA74-20E774E1F858} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{BFF99BDE-572E-4784-AE37-2F49C0B3B569} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{C59FF3F6-F7F6-4FE6-9A95-B149BA3742EE} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{C59FF3F6-F7F6-4FE6-9A95-B149BA3742EE}\4656661657C647 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{C59FF3F6-F7F6-4FE6-9A95-B149BA3742EE}\D69777962756C6563737 : DhcpNameServer = 207.164.234.193 67.69.184.135
TCP: Interfaces\{C5CA6EF3-4BE2-4EF5-84A4-E8FD185F2152} : DhcpNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64:     AcroIEHelperStub - No File
BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO-X64:     Search Helper - No File
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: Windows Live Toolbar Helper: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
TB-X64: &Windows Live Toolbar: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
mRun-x64: [dellsupportcenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRunOnce-x64: [STToasterLauncher] C:\program files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe
IE-X64: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\David Crawford\AppData\Roaming\Mozilla\Firefox\Profiles\w41bhm11.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: C:\Users\David Crawford\AppData\Roaming\Mozilla\Firefox\Profiles\w41bhm11.default\extensions\{942cd1d4-9cc1-4d31-876a-ea8f489f7a59}\components\RadioWMPCoreGecko19.dll
FF - component: C:\Users\David Crawford\AppData\Roaming\Mozilla\Firefox\Profiles\w41bhm11.default\extensions\[email protected]\components\RadioWMPCoreGecko19.dll
FF - plugin: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: C:\Program Files (x86)\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\David Crawford\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Users\David Crawford\AppData\Roaming\Mozilla\Firefox\Profiles\w41bhm11.default\extensions\[email protected]\plugins\npLogitechDeviceDetection.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-20 92160]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-10-27 44768]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2009-11-20 656624]
R3 netr28ux;RT2870 USB Extensible Wireless LAN Card Driver;C:\Windows\system32\DRIVERS\netr28ux.sys --> C:\Windows\system32\DRIVERS\netr28ux.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys --> C:\Windows\system32\Drivers\RtsUStor.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SessionLauncher;SessionLauncher;c:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe --> c:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [?]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service --> C:\Windows\system32\GameMon.des -service [?]
S3 RoxMediaDB10;RoxMediaDB10;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCom\RoxMediaDB10.exe [2009-6-26 1124848]
S3 vcd10bus;Virtual CD v10 Bus Enumerator;C:\Windows\system32\DRIVERS\vcd10bus.sys --> C:\Windows\system32\DRIVERS\vcd10bus.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 Apache2.2;Apache2.2;C:\xampp\apache\bin\apache.exe [2008-1-17 24635]
S4 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2008-12-18 155648]
S4 pgsql-8.3;PostgreSQL Database Server 8.3;C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe [2008-2-1 65536]
S4 StarWindServiceAE;StarWind AE Service;C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
.
=============== Created Last 30 ================
.
2011-10-28 05:30:47   69000   ----a-w-   C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D21EDB31-CD3E-4158-B096-B0FC27C48E0F}\offreg.dll
2011-10-28 04:00:27   --------   d-----w-   C:\ProgramData\Malwarebytes
2011-10-28 04:00:24   --------   d-----w-   C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-10-28 03:58:37   --------   d-----w-   C:\Users\David Crawford\AppData\Roaming\SUPERAntiSpyware.com
2011-10-28 03:58:16   --------   d-----w-   C:\ProgramData\SUPERAntiSpyware.com
2011-10-28 03:58:16   --------   d-----w-   C:\Program Files\SUPERAntiSpyware
2011-10-28 03:55:16   65368   ----a-w-   C:\Windows\System32\drivers\aswMonFlt.sys
2011-10-28 03:55:16   601944   ----a-w-   C:\Windows\System32\drivers\aswSnx.sys
2011-10-28 03:55:11   41184   ----a-w-   C:\Windows\avastSS.scr
2011-10-28 03:55:06   --------   d-----w-   C:\ProgramData\AVAST Software
2011-10-28 03:55:06   --------   d-----w-   C:\Program Files\AVAST Software
2011-10-28 03:47:22   9049936   ----a-w-   C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D21EDB31-CD3E-4158-B096-B0FC27C48E0F}\mpengine.dll
2011-10-07 18:43:45   --------   d-----w-   C:\Users\David Crawford\AppData\Roaming\Research In Motion
2011-10-07 18:41:28   31744   ----a-w-   C:\Windows\System32\drivers\RimSerial_AMD64.sys
2011-10-07 18:41:14   --------   d-----w-   C:\ProgramData\Research In Motion
2011-10-07 18:41:06   --------   d-----w-   C:\Program Files (x86)\Research In Motion
2011-10-07 18:41:06   --------   d-----w-   C:\Program Files (x86)\Common Files\Research In Motion
.
==================== Find3M  ====================
.
2011-10-05 10:39:53   414368   ----a-w-   C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-01 03:21:20   1638912   ----a-w-   C:\Windows\System32\mshtml.tlb
2011-10-01 02:59:14   1638912   ----a-w-   C:\Windows\SysWow64\mshtml.tlb
2011-09-26 22:39:04   472808   ----a-w-   C:\Windows\SysWow64\deployJava1.dll
2011-09-17 17:42:53   627600   ----a-w-   C:\Windows\System32\deployJava1.dll
2011-09-06 03:07:02   3134976   ----a-w-   C:\Windows\System32\win32k.sys
2011-08-31 21:00:50   25416   ----a-w-   C:\Windows\System32\drivers\mbam.sys
2011-08-27 05:40:28   861184   ----a-w-   C:\Windows\System32\oleaut32.dll
2011-08-27 05:40:28   331776   ----a-w-   C:\Windows\System32\oleacc.dll
2011-08-27 04:43:07   571904   ----a-w-   C:\Windows\SysWow64\oleaut32.dll
2011-08-27 04:43:06   233472   ----a-w-   C:\Windows\SysWow64\oleacc.dll
2011-08-20 05:45:20   1197568   ----a-w-   C:\Windows\System32\wininet.dll
2011-08-20 05:41:16   57856   ----a-w-   C:\Windows\System32\licmgr10.dll
2011-08-20 04:38:10   981504   ----a-w-   C:\Windows\SysWow64\wininet.dll
2011-08-20 04:35:20   44544   ----a-w-   C:\Windows\SysWow64\licmgr10.dll
2011-08-20 04:20:23   482816   ----a-w-   C:\Windows\System32\html.iec
2011-08-20 03:26:38   386048   ----a-w-   C:\Windows\SysWow64\html.iec
2011-08-17 05:32:24   613888   ----a-w-   C:\Windows\System32\psisdecd.dll
2011-08-17 05:27:46   75776   ----a-w-   C:\Windows\System32\MSDvbNP.ax
2011-08-17 05:27:46   288256   ----a-w-   C:\Windows\System32\MSNP.ax
2011-08-17 05:27:46   108032   ----a-w-   C:\Windows\System32\psisrndr.ax
2011-08-17 05:27:46   104960   ----a-w-   C:\Windows\System32\Mpeg2Data.ax
2011-08-17 04:26:02   465408   ----a-w-   C:\Windows\SysWow64\psisdecd.dll
2011-08-17 04:22:23   75776   ----a-w-   C:\Windows\SysWow64\psisrndr.ax
2011-08-17 04:22:23   72704   ----a-w-   C:\Windows\SysWow64\Mpeg2Data.ax
2011-08-17 04:22:23   59904   ----a-w-   C:\Windows\SysWow64\MSDvbNP.ax
2011-08-17 04:22:23   204288   ----a-w-   C:\Windows\SysWow64\MSNP.ax
.
============= FINISH:  1:43:20.26 ===============

dds2
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 11/26/2009 1:21:38 AM
System Uptime: 10/28/2011 1:27:32 AM (0 hours ago)
.
Motherboard: DELL Inc. |  | 0X501H
Processor: Intel(R) Core(TM) i7 CPU         920  2.67GHz | CPU 1 | 2668/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 922 GiB total, 750.259 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is CDROM ()
G: is CDROM ()
X: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP367: 10/7/2011 5:37:22 PM - Windows Update
RP368: 10/11/2011 11:08:06 AM - Windows Update
RP369: 10/12/2011 10:27:27 AM - Windows Update
RP370: 10/13/2011 2:24:49 AM - Windows Update
RP371: 10/14/2011 10:42:02 AM - Windows Update
RP372: 10/18/2011 11:56:05 AM - Windows Update
RP373: 10/21/2011 11:37:33 AM - Windows Update
RP374: 10/25/2011 10:07:12 AM - Windows Update
RP375: 10/26/2011 4:16:27 PM - Windows Update
RP376: 10/27/2011 11:28:08 PM - Windows Update
RP377: 10/27/2011 11:29:16 PM - Windows Update
RP378: 10/28/2011 1:35:43 AM - Windows Update
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Flash Media Encoder 2.5
Adobe Flash Player 10 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader 9.1.2
Adobe Shockwave Player 11.5
ATMA V 5.05
µTorrent
avast! Free Antivirus
BlackBerry Desktop Software 6.1
CCleaner
Compatibility Pack for the 2007 Office system
Dell DataSafe Local Backup
Dell DataSafe Local Backup - Support Software
Dell Getting Started Guide
Dell Support Center (Support Software)
Diablo II
DirectXInstallService
EMC 10 Content
GoToAssist 8.0.0.514
Hero Editor V0.96
Hero Editor V0.96 (C:\Program Files (x86)\Hero Editor\diablo II\hero editor\)
Java Auto Updater
Java(TM) 6 Update 27
Junk Mail filter update
K-Lite Mega Codec Pack 5.4.4
KingAgnostic's Minecraft 1.1.2_01
League of Legends
Left 4 Dead 2
Livestream Procaster
Macromedia Extension Manager
Macromedia Flash 8
Macromedia Flash 8 Video Encoder
Malwarebytes' Anti-Malware version 1.51.2.1300
Media Player Classic - Home Cinema v. 1.3.1249.0
Microsoft .NET Framework 1.1
Microsoft .NET Framework SDK (English) 1.1
Microsoft Choice Guard
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319
Microsoft Works
Microsoft WSE 3.0 Runtime
Microsoft XML Parser
mIRC
Mozilla Firefox 7.0.1 (x86 en-US)
MS Access 97 SP2
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML4 Parser
NVIDIA PhysX
OpenOffice.org 3.1
PokerStars
PokerStrategy.com Elephant
Portforward Static IP Address 1.0.45
PostgreSQL 8.3
PowerDVD DX
PremiumSoft Navicat Premium 8.2
Realtek High Definition Audio Driver
Remere's Map Editor
Roxio Activation Module
Roxio BackOnTrack
Roxio CENTRAL Audio
Roxio Central Copy
Roxio Central Core
Roxio Central Data
Roxio Central Tools
Roxio Easy CD and DVD Burning
Roxio Express Labeler 3
Roxio Update Manager
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Skype™ 5.1
Sonic CinePlayer Decoder Pack
SplitMediaLabs VH Screen Capture Driver (x86)
StarCraft II
Steam
Team Fortress 2
TeamSpeak 3 Client
Tibia
Tibia MULTI-ip changer
Unity Web Player
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Vegas Pro 9.0
Ventrilo Client
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows Media Player Firefox Plugin
WinPcap 4.1.1
XAMPP 1.6.6a
XSplit
.
==== Event Viewer Messages From Past Week ========
.
10/28/2011 1:35:44 AM, Error: Ntfs [55]  - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume .
10/28/2011 1:28:54 AM, Error: VDS Basic Provider [1]  - Unexpected failure. Error code: [email protected]
10/28/2011 1:28:40 AM, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  RxFilter
10/28/2011 1:28:35 AM, Error: Service Control Manager [7000]  - The SessionLauncher service failed to start due to the following error:  The system cannot find the file specified.
10/27/2011 11:54:47 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
10/27/2011 11:45:38 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
10/27/2011 11:45:38 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
10/27/2011 11:45:35 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
10/27/2011 11:45:24 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
10/27/2011 11:45:21 PM, Error: Service Control Manager [7001]  - The Computer Browser service depends on the Server service which failed to start because of the following error:  The dependency service or group failed to start.
10/27/2011 11:45:16 PM, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  discache RxFilter spldr sptd Wanarpv6
10/27/2011 11:44:56 PM, Error: sptd [4]  - Driver detected an internal error in its data structures for .
10/27/2011 11:43:12 PM, Error: Service Control Manager [7034]  - The PostgreSQL Database Server 8.3 service terminated unexpectedly.  It has done this 1 time(s).
10/27/2011 11:32:27 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
10/27/2011 11:31:21 PM, Error: Service Control Manager [7001]  - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:  The dependency service or group failed to start.
10/27/2011 11:31:11 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
10/27/2011 11:31:11 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
10/27/2011 11:30:52 PM, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  AFD DfsC discache NETBIOS NetBT nsiproxy Psched rdbss RxFilter spldr sptd tdx vwififlt Wanarpv6 WfpLwf
10/27/2011 11:30:52 PM, Error: Service Control Manager [7001]  - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.
10/27/2011 11:30:52 PM, Error: Service Control Manager [7001]  - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error:  A device attached to the system is not functioning.
10/27/2011 11:30:52 PM, Error: Service Control Manager [7001]  - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error:  A device attached to the system is not functioning.
10/27/2011 11:30:52 PM, Error: Service Control Manager [7001]  - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error:  The dependency service or group failed to start.
10/27/2011 11:30:52 PM, Error: Service Control Manager [7001]  - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error:  The dependency service or group failed to start.
10/27/2011 11:30:52 PM, Error: Service Control Manager [7001]  - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error:  A device attached to the system is not functioning.
10/27/2011 11:30:52 PM, Error: Service Control Manager [7001]  - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.
10/27/2011 11:30:52 PM, Error: Service Control Manager [7001]  - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.
10/27/2011 11:30:52 PM, Error: Service Control Manager [7001]  - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error:  A device attached to the system is not functioning.
10/27/2011 11:30:52 PM, Error: Service Control Manager [7001]  - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error:  A device attached to the system is not functioning.
10/27/2011 11:30:52 PM, Error: Service Control Manager [7001]  - The Apache2.2 service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error:  A device attached to the system is not functioning.
10/27/2011 11:28:46 PM, Error: Service Control Manager [7031]  - The Windows Modules Installer service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 300000 milliseconds: Restart the service.
10/27/2011 11:28:42 PM, Error: Service Control Manager [7031]  - The Windows Modules Installer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
.
==== End Of File ===========================

I havent restored to my old settings yet, and when I search something on google, whatever link I pick gets hijacked still.

Please visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here.Combofix log:

I hope I didnt do anything bad, but iexplorer was at about 450 mbs while it wrote logs and I ended it under the assumption that combofix wasnt the one using it..  I have no problem re-running the program if that could have affected the results.

My searches are still hijacked.

ComboFix 11-10-28.04 - David Crawford 10/28/2011  11:40:59.1.8 - x64
Microsoft Windows 7 Home Premium   6.1.7600.0.1252.2.1033.18.6135.4377 [GMT -4:00]
Running from: c:\users\David Crawford\Downloads\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\users\David Crawford\AppData\Roaming\Minecraft.exe
c:\users\David Crawford\AppData\Roaming\Uninstal.exe
.
.
(((((((((((((((((((((((((   Files Created from 2011-09-28 to 2011-10-28  )))))))))))))))))))))))))))))))
.
.
2011-10-28 16:18 . 2011-10-28 16:18   69000   ----a-w-   c:\programdata\Microsoft\Windows Defender\Definition Updates\{FCBA32D9-AC22-4A4F-9AA3-EB763402364A}\offreg.dll
2011-10-28 16:13 . 2011-10-28 16:13   --------   d-----w-   c:\users\elephant\AppData\Local\temp
2011-10-28 16:13 . 2011-10-28 16:13   --------   d-----w-   c:\users\Default\AppData\Local\temp
2011-10-28 05:36 . 2011-10-18 06:27   8570192   ----a-w-   c:\programdata\Microsoft\Windows Defender\Definition Updates\{FCBA32D9-AC22-4A4F-9AA3-EB763402364A}\mpengine.dll
2011-10-28 05:35 . 2011-08-15 05:08   6144   ----a-w-   c:\program files\Internet Explorer\iecompat.dll
2011-10-28 05:35 . 2011-08-15 04:25   6144   ----a-w-   c:\program files (x86)\Internet Explorer\iecompat.dll
2011-10-28 04:00 . 2011-10-28 04:00   --------   d-----w-   c:\programdata\Malwarebytes
2011-10-28 04:00 . 2011-10-28 04:00   --------   d-----w-   c:\program files (x86)\Malwarebytes' Anti-Malware
2011-10-28 03:58 . 2011-10-28 03:58   --------   d-----w-   c:\users\David Crawford\AppData\Roaming\SUPERAntiSpyware.com
2011-10-28 03:58 . 2011-10-28 03:58   --------   d-----w-   c:\program files\SUPERAntiSpyware
2011-10-28 03:58 . 2011-10-28 03:58   --------   d-----w-   c:\programdata\SUPERAntiSpyware.com
2011-10-28 03:55 . 2011-09-06 20:45   254400   ----a-w-   c:\windows\system32\aswBoot.exe
2011-10-28 03:55 . 2011-10-28 15:30   --------   d-----w-   c:\programdata\AVAST Software
2011-10-28 03:55 . 2011-10-28 03:55   --------   d-----w-   c:\program files\AVAST Software
2011-10-07 18:43 . 2011-10-28 03:38   --------   d-----w-   c:\users\David Crawford\AppData\Roaming\Research In Motion
2011-10-07 18:41 . 2009-01-09 20:02   31744   ----a-w-   c:\windows\system32\drivers\RimSerial_AMD64.sys
2011-10-07 18:41 . 2011-10-07 18:41   --------   d-----w-   c:\programdata\Research In Motion
2011-10-07 18:41 . 2011-10-28 03:40   --------   d-----w-   c:\program files (x86)\Common Files\Research In Motion
2011-10-07 18:41 . 2011-10-07 18:41   --------   d-----w-   c:\program files (x86)\Research In Motion
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-05 10:39 . 2011-05-29 16:04   414368   ----a-w-   c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-26 22:39 . 2010-05-02 17:04   472808   ----a-w-   c:\windows\SysWow64\deployJava1.dll
2011-09-17 17:42 . 2011-09-17 17:43   627600   ----a-w-   c:\windows\system32\deployJava1.dll
2011-08-31 21:00 . 2009-12-18 19:18   25416   ----a-w-   c:\windows\system32\drivers\mbam.sys
2011-08-10 17:48 . 2011-08-10 17:48   375   ----a-w-   c:\users\David Crawford\AppData\Local\postgresinstall.bat
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-10-17 5500800]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"dellsupportcenter"="c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SessionLauncher;SessionLauncher;c:\users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe


R3 dump_wmimmc;dump_wmimmc;c:\program files (x86)\NCsoft\Lineage II\system\GameGuard\dump_wmimmc.sys

R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-26 1124848]
R3 vcd10bus;Virtual CD v10 Bus Enumerator;c:\windows\system32\DRIVERS\vcd10bus.sys

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe

R3 X6va001;X6va001;c:\users\DAVIDC~1\AppData\Local\Temp\0019F35.tmp

R4 Apache2.2;Apache2.2;c:\xampp\apache\bin\apache.exe [2008-01-17 24635]
R4 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-12-18 155648]
R4 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe [2008-02-01 65536]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys

S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys

S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys

S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-03-31 92160]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys

S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2009-08-17 656624]
S3 netr28ux;RT2870 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr28ux.sys

S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys

S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys

S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys

S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys

.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-05-23 7833120]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-26 16327712]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-04-13 2399632]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.ask.com?o=15179&l=dis
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\David Crawford\AppData\Roaming\Mozilla\Firefox\Profiles\w41bhm11.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-KingAgnostic's Minecraft 1.1.2_01 - c:\users\David Crawford\AppData\Roaming\Uninstal.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va001]
"ImagePath"="\??\c:\users\DAVIDC~1\AppData\Local\Temp\0019F35.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1420202529-2994384463-3620377272-1000\Software\SecuROM\License information*]
"datasecu"=hex:ab,c1,18,de,39,40,5d,ca,5c,da,52,8e,98,99,1a,67,5a,1b,66,15,97,
   13,8e,64,16,8a,5e,3f,e3,be,50,3f,cb,3d,6e,ae,6d,c5,65,75,b7,2b,0a,15,fd,a1,\
"rkeysecu"=hex:25,4f,b3,cc,e4,e2,cb,56,0d,50,05,5e,1b,f7,d9,c6
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
Denied: (A 2) (Everyone)
="FlashBroker"
"LocalizedString"="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10w_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10w_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
Denied: (A 2) (Everyone)
="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
Denied: (A 2) (Everyone)
="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
Denied: (A 2) (Everyone)
="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
Denied: (A) (Users)
Denied: (A) (Everyone)
Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files (x86)\Dell Support Center\bin\sprtsvc.exe
c:\program files (x86)\Internet Explorer\iexplore.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
c:\program files (x86)\Windows Live\Toolbar\wltuser.exe
.
**************************************************************************
.
Completion time: 2011-10-28  12:37:26 - machine was rebooted
ComboFix-quarantined-files.txt  2011-10-28 16:37
.
Pre-Run: 806,115,491,840 bytes free
Post-Run: 805,085,458,432 bytes free
.
- - End Of File - - AAE2156689C8FB6ED407442E9F018477Log should be fine.

ESET Online Scan

Please run a free online scan with the ESET Online Scanner
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
[email protected] as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=7434ac6c61704f42b7b1f9b2749fb2da
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-10-30 06:13:57
# local_time=2011-10-30 02:13:57 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=6.1.7600 NT
# compatibility_mode=768 16777215 100 0 0 0 0 0
# compatibility_mode=5893 16776573 100 94 0 71495178 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=268024
# found=4
# cleaned=4
# scan_time=3508
C:\Users\David Crawford\Desktop\Games\Cipsoft Project 0.3.5\Crying Damson.exe   a variant of Win32/GameServer.AA application (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
C:\Users\David Crawford\Desktop\Games\Cipsoft Project 0.3.5\OT\The Forgotten Server v0.2.7 MYSTIC Spirit console\The Forgotten Server.exe   a variant of Win32/GameServer.AA application (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
C:\Users\David Crawford\Desktop\Games\Cipsoft Project 0.3.5\OT\The Forgotten Server v0.2.7 Mystic Spirit GUI\The Forgotten Server.exe   a variant of Win32/GameServer.AA application (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
C:\Windows\InternetExplorer.exe   probably a variant of Win32/Autorun.KYOHRBW worm (cleaned by deleting - quarantined)   00000000000000000000000000000000   C


Havent checked to see if the problem is resolved, I will update tomorrow if necessary.  Thank you for all the help so far, especially considering it was over the weekend!Update me on how it is running...It seems there is still something on my computer.

I let iexplorer run itself to about 350 mb's and then it caused an error and a few popups came up.

One mentioned a file with what looked like a virus name, and another mentioned something about creating something and access denied.

The virus was in a "temp" folder, though I couldnt find it manually.Please download DrWeb-CureIt and save it to your Desktop. Do NOT perform a scan yet

  • Double-click on drweb-cureit.exe to start the program.
    An Express Scan of your PC notice will appear.
  • Under Start the Express Scan Now, Click OK to start the scan.
    This is a short scan that will scan the files currently running in memory.
    If something is found, click the Yes button when it asks you if you want to cure it.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the Scan tab and UNcheck Heuristic analysis
  • Back at the main window, click Custom Scan, then Select drives (a red dot will show which drives have been chosen).
  • Then click the Start/Stop Scanning button (green arrow on the right, and the scan will start.
  • When finished, a message will be displayed at the bottom advising if any viruses were found.
  • Click Yes to all if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can see the icon next to the files found.

If so, click it, then click the next icon right below and select Move incurable.
(This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
  • Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
  • Save the DrWeb.csv report to your Desktop.
  • Exit Dr.Web Cureit when you have finished.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)
I can not access your link directly, and the text was already purple before I clicked on it.

I googled the link location and accessed the ftp server or whatever that was and am downloading this:"http://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe" file at 30 kb/s.

If you know a better place to download this file from I would appreciate it.The report came up with nothing.

Quote
dds.scr;C:\Documents and Settings\David Crawford\Desktop;Trojan.MulDrop3.6866;;
dds.scr;C:\Documents and Settings\David Crawford\DoctorWeb\Quarantine;Trojan.MulDrop3.6866;Incurable.Moved.;
dds.scr;C:\Users\David Crawford\Desktop;Trojan.MulDrop3.6866;;
If this has any impact, the negative effects of it now are the constant running of IE in the background, searches being hijacked (and generally to blinkx.com), IE windows opening on my screen, and ads playing in the background.

Please download aswMBR from here

  • Save aswMBR.exe to your Desktop
  • Double click aswMBR.exe to run it
  • Click the Scan button to start the scan as illustrated below


Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives

  • Once the scan finishes click Save log to save the log to your Desktop


  • Copy and paste the contents of aswMBR.txt back here for review
Quote
aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
Run date: 2011-11-01 11:40:33
-----------------------------
11:40:33.032    OS Version: Windows x64 6.1.7600
11:40:33.032    Number of processors: 8 586 0x1A05
11:40:33.032    ComputerName: DAVE  UserName:
11:40:35.032    Initialize success
11:41:51.612    AVAST engine defs: 11110102
11:42:13.542    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
11:42:13.552    Disk 0 Vendor: SAMSUNG_ 1AA0 Size: 953869MB BusType: 3
11:42:13.552    Disk 0 MBR read error 0
11:42:13.552    Disk 0 MBR scan
11:42:13.562    Disk 0 unknown MBR code
11:42:13.562    MBR BIOS signature not found 0
11:42:13.562    Service scanning
11:42:13.982    Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32
11:42:14.522    Modules scanning
11:42:14.522    Disk 0 trace - called modules:
11:42:14.542    ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa8006649334]<<
11:42:14.542    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006636060]
11:42:14.552    3 CLASSPNP.SYS[fffff8800140143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8006351050]
11:42:14.552    \Driver\iaStor[0xfffffa80062c5af0] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0xfffffa8006649334
11:42:16.672    AVAST engine scan C:\Windows
11:42:52.622    AVAST engine scan C:\Windows\system32
11:43:02.622    AVAST engine scan C:\Windows\system32\drivers
11:43:12.622    AVAST engine scan C:\Users\David Crawford
11:43:22.622    AVAST engine scan C:\ProgramData
11:43:22.622    Scan finished successfully
11:47:21.476    Disk 0 MBR has been saved successfully to "C:\Users\David Crawford\Desktop\MBR.dat"
11:47:21.482    The log file has been saved successfully to "C:\Users\David Crawford\Desktop\aswMBR.txt"

I havent clicked fix yetWe need to fix the infection found with aswMBR now

  • Double click aswMBR.exe to run it like before
  • Once the scan finishes click Fix to remove the infection as illustrated below


  • Once the scan finishes click Save log to save the log to your Desktop



  • Copy and paste the contents of aswMBR.txt back here for review
Quote
aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
Run date: 2011-11-01 11:40:33
-----------------------------
11:40:33.032    OS Version: Windows x64 6.1.7600
11:40:33.032    Number of processors: 8 586 0x1A05
11:40:33.032    ComputerName: DAVE  UserName:
11:40:35.032    Initialize success
11:41:51.612    AVAST engine defs: 11110102
11:42:13.542    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
11:42:13.552    Disk 0 Vendor: SAMSUNG_ 1AA0 Size: 953869MB BusType: 3
11:42:13.552    Disk 0 MBR read error 0
11:42:13.552    Disk 0 MBR scan
11:42:13.562    Disk 0 unknown MBR code
11:42:13.562    MBR BIOS signature not found 0
11:42:13.562    Service scanning
11:42:13.982    Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32
11:42:14.522    Modules scanning
11:42:14.522    Disk 0 trace - called modules:
11:42:14.542    ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa8006649334]<<
11:42:14.542    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006636060]
11:42:14.552    3 CLASSPNP.SYS[fffff8800140143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8006351050]
11:42:14.552    \Driver\iaStor[0xfffffa80062c5af0] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0xfffffa8006649334
11:42:16.672    AVAST engine scan C:\Windows
11:42:52.622    AVAST engine scan C:\Windows\system32
11:43:02.622    AVAST engine scan C:\Windows\system32\drivers
11:43:12.622    AVAST engine scan C:\Users\David Crawford
11:43:22.622    AVAST engine scan C:\ProgramData
11:43:22.622    Scan finished successfully
11:47:21.476    Disk 0 MBR has been saved successfully to "C:\Users\David Crawford\Desktop\MBR.dat"
11:47:21.482    The log file has been saved successfully to "C:\Users\David Crawford\Desktop\aswMBR.txt"
14:09:23.186    Disk 0 MBR fix error
14:10:04.942    Disk 0 MBR has been saved successfully to "C:\Users\David Crawford\Desktop\MBR.dat"
14:10:04.947    The log file has been saved successfully to "C:\Users\David Crawford\Desktop\aswMBR.txt"

I assume that isnt supposed to happen.
388.

Solve : exe.exe?

Answer»

I have downloaded 7 zip which is a "exe.exe" file. I have HEARD that  files or softwares with "exe.exe" extensions are harmful. Is it true? If it so please let me KNOW any free SOFTWARE that unzip files and is without "exe.exe" extension.All Windows Applications are EXE files. Yes, but he WONDERS about it's filename which is also named "exe" (the same as the extension)begginer, why are you calling it a "7 zip" if it has the extension exe.exe?

What is it and where did you get it from?

(by the way "beginner" has ONE 'g' and two 'n's)

389.

Solve : Errors running merged-mine-proxy?

Answer»

So I have added the wxWidgets patch and COMPILED bitcoind I also applied the bitcoin-4diff.txt patch. Downloaded 3.24.60 of namecoind and configured my bitcoin.conf file.

I ran bitcoind in testnet and namcoind in production mode.

Then called ran merged-mine-proxy and got...



      
   
Code:
./merged-mine-proxy -w 8330 -p http://pass:[email protected]:8337/ -x http://pass:[email protected]:9098



merkle size = 1
Unhandled error in Deferred:
Traceback (most recent call last):
  File "/usr/lib/python2.7/dist-packages/twisted/internet/defer.py", line 388, in errback
    self._startRunCallbacks(fail)
  File "/usr/lib/python2.7/dist-packages/twisted/internet/defer.py", line 455, in _startRunCallbacks
    self._runCallbacks()
  File "/usr/lib/python2.7/dist-packages/twisted/internet/defer.py", line 542, in _runCallbacks
    current.result = callback(current.result, *ARGS, **kw)
  File "/usr/lib/python2.7/dist-packages/twisted/internet/defer.py", line 1076, in gotResult
    _inlineCallbacks(r, g, deferred)
--- ---
  File "/usr/lib/python2.7/dist-packages/twisted/internet/defer.py", line 1018, in _inlineCallbacks
    result = result.throwExceptionIntoGenerator(g)
  File "/usr/lib/python2.7/dist-packages/twisted/python/failure.py", line 349, in throwExceptionIntoGenerator
    return g.throw(self.type, self.value, self.tb)
  File "./merged-mine-proxy", line 249, in update_auxs
    aux_block = (yield self.auxs[chain].rpc_getauxblock())
  File "/usr/lib/python2.7/dist-packages/twisted/internet/defer.py", line 1018, in _inlineCallbacks
    result = result.throwExceptionIntoGenerator(g)
  File "/usr/lib/python2.7/dist-packages/twisted/python/failure.py", line 349, in throwExceptionIntoGenerator
    return g.throw(self.type, self.value, self.tb)
  File "./merged-mine-proxy", line 97, in callRemote
    resp = json.loads(resp)
  File "/usr/lib/python2.7/json/__init__.py", line 326, in loads
    return _default_decoder.decode(s)
  File "/usr/lib/python2.7/json/decoder.py", line 360, in decode
    OBJ, end = self.raw_decode(s, idx=_w(s, 0).end())
  File "/usr/lib/python2.7/json/decoder.py", line 378, in raw_decode
    raise ValueError("No JSON object could be decoded")
exceptions.ValueError: No JSON object could be decoded
   
      



Here is a copy of my bitcoin.conf for the bitcoind...

      
   
Code:
# Run on the test network instead of the real bitcoin network.
testnet=1
# server=1 tells Bitcoin to accept JSON-RPC commands.
server=1

# You must set rpcuser and rpcpassword to secure the JSON-RPC api
rpcuser=bit
rpcpassword=pass

# How many seconds bitcoin will wait for a COMPLETE RPC HTTP request.
# after the HTTP connection is established.
rpctimeout=30

# Listen for RPC connections on this TCP port:
rpcport=8337

# You can use Bitcoin or bitcoind to send commands to Bitcoin/bitcoind
# running on another HOST using this option:
rpcconnect=127.0.0.1

# Set gen=1 to attempt to generate bitcoins
gen=0
   
      


Here is a copy of my settings for namecoind's bitcoin.conf

      
   
Code:
server=1
addnode=78.47.40.55:18334
rpcuser=bit
rpcpassword=pass
rpctimeout=30
rpcport=9098
rpcconnect=127.0.0.1
gen=0
paytxfee=0.00

390.

Solve : Virus disabling all security, scans, please help!!?

Answer»

Hi there. My Avira auto guard has switched itself off and is unable to get back on. I try to scan with it but I receive multiple error messages.

I thought MAYBE uninstall-reinstall but then it turns out the latest version isn't compatible with my system so I downloaded Avast instead. The same thing has happened with it, it's auto guard has shut and won't open and it won't scan properly.

TrendMicro house doctor won't open. The only thing that works is SpyBot which got rid of a trojan but it hasn't really improved my situation.

Even HijackThis won't work so I can't even post one of them. And to make matters harder I have a search engine redirect virus, too.

I'm utterly clueless. Please can someone help me! 

Edit - also in task manager 'svchost.exe' has ridiculously high mem usage (over 300k)Please visit this WEBPAGE for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here.Thanks a LOT for the reply, DragonMaster Jay.

Here's the log:




ComboFix 11-11-03.01 - UserXP 11/03/2011  13:36:36.1.2 - x86
Microsoft Windows XP Professional  5.1.2600.2.1252.44.1033.18.1012.756 [GMT 0:00]
Running from: c:\documents and settings\UserXP\Desktop\ComboFix.exe
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\92764206.ini
c:\documents and settings\UserXP\Application Data\PriceGong
c:\documents and settings\UserXP\Application Data\PriceGong\Data\1.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\a.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\b.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\c.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\d.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\e.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\f.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\g.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\h.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\i.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\J.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\k.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\l.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\m.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\n.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\o.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\p.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\q.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\r.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\s.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\t.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\u.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\v.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\w.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\x.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\y.xml
c:\documents and settings\UserXP\Application Data\PriceGong\Data\z.xml
c:\documents and settings\UserXP\Start Menu\Programs\1964.lnk
c:\windows\$NtUninstallKB6897$\1168079883
c:\windows\$NtUninstallKB6897$\257550935\
c:\windows\$NtUninstallKB6897$\257550935\L\loipyrpm
c:\windows\$NtUninstallKB6897$\257550935\loader.tlb
c:\windows\$NtUninstallKB6897$\257550935\U\00000001
c:\windows\$NtUninstallKB6897$\257550935\U\000000c0
c:\windows\$NtUninstallKB6897$\257550935\U\000000cb
c:\windows\$NtUninstallKB6897$\257550935\U\000000cf
c:\windows\$NtUninstallKB6897$\257550935\U\80000000
c:\windows\$NtUninstallKB6897$\257550935\U\800000c0
c:\windows\$NtUninstallKB6897$\257550935\U\800000cb
c:\windows\$NtUninstallKB6897$\257550935\U\800000cf
c:\windows\1474976015
c:\windows\system32\
c:\windows\system32\_000110_.tmp.dll
c:\windows\system32\AF15BDAEX.dll
c:\windows\system32\lowsec
c:\windows\system32\UACkylvjkibeftbmppqb.db
c:\windows\$NtUninstallKB6897$ . . . . Failed to delete
.
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_PCMSTUB
-------\Legacy_UACd.sys
-------\Service_f59ea57
-------\Service_UACd.sys
.
.
(((((((((((((((((((((((((   Files Created from 2011-10-03 to 2011-11-03  )))))))))))))))))))))))))))))))
.
.
2011-11-03 11:18 . 2011-11-03 11:18   102400   ----a-w-   c:\windows\RegBootClean.exe
2011-11-03 11:18 . 2011-11-03 11:18   22032   ----a-w-   c:\windows\DCEBoot.exe
2011-11-03 11:07 . 2011-06-21 04:09   200976   ----a-w-   c:\windows\system32\drivers\tmcomm.sys
2011-11-02 23:31 . 2011-11-02 23:37   --------   d-----w-   C:\ea3a44c8c715befe6d44a5
2011-11-02 23:29 . 2011-11-02 23:29   --------   d-sh--w-   c:\documents and settings\Default User\IETldCache
2011-11-02 23:28 . 2011-11-02 23:28   --------   d-----w-   c:\windows\system32\XPSViewer
2011-11-02 23:28 . 2011-11-02 23:28   --------   d-----w-   c:\program files\MSBuild
2011-11-02 23:28 . 2011-11-02 23:28   --------   d-----w-   c:\program files\Reference Assemblies
2011-11-02 23:27 . 2008-07-06 12:06   89088   ----a-w-   c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-11-02 23:27 . 2008-07-06 12:06   89088   -c----w-   c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-11-02 23:27 . 2008-07-06 12:06   575488   -c----w-   c:\windows\system32\dllcache\xpsshhdr.dll
2011-11-02 23:27 . 2008-07-06 12:06   575488   ------w-   c:\windows\system32\xpsshhdr.dll
2011-11-02 23:27 . 2008-07-06 12:06   117760   ------w-   c:\windows\system32\prntvpt.dll
2011-11-02 23:27 . 2008-07-06 10:50   597504   -c----w-   c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-11-02 23:27 . 2008-07-06 10:50   597504   ------w-   c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-11-02 23:27 . 2011-11-02 23:28   --------   d-----w-   C:\e0e0ec9797bb6e1d6c
2011-11-02 23:27 . 2008-07-06 12:06   1676288   -c----w-   c:\windows\system32\dllcache\xpssvcs.dll
2011-11-02 23:27 . 2008-07-06 12:06   1676288   ------w-   c:\windows\system32\xpssvcs.dll
2011-11-02 23:18 . 2011-11-03 10:46   --------   d-----w-   C:\dd6e76892436c82b6336baa1b437
2011-11-02 22:49 . 2011-11-03 13:21   --------   d-----w-   c:\documents and settings\All Users\Application Data\AVAST Software
2011-11-02 22:49 . 2011-11-02 22:49   --------   d-----w-   c:\program files\AVAST Software
2011-11-02 22:26 . 2011-11-02 22:26   --------   d-----w-   c:\windows\system32\KB905474
2011-11-02 22:24 . 2011-11-02 22:24   --------   d-----w-   c:\program files\MSXML 6.0
2011-11-02 22:14 . 2011-11-02 22:14   --------   d-----w-   c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2011-11-02 22:11 . 2011-11-02 22:11   --------   d-----w-   c:\program files\MSXML 4.0
2011-11-02 22:09 . 2011-11-02 22:24   --------   d-----w-   c:\windows\system32\CatRoot_bak
2011-11-02 21:59 . 2008-06-13 13:10   272128   -c----w-   c:\windows\system32\dllcache\bthport.sys
2011-11-02 21:59 . 2010-05-06 10:41   599040   -c----w-   c:\windows\system32\dllcache\msfeeds.dll
2011-11-02 21:59 . 2010-05-06 10:41   55296   -c----w-   c:\windows\system32\dllcache\msfeedsbs.dll
2011-11-02 21:59 . 2010-05-06 10:41   743424   -c----w-   c:\windows\system32\dllcache\iedvtool.dll
2011-11-02 21:58 . 2010-02-12 10:03   293376   ------w-   c:\windows\system32\browserchoice.exe
2011-11-02 21:58 . 2009-10-23 14:27   3555328   -c----w-   c:\windows\system32\dllcache\moviemk.exe
2011-11-02 21:58 . 2008-08-14 09:51   138368   -c----w-   c:\windows\system32\dllcache\afd.sys
2011-11-02 21:58 . 2009-12-31 16:14   352640   -c----w-   c:\windows\system32\dllcache\srv.sys
2011-11-02 21:58 . 2008-05-01 14:30   331776   -c----w-   c:\windows\system32\dllcache\msadce.dll
2011-11-02 21:57 . 2009-06-21 22:04   153088   -c----w-   c:\windows\system32\dllcache\triedit.dll
2011-11-02 21:56 . 2010-02-24 12:31   454016   -c----w-   c:\windows\system32\dllcache\mrxsmb.sys
2011-11-02 21:56 . 2010-06-14 14:30   743936   -c----w-   c:\windows\system32\dllcache\helpsvc.exe
2011-11-02 21:53 . 2009-06-05 07:42   655872   -c----w-   c:\windows\system32\dllcache\mstscax.dll
2011-11-02 21:53 . 2009-11-21 16:36   470528   -c----w-   c:\windows\system32\dllcache\aclayers.dll
2011-11-02 21:50 . 2008-10-15 16:57   332800   -c----w-   c:\windows\system32\dllcache\netapi32.dll
2011-11-02 21:49 . 2009-07-31 04:57   1172480   -c----w-   c:\windows\system32\dllcache\msxml3.dll
2011-11-02 21:49 . 2008-04-21 10:02   215552   -c----w-   c:\windows\system32\dllcache\wordpad.exe
2011-10-30 12:11 . 2011-11-03 10:05   --------   d-sh--w-   c:\documents and settings\UserXP\Local Settings\Application Data\0f59ea57
2011-10-30 10:01 . 2011-11-02 07:54   --------   d-----w-   c:\documents and settings\UserXP\Application Data\MediaWmplay
2011-10-09 16:01 . 2011-11-02 20:44   --------   d-----w-   c:\documents and settings\UserXP\Application Data\Umovu
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-03 13:54 . 2011-04-10 17:00   218688   ----a-w-   c:\windows\system32\drivers\dtsoftbus01.sys
2011-11-03 11:18 . 2011-04-05 19:21   20992   ----a-w-   c:\windows\system32\libusbd-nt.exe
2011-10-16 09:31 . 2011-05-26 10:07   414368   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-30 21:44 . 2011-04-05 17:43   134104   ----a-w-   c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-12-09 12:51   3911776   ----a-w-   c:\program files\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-12-09 12:51   3911776   ----a-w-   c:\program files\uTorrentBar\tbuTor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "c:\program files\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-27 421160]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
.
[HKLM\~\startupfolder\C:^Documents and Settings^UserXP^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snp2uvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 03:08   35696   ----a-w-   c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43   69632   ----a-w-   c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
2006-07-17 14:40   53248   ------w-   c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-05-12 20:27   133104   ----atw-   c:\documents and settings\UserXP\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-02-28 07:00   166424   ----a-w-   c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2008-02-28 07:00   141848   ----a-w-   c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2008-02-28 07:00   137752   ----a-w-   c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PLFSetL]
2007-07-05 10:35   94208   ----a-w-   c:\windows\PLFSetL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-05-16 06:39   16862720   ----a-w-   c:\windows\RTHDCPL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 14:07   2260480   ------w-   c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-05-12 21:49   148888   ----a-w-   c:\program files\Java\jre6\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2008-04-25 01:32   1044480   ----a-w-   c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"vsmon"=2 (0x2)
"iPod Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe --> system32\libusbd-nt.exe [?]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [4/10/2011 5:00 PM 218688]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [4/5/2011 7:02 PM 33792]
S3 AF9035BDA;AF9035 BDA Devices;c:\windows\system32\drivers\AF9035BDA.sys [8/29/2009 8:49 AM 241792]
S3 CAM1690;USB 2.0 Compliance JPEG Video Camera;c:\windows\system32\Drivers\cam1690.sys --> c:\windows\system32\Drivers\cam1690.sys [?]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [6/14/2010 12:59 PM 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [6/14/2010 12:59 PM 8456]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [5/12/2009 10:06 PM 96856]
S3 MagixASIODrv;MAGIX_ASIO_BoostDriver;\??\c:\program files\MAGIX\Samplitude_10_SE\mxasio.sys --> c:\program files\MAGIX\Samplitude_10_SE\mxasio.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper   REG_MULTI_SZ      getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-02 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2011-11-02 22:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.254
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
FF - ProfilePath - c:\documents and settings\UserXP\Application Data\Mozilla\Firefox\Profiles\kklodkg8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Toolbar-Locked - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKCU-Run-{A78E3A29-141E-D17E-F14A-470BBB3C36AD} - c:\documents and settings\UserXP\Application Data\Nymekos\atrycoe.exe
AddRemove-LibUSB-Win32_is1 - c:\documents and settings\UserXP\Desktop\LibUSB-Win32-0.1.10.1\unins000.exe
AddRemove-My ScreenCam - c:\progra~1\MYSCRE~1\UNWISE.EXE
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-03 13:52
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ... 
.
scanning hidden autostart entries ...
.
scanning hidden files ... 
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(1792)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\libusbd-nt.exe
.
**************************************************************************
.
Completion time: 2011-11-03  13:59:35 - machine was rebooted
ComboFix-quarantined-files.txt  2011-11-03 13:59
.
Pre-Run: 80,291,270,656 bytes free
Post-Run: 83,088,691,200 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[Boot Loader]
timeout=2
Default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[Operating Systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 89C837FA33A397959261353CF4BB002D
Please DOWNLOAD aswMBR from here

  • Save aswMBR.exe to your Desktop
  • Double click aswMBR.exe to run it
  • Click the Scan button to start the scan as illustrated below


Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives

  • Once the scan finishes click Save log to save the log to your Desktop


  • Copy and paste the contents of aswMBR.txt back here for review
391.

Solve : Anti Virus program useable with Windows ME?

Answer»

My wife continues to use a computer with win ME. Up until very recently she has been using Avast. However they have just advised that Avast no longer supports ME. I have done extensive searching for an alternative. So far the only one i was able to find is "ClamWin". However it has a very major drawback--it will only scan folders manually selected. There is no real time scan option with it. Does anyone know of any usable real time anti virus SCANNER than will STILL work with Win ME? Thank you,truenorth
Please do NOT respond with she NEEDS to upgrade to a more recent O/S. She has other computers with XP and Win 7 on them but she still likes/wants to use the ME one as well.This might seem a bit reckless, but as long as all the important data is backed up, you could try and see what happens without an AV at all.

Windows 9x doesn't really show up as a prime target anymore, for new malware; (actually, in that sense, you would probably be able to live with just the unsupported AV product).

updates to an AV add new definitions so the product can find more viruses; while I have nothing to support this, I don't see windows 9x being a big target these days; Windows Vista and 7 are the new targets that malware authors would go after, and things written for NT aren't typically something that works the same on windows 9x, especially low level things like what a virus would typically do. The operating environments are similar but are full of gotchas (to that, I can definitely attest first-hand) that require due care and attention, neither of which are usually paid with your average malware program.

Another suggestion might be to go with clamwin and use task scheduler to schedule a full scan at some time where the machine won't be in use but might be on.
BC, Again i am indebted for your help. Your conclusion re the vulnerability (lack of) of her O/S was frequently put forth during my search on the internet for a usable alternative. I certainly concur with your logic. I cannot see any mileage for malicious virus creators to place any effort into an old O/S like ME. Her habit of use is to only use the wireless adapter when she needs to go on-line otherwise she removes it. Also that particular computer is very seldom used and when it is not it is turned off. I have read your reply to her and she also sees the wisdom of it and her fear level has diminished considerably. 
 On your suggestion re ClamWin. We of course are not familiar with it other than what i have read. However re the suggestion you made re the virus scans. I may have not understood what it does and doesn't do entirely. But i gathered the impression that the only thing that could be scheduled was the update function and scanning--but only insofar as a time. It seemed that the USER still had to manually select what was to be scanned at the time chosen at the actual moment of the scan. I could be mistaken about that. Thanks again,truenorth Quote from: truenorth on October 29, 2011, 02:53:16 PM

But i gathered the impression that the only thing that could be scheduled was the update function and scanning--but only insofar as a time. It seemed that the user still had to manually select what was to be scanned at the time chosen at the actual moment of the scan. I could be mistaken about that. Thanks again
For task scheduler, clamwin can be made to scan using it's command line program, "clamscan.exe" via a batch file. I'm sure if you choose to take this route I or another member could help you with such a configuration.BC, Yes because it is an open source program i would imagine that competent people could have it do various things. However i read your gracious offer to "she who must be obeyed" and  the immediate response was "FORGET it". I have only very recently  been allowed to put my hands on it (but with a very short leash). Were it mine i would certainly accept your offer so as to advance my very limited knowledge in the programming arena. Thanks again,truenorth
392.

Solve : get answers fast!!!?

Answer»

hi guys,
i'm sure you guys know about this get-answers-fast.com thing, where after a few google searches it jumps to that horrible website.

in my feeble attempt to defend myself, i ran f-secure... (which i'm never really sure if it does anything). nothing was detected.
then i downloaded microsoft security essentials.  when i ran a quick scan nothing was detected. when i ran a full scan, it got stuck, and now i can't even cancel it. (i don't know if that is relevant at all)

i know you guys are geniuses... so please tell me what to do.

thank you so much for your time... and your good electronic will.

yinPlease visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here.log is as follows... thanks! and i want to share with you a screen shot of some error messages which came up after combofix rebooted (3 errors: 1- there is a problem starting C:\ProgramData\MousePolicyPolicy.dll  2- RECYCLE Bin on C:\ is corrupted Do you wan to empty the Recycle Bin for this drive?  3- There was a problem starting C:\UserszyinzAppData\Local\Installer4632\Installer4632Update\Installer4632updt32.DLL The specified module could not be found

thanksthanksthanks!

ComboFix 11-10-27.05 - yin 10/27/2011  11:08:23.1.4 - x64
Microsoft Windows 7 Home Premium   6.1.7600.0.1252.1.1033.18.3894.2171 [GMT -4:00]
Running from: c:\users\yin\Desktop\ComboFix.exe
AV: F-Secure Client Security 9.11 *Disabled/Updated* {15414183-282E-D62C-CA37-EF24860A2F17}
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
FW: F-Secure Client Security 9.11 *Disabled* {2D7AC0A6-6241-D774-E168-461178D9686C}
SP: F-Secure Client Security 9.11 *Disabled/Updated* {AE20A067-0E14-D9A2-F087-D456FD8D65AA}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\autorun.inf
c:\program files\Setup.exe
c:\programdata\MousePolicyPolicy.dll
c:\users\yin\AppData\Local\Installer4632\Installer4632Update\Installer4632updt32.dll
c:\windows\IsUn0804.exe
.
.
(((((((((((((((((((((((((   Files Created from 2011-09-27 to 2011-10-27  )))))))))))))))))))))))))))))))
.
.
2011-10-27 15:16 . 2011-10-27 15:16   --------   d-----w-   c:\users\Default\AppData\Local\temp
2011-10-27 14:07 . 2011-10-27 14:07   --------   d-----w-   c:\users\Default\AppData\Local\Microsoft Help
2011-10-27 00:10 . 2011-09-12 21:26   9049936   ----a-w-   c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-27 00:09 . 2011-10-27 15:17   69000   ----a-w-   c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F8A45CB0-27D8-4226-9B5A-36007A5A3634}\offreg.dll
2011-10-27 00:09 . 2011-10-07 01:16   8570192   ----a-w-   c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F8A45CB0-27D8-4226-9B5A-36007A5A3634}\mpengine.dll
2011-10-27 00:06 . 2011-10-27 00:05   917840   ------w-   c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{15389EEF-C043-40D1-A8A2-12443A420514}\gapaengine.dll
2011-10-26 23:44 . 2011-10-26 23:44   --------   d-----w-   c:\program files (x86)\Microsoft Security Client
2011-10-26 23:43 . 2011-10-26 23:45   --------   d-----w-   c:\program files\Microsoft Security Client
2011-10-26 23:43 . 2010-04-09 11:06   374664   ----a-w-   c:\windows\system32\drivers\netio.sys
2011-10-26 23:04 . 2011-10-26 23:43   --------   d-----w-   c:\users\yin\AppData\Roaming\GetRightToGo
2011-10-25 21:12 . 2011-10-26 13:03   69000   ----a-w-   c:\programdata\Microsoft\Windows Defender\Definition Updates\{BBBDCD4C-2B17-440D-B994-940C02ED2A8A}\offreg.dll
2011-10-25 21:12 . 2011-10-07 04:16   8570192   ----a-w-   c:\programdata\Microsoft\Windows Defender\Definition Updates\{BBBDCD4C-2B17-440D-B994-940C02ED2A8A}\mpengine.dll
2011-10-24 01:28 . 2011-10-26 04:00   --------   d-----w-   c:\users\yin\AppData\Roaming\FileZilla
2011-10-24 01:28 . 2011-10-24 01:28   --------   d-----w-   c:\program files (x86)\FileZilla FTP Client
2011-10-14 18:11 . 2011-10-14 18:11   --------   d--h--w-   c:\programdata\CanonIJEPPEX2
2011-10-14 18:11 . 2011-10-14 18:11   --------   d--h--w-   c:\programdata\CanonEPP
2011-10-14 18:09 . 2011-10-14 18:09   --------   d-----w-   c:\programdata\Canon IJ Network Tool
2011-10-14 18:09 . 2010-03-18 18:25   307200   ----a-w-   c:\windows\SysWow64\CNC5200L.dll
2011-10-14 18:09 . 2010-03-18 16:11   106496   ----a-w-   c:\windows\SysWow64\CNC5200U.dll
2011-10-14 18:09 . 2008-08-25 17:02   15872   ----a-w-   c:\windows\SysWow64\CNHMCA.dll
2011-10-14 18:07 . 2011-10-14 18:07   --------   d-----w-   c:\programdata\CanonIJMSetup
2011-10-14 18:01 . 2011-10-14 18:01   --------   d-----w-   c:\program files\Common Files\CANON
2011-10-14 18:01 . 2011-10-14 18:01   --------   d-----w-   c:\programdata\CanonIJWSpt
2011-10-14 17:59 . 2011-10-14 17:59   --------   d-----w-   c:\program files\Canon
2011-10-14 17:58 . 2011-10-14 17:58   --------   d--h--w-   c:\programdata\CanonBJ
2011-10-14 17:58 . 2010-04-07 04:00   87040   ----a-w-   c:\windows\system32\Spool\prtprocs\x64\CNMPPAE.DLL
2011-10-14 17:58 . 2010-04-07 04:00   28672   ----a-w-   c:\windows\system32\Spool\prtprocs\x64\CNMPDAE.DLL
2011-10-14 17:58 . 2011-10-14 17:58   --------   d--h--w-   c:\windows\system32\CanonIJ Uninstaller Information
2011-10-14 17:57 . 2010-04-07 04:00   361472   ----a-w-   c:\windows\system32\CNMLMAE.DLL
2011-10-14 17:57 . 2010-03-11 07:57   248320   ----a-w-   c:\windows\system32\CNMIUAE.DLL
2011-10-14 17:57 . 2011-10-14 17:57   --------   d-----w-   c:\windows\system32\STRING
2011-10-14 17:57 . 2010-02-05 09:37   37376   ----a-w-   c:\windows\system32\CNMN6UI.DLL
2011-10-14 17:57 . 2010-02-05 09:37   327680   ----a-w-   c:\windows\system32\CNMN6PPM.DLL
2011-10-14 17:55 . 2011-10-14 18:11   --------   d-----w-   c:\program files (x86)\Canon
2011-10-14 00:53 . 2011-08-20 05:40   1013248   ----a-w-   c:\program files\Internet Explorer\iedvtool.dll
2011-10-14 00:53 . 2011-08-20 04:34   860672   ----a-w-   c:\program files (x86)\Internet Explorer\iedvtool.dll
2011-10-14 00:53 . 2011-08-20 05:45   1197568   ----a-w-   c:\windows\system32\wininet.dll
2011-10-14 00:51 . 2011-08-17 05:32   613888   ----a-w-   c:\windows\system32\psisdecd.dll
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-17 10:22 . 2011-07-04 12:37   42672   ----a-w-   c:\windows\SysWow64\drivers\fsbts.sys
2011-02-23 01:55 . 2011-02-23 01:54   4772720   ----a-w-   c:\program files\BitTorrent-7.2.exe
2010-02-23 09:49 . 2011-06-26 23:03   549216   ----a-w-   c:\program files\AecSetup.dll
2010-02-10 00:16 . 2011-06-26 23:03   1049312   ----a-w-   c:\program files\PatchMgr.dll
2010-02-10 00:16 . 2011-06-26 23:03   47328   ----a-w-   c:\program files\AcSetup.dll
2010-01-14 14:40 . 2011-06-26 23:03   704360   ----a-w-   c:\program files\SetupAcadUi.dll
2010-01-14 14:40 . 2011-06-26 23:03   693096   ----a-w-   c:\program files\SetupUi.dll
2010-01-14 14:40 . 2011-06-26 23:03   108392   ----a-w-   c:\program files\LiteHtml.dll
2010-01-14 14:40 . 2011-06-26 23:03   544616   ----a-w-   c:\program files\DeployUi.dll
2010-01-14 14:40 . 2011-06-26 23:03   85352   ----a-w-   c:\program files\CIPUtil.dll
2010-01-14 14:40 . 2011-06-26 23:02   161640   ----a-w-   c:\program files\AcDelTree.exe
2010-01-14 14:37 . 2011-06-26 23:03   319248   ----a-w-   c:\program files\UPI.dll
2010-01-14 14:36 . 2011-06-26 23:03   375128   ----a-w-   c:\program files\MC3Res.dll
2010-01-14 14:36 . 2011-06-26 23:03   1764696   ----a-w-   c:\program files\MC3.dll
2010-01-14 14:36 . 2011-06-26 23:03   190688   ----a-w-   c:\program files\senddmp.exe
2009-11-19 23:07 . 2011-06-26 23:03   189800   ----a-w-   c:\program files\adlmutil.dll
2009-11-19 23:07 . 2011-06-26 23:03   1274728   ----a-w-   c:\program files\adlmPIT.dll
2009-10-29 04:18 . 2011-06-26 23:03   653120   ----a-w-   c:\program files\msvcr90.dll
2009-10-29 04:18 . 2011-06-26 23:03   569664   ----a-w-   c:\program files\msvcp90.dll
2009-10-29 04:18 . 2011-06-26 23:03   225280   ----a-w-   c:\program files\msvcm90.dll
2009-09-10 02:57 . 2009-09-10 02:57   289830672   ------w-   c:\program files\Setup Prerequisites 08.11.07.03_en.exe
2009-06-08 01:37 . 2011-06-26 23:03   3783672   ----a-w-   c:\program files\mfc90u.dll
2008-05-05 19:55 . 2011-06-26 23:03   319248   ----a-w-   c:\program files\UPI32.dll
2008-04-10 11:31 . 2011-06-26 23:03   1835888   ----a-r-   c:\program files\xerces-c_2_8_AEC.dll
2004-05-04 14:53 . 2011-06-26 23:03   1645320   ----a-w-   c:\program files\gdiplus.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-06-15 15141768]
"AdobeUpdater"="c:\program files (x86)\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2011-02-16 2356088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-04-13 284696]
"HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2010-07-02 602680]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 624248]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"F-Secure Manager"="c:\program files (x86)\F-Secure\Common\FSM32.EXE" [2011-05-19 302832]
"F-Secure TNB"="c:\program files (x86)\F-Secure\FSGUI\TNBUtil.exe" [2011-05-19 1654512]
"CanonSolutionMenuEx"="c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112]
"IJNetworkScanUtility"="c:\program files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe" [2010-03-02 140640]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages   REG_MULTI_SZ      kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
="Service"
.
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-10 136176]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-06-18 103992]
R2 RtVOsdService;RtVOsdService Installer;c:\program files\Realtek\RtVOsd\RtVOsdService.exe [2010-06-17 315392]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-06-27 1436424]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files (x86)\F-Secure\ORSP Client\fsorsp.exe [2011-07-06 61088]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-10 136176]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys


R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows VISTA 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys

R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys

R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-09-23 225280]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys

R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS

R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS

R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe

R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys

S1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files (x86)\F-Secure\HIPS\drivers\fshs.sys [2011-05-19 61008]
S1 FSES;F-Secure Email Scanning Driver;c:\windows\system32\drivers\fses.sys

S1 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys

S1 fsvista;F-Secure Vista Support Driver;c:\program files (x86)\F-Secure\Anti-Virus\minifilter\fsvista.sys [2011-05-19 15856]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys

S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-07-02 27192]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-04-13 13336]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files (x86)\F-Secure\Anti-Virus\minifilter\fsgk.sys [2011-09-08 198808]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys

S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys

S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys

S3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys

.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai   REG_MULTI_SZ      Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-10 01:37]
.
2011-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-10 01:37]
.
2011-10-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-71440679-69947657-1278906953-1000Core.job
- c:\users\yin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-08 01:06]
.
2011-10-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-71440679-69947657-1278906953-1000UA.job
- c:\users\yin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-08 01:06]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2010-03-13 6234144]
"HPWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe" [2010-06-18 8192]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 161304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 415256]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2726728]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uStart Page = https://login.live.com/login.srf?cbcxt=out&vv=900&wa=wsignin1.0&wtrealm=urn:federation:MicrosoftOnline&wctx=wa%3Dwsignin1.0%26rpsnv%3D2%26ct%3D1298333514%26rver%3D6.1.6206.0%26wp%3DMBI_KEY%26wreply%3Dhttps:%252F%252Fwww.outlook.com%252Fowa%252F%26id%3D260563%26CBCXT%3Dout
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\yin\AppData\Roaming\Mozilla\Firefox\Profiles\k1t56s8f.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Browsing Protection: [email protected] - c:\program files (x86)\F-Secure\NRS\[email protected]
FF - Ext: Ovi Maps 3D browser plugin: [email protected] - %profile%\extensions\[email protected]
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-MousePolicyPolicy - c:\programdata\MousePolicyPolicy.dll
Wow6432Node-HKCU-Run-Mozilla Update - c:\users\yin\AppData\Local\Installer4632\Installer4632Update\Installer4632updt32.DLL
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
Denied: (A 2) (Everyone)
="FlashBroker"
"LocalizedString"="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
Denied: (A 2) (Everyone)
="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
Denied: (A 2) (Everyone)
="Macromedia Flash FACTORY Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
Denied: (A 2) (Everyone)
="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\windows\SysWOW64\ezSharedSvcHost.exe
c:\program files (x86)\F-Secure\Anti-Virus\fsgk32st.exe
c:\program files (x86)\F-Secure\Common\FSMA32.EXE
c:\program files (x86)\F-Secure\Anti-Virus\FSGK32.EXE
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\F-Secure\Anti-Virus\fssm32.exe
c:\program files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files (x86)\F-Secure\common\FSLAUNCH.EXE
.
**************************************************************************
.
Completion time: 2011-10-27  11:24:36 - machine was rebooted
ComboFix-quarantined-files.txt  2011-10-27 15:24
.
Pre-Run: 388,781,756,416 bytes free
Post-Run: 388,530,745,344 bytes free
.
- - End Of File - - 6D9C5D0ADBFFC11BACC6D5776E871A56
Scan for malware

Please download Malwarebytes Anti-Malware from Download.CNET.com.
Alternate link: BleepingComputer.com.
(Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

Double Click mbam-setup.exe to install the application.

(Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. If you are prompted to restart, please allow it to restart your computer. Failure to do this, will cause the infection to still be active on the computer.
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • The log can also be found at C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Copy and paste the entire report in your next reply.
heres my log from malwarebytes: am i ok now???
thanks again


Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8030

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

10/27/2011 2:20:21 PM
mbam-log-2011-10-27 (14-20-21).txt

Scan type: Quick scan
Objects scanned: 181827
Time elapsed: 2 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory MODULES Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
One more scan and I think you'll be good...

ESET Online Scan

Please run a free online scan with the ESET Online Scanner
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
393.

Solve : System Idle Process CPU won't go down?

Answer»

Okay, So I am quite stuck with this issue. I know that the System Idle Process is used when there's nothing to do and it will always be 99 around that. But the problem is that when I run a busy program or games which normally would instantly replace the CPU usage from System Idle Process. It doesn't now or it does only 50%, which makes my games lag and barely unplayable.

My computer spec isn't that stone and I think spec isn't the problem because the game I always run are just Warcraft III, Starcraft, Civilization etc..

I'm using WINXP SP3 with Intel Core 2 Duo 2.80 Ghz / 4 GB of RAM / Nvidia GeForce 9800GT

I have tried scanning with Malwarebytes(the first time I ever used antivirus since I formatted it) and it detected 9 infected files, mostly are the keygen and stuff, so I removed them and restarted, hoping my comp will be back just like normal but still bad luck. :/

Could it be my hardware problem ? Graphic card ? Fans ? getting old and dusty ?
or could it be any malware or virus ?

It just happened today for no reason. I am now can't get a decent Warcraft III game going because all the CPU goes to System Idle Process instead of the game. I'm currently so desperate right now and my school break is almost over. Any helps would be apreciated. Thx D:

If nothing could solve this then I think I will have to try my last trick, formatting my C: once again. D: D:

Edited. I have checked inside my case if all the fans are working properly and all the fans seem to work just fine
I used to face with this virus called KZipShell.dll, I got it from Chinese Online game called Dragonnest. The software was fake to be something similiar to WinRAR called KZip but the actual threat files is KZipShell.dll. It disabled my right clicking and deleting option until I can removed it manually by someway but I cannot remove the .dll file. I'm not sure if this got something to do with this issue because after I left the .dll  there everything works just fine ( it was about 2 months ago btw) until now.Hello.

Would you post the MBAM log please?

Please download DDS by sUBs from BleepingComputer.com or Forospyware.com and save it to your Desktop.

Note: Before scanning, make sure all other running programs are closed. There shouldn't be any scheduled antivirus scans running while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool.  No input is NEEDED, the scan is running.
  • Notepad will open with the results, click Yes to the Optional_Scan
  • Please follow the instructions that pop up for posting the results. Post only the contents of both logs. There is no way to attach.
  • Close the program window, and delete the program from your Desktop.
MBAM Log

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8021

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

10/26/2011 5:47:37 PM
mbam-log-2011-10-26 (17-47-37).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 373381
Time elapsed: 1 hour(s), 12 minute(s), 32 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 11

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\documents and settings\Nookia\my documents\cdkeybuddy v1.04\cdkeybuddy.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
d:\downloads\guitar pro 6.0.8 r9626 multilingual\Keymaker\keygen.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
d:\downloads\CS5\adobe photoshop cs5 extended\adobe cs5 all products keygens + individual product keygen\adobe creative suite 5 master collection keymaker\adobe_keygen_mc_cs5.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
d:\downloads\CS5\adobe photoshop cs5 extended\adobe cs5 all products keygens + individual product keygen\adobe dreamweaver cs5 v11.0.4909 keygen\adobe_dw_cs5_keygen.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
d:\downloads\CS5\adobe photoshop cs5 extended\adobe cs5 all products keygens + individual product keygen\adobe flash professional cs5 v11.0.0.485 keygen\adobe_fp_cs5_keygen.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
d:\downloads\CS5\adobe photoshop cs5 extended\adobe cs5 all products keygens + individual product keygen\adobe illustrator cs5 v15.0 keygen\adobe_il_cs5_keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
d:\downloads\CS5\adobe photoshop cs5 extended\adobe cs5 all products keygens + individual product keygen\adobe indesign cs5 premium v7.0 keygen\adobe_idp_cs5_keygen.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
d:\downloads\CS5\adobe photoshop cs5 extended\adobe cs5 all products keygens + individual product keygen\adobe photoshop cs5 extended v12.0 keygen\adobe_ps_cs5_keygen.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
d:\downloads\CS5\adobe photoshop cs5 extended\adobe cs5 all products keygens + individual product keygen\core adobe master collection cs5\adobe_keygen_mc_cs5.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
d:\Games\rhythm zone\uninstall.exe (Malware.Packer.Krunchy) -> Quarantined and deleted successfully.
d:\system volume information\_restore{65cd1720-a71e-43e1-a698-25902bb3649f}\RP11\A0014272.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
DDS Log [Both]

DDS

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702  BrowserJavaVersion: 1.6.0_27
Run by Nookia at 20:34:10 on 2011-10-26
Microsoft Windows XP Professional  5.1.2600.3.874.66.1033.18.3327.2663 [GMT 7:00]
.
.
============== Running Processes ===============
.
C:\WINXP\system32\nvsvc32.exe
C:\WINXP\system32\svchost -k DcomLaunch
svchost.exe
C:\WINXP\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINXP\system32\spoolsv.exe
C:\WINXP\Explorer.EXE
C:\WINXP\system32\RUNDLL32.EXE
C:\WINXP\RTHDCPL.EXE
C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe
svchost.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINXP\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\SddSUpdate\SddSUpdate.exe
C:\WINXP\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINXP\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.th/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: FlashGetBHO: {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - c:\documents and settings\nookia\application data\flashgetbho\FlashGetBHO3.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [CTFMON.EXE] c:\winxp\system32\ctfmon.exe
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [FlashGet 3] "c:\program files\flashget network\flashget 3\FlashGet3.exe" -minimize
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [NvMediaCenter] RUNDLL32.EXE c:\winxp\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\winxp\system32\NvCpl.dll,NvStartup
mRun: [IMJPMIG8.1] "c:\winxp\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\winxp\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\winxp\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [SIX Engine] "c:\program files\asus\epu-4 engine\FourEngine.exe" -r
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [NeroFilterCheck] c:\winxp\system32\NeroCheck.exe
mRun: [PlusService] c:\program files\yuna software\messenger plus!\PlusService.exe
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
dRun: [CTFMON.EXE] c:\winxp\system32\CTFMON.EXE
IE: Download all by FlashGet3 - c:\documents and settings\nookia\application data\flashgetbho\GetAllUrl.htm
IE: Download by FlashGet3 - c:\documents and settings\nookia\application data\flashgetbho\GetUrl.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
Trusted Zone: com.cn\*.cga
Trusted Zone: kuaiche.com\software
Trusted Zone: ogdev.net
Trusted Zone: sdo.com
DPF: {2B6F3D45-8258-4A13-85B8-58C62DFDB4EA} - hxxps://secure1.playfps.com/play/ava/ax/WebLauncher.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: Interfaces\{74B61D8C-FD92-4099-9703-D4AD44B5EB4C} : NameServer = 192.168.1.2,192.168.1.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~3\office12\GR99D3~1.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\winxp\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\nookia\application data\mozilla\firefox\profiles\msprhzcg.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.th/
FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
.
============= SERVICES / DRIVERS ===============
.
R0 mv61xx;mv61xx;c:\winxp\system32\drivers\mv61xx.sys [2011-3-2 159024]
R0 mv61xxmm;mv61xxmm;c:\winxp\system32\drivers\mv61xxmm.sys [2011-3-2 13616]
R0 mv64xxmm;mv64xxmm;c:\winxp\system32\drivers\mv64xxmm.sys [2011-3-2 5632]
R0 mvxxmm;mvxxmm;c:\winxp\system32\drivers\mvxxmm.sys [2011-3-2 13616]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\winxp\system32\drivers\dtsoftbus01.sys [2011-5-16 218688]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-10-26 366152]
R2 SddSUpdate;SddSUpdate;c:\program files\sddsupdate\SddSUpdate.exe [2011-9-27 466440]
R3 MBAMProtector;MBAMProtector;c:\winxp\system32\drivers\mbam.sys [2011-10-26 22216]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\winxp\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-7-30 136176]
S3 1394hub;1394 Enabled Hub;c:\winxp\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S3 Ambfilt;Ambfilt;c:\winxp\system32\drivers\Ambfilt.sys [2011-5-16 1684736]
S3 dump_wmimmc;dump_wmimmc;\??\d:\games\ea sports\fifa online 2\gameguard\dump_wmimmc.sys --> d:\games\ea sports\fifa online 2\gameguard\dump_wmimmc.sys [?]
S3 EagleXNt;EagleXNt;\??\c:\winxp\system32\drivers\eaglexnt.sys --> c:\winxp\system32\drivers\EagleXNt.sys [?]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\garena classic\safedrv.sys --> c:\program files\garena classic\safedrv.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-7-30 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\winxp\system32\drivers\mbamswissarmy.sys --> c:\winxp\system32\drivers\mbamswissarmy.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\winxp\system32\gamemon.des -service --> c:\winxp\system32\GameMon.des -service [?]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\winxp\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S3 XDva385;XDva385;\??\c:\winxp\system32\xdva385.sys --> c:\winxp\system32\XDva385.sys [?]
S3 XDva387;XDva387;\??\c:\winxp\system32\xdva387.sys --> c:\winxp\system32\XDva387.sys [?]
.
=============== Created Last 30 ================
.
2011-10-26 11:35:40   --------   d-----w-   c:\winxp\pss
2011-10-26 09:33:00   --------   d-----w-   c:\documents and settings\nookia\application data\Malwarebytes
2011-10-26 09:32:54   --------   d-----w-   c:\documents and settings\all users\application data\Malwarebytes
2011-10-26 09:32:51   22216   ----a-w-   c:\winxp\system32\drivers\mbam.sys
2011-10-26 09:32:51   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2011-10-25 12:30:45   --------   d-----w-   C:\Log
2011-10-25 10:19:29   --------   d-----w-   c:\winxp\EA Sports FIFA Online 2
2011-10-25 10:19:29   --------   d-----w-   C:\Joy2Key
2011-10-24 11:10:25   --------   d-----w-   c:\program files\KONAMI
2011-10-18 02:29:14   39424   ----a-w-   c:\winxp\LZService.exe
2011-10-18 02:28:45   132880   ----a-w-   c:\winxp\system32\MSINET.OCX
2011-10-16 17:06:49   74072   ----a-w-   c:\winxp\system32\XAPOFX1_5.dll
2011-10-16 17:06:49   527192   ----a-w-   c:\winxp\system32\XAudio2_7.dll
2011-10-16 17:06:49   239960   ----a-w-   c:\winxp\system32\xactengine3_7.dll
2011-10-16 17:06:49   2106216   ----a-w-   c:\winxp\system32\D3DCompiler_43.dll
2011-10-16 17:06:48   470880   ----a-w-   c:\winxp\system32\d3dx10_43.dll
2011-10-16 17:06:48   248672   ----a-w-   c:\winxp\system32\d3dx11_43.dll
2011-10-16 17:06:48   1868128   ----a-w-   c:\winxp\system32\d3dcsx_43.dll
2011-10-16 17:06:47   1998168   ----a-w-   c:\winxp\system32\D3DX9_43.dll
2011-10-16 16:40:09   --------   d-----w-   c:\documents and settings\nookia\application data\NVIDIA
2011-10-11 15:47:15   74072   ----a-w-   c:\winxp\system32\XAPOFX1_4.dll
2011-10-11 15:47:15   528216   ----a-w-   c:\winxp\system32\XAudio2_6.dll
2011-10-11 15:47:15   238936   ----a-w-   c:\winxp\system32\xactengine3_6.dll
2011-10-11 15:47:14   22360   ----a-w-   c:\winxp\system32\X3DAudio1_7.dll
2011-10-10 04:09:40   4550304   ----a-w-   c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
2011-10-07 05:33:50   --------   d-----w-   c:\program files\HHD Software
2011-10-06 03:54:14   --------   d-----w-   c:\documents and settings\nookia\application data\fretsonfire
2011-10-06 03:53:56   --------   d-----w-   c:\program files\Frets on Fire
2011-10-04 03:14:25   --------   d-----w-   c:\program files\Activision
2011-10-04 02:58:01   --------   d-----w-   c:\documents and settings\nookia\local settings\application data\Activision
2011-10-04 02:41:11   --------   d-sh--w-   c:\winxp\ftpcache
2011-10-02 08:56:03   --------   d-----w-   c:\documents and settings\all users\application data\NexonUS
2011-10-02 04:17:27   --------   d-----w-   c:\program files\Acoustica Shared Effects
2011-10-02 04:08:09   --------   d-----w-   c:\documents and settings\all users\application data\Acoustica
2011-10-02 04:07:33   --------   d-----w-   c:\program files\Acoustica Mixcraft 5
2011-10-01 15:51:06   --------   d-----w-   c:\program files\ASIO4ALL v2
2011-10-01 15:50:50   225280   ----a-w-   c:\winxp\system32\rewire.dll
2011-10-01 15:50:50   --------   d-----w-   c:\program files\VstPlugins
2011-10-01 15:50:43   1554944   ----a-w-   c:\winxp\system32\vorbis.acm
2011-10-01 15:50:39   --------   d-----w-   c:\program files\Outsim
2011-10-01 15:47:09   --------   d-----w-   c:\program files\Image-Line
2011-10-01 15:47:04   1700352   ----a-w-   c:\winxp\system32\gdiplus.dll
2011-10-01 15:44:42   --------   d-----w-   c:\program files\FL Studio
2011-09-30 13:34:35   --------   d-----w-   c:\documents and settings\all users\application data\Electronic Arts
2011-09-30 13:34:35   --------   d-----w-   c:\documents and settings\all users\application data\EA Core
2011-09-30 13:32:51   447752   ----a-r-   c:\winxp\system32\vp6vfw.dll
2011-09-30 13:32:50   --------   d-----w-   c:\program files\Microsoft WSE
2011-09-29 10:46:57   --------   d-----w-   c:\documents and settings\nookia\local settings\application data\Firaxis Games
2011-09-29 09:39:02   --------   d-----w-   c:\winxp\system32\XPSViewer
2011-09-29 01:58:32   89088   ----a-w-   c:\winxp\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-09-29 01:58:10   89088   -c----w-   c:\winxp\system32\dllcache\filterpipelineprintproc.dll
2011-09-29 01:58:10   117760   ------w-   c:\winxp\system32\prntvpt.dll
2011-09-29 01:58:09   597504   -c----w-   c:\winxp\system32\dllcache\printfilterpipelinesvc.exe
2011-09-29 01:58:09   597504   ------w-   c:\winxp\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-09-29 01:58:09   575488   -c----w-   c:\winxp\system32\dllcache\xpsshhdr.dll
2011-09-29 01:58:09   575488   ------w-   c:\winxp\system32\xpsshhdr.dll
2011-09-29 01:58:09   1676288   -c----w-   c:\winxp\system32\dllcache\xpssvcs.dll
2011-09-29 01:58:09   1676288   ------w-   c:\winxp\system32\xpssvcs.dll
2011-09-29 01:58:09   --------   d-----w-   C:\3f9d14be43711397db9ffd31043f28bc
2011-09-29 01:54:54   --------   d-----w-   C:\cc6b51d250c0cea3656f1fb210
2011-09-29 01:54:37   --------   d-----w-   C:\02798d8739b357d4a4b0e2
2011-09-28 17:31:03   --------   d-----w-   C:\7beff02027e3d28540fca470
2011-09-26 16:11:53   --------   d-----w-   c:\program files\common files\Steam
.
==================== Find3M  ====================
.
2011-10-23 02:12:11   414368   ----a-w-   c:\winxp\system32\FlashPlayerCPLApp.cpl
2011-10-16 18:20:04   444952   ----a-w-   c:\winxp\system32\wrap_oal.dll
2011-10-16 18:20:04   109080   ----a-w-   c:\winxp\system32\OpenAL32.dll
2011-09-10 02:42:04   73728   ----a-w-   c:\winxp\system32\javacpl.cpl
2011-09-10 02:42:03   472808   ----a-w-   c:\winxp\system32\deployJava1.dll
.
============= FINISH: 20:34:17.51 ===============
DDS Log [Both]

Attach

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702  BrowserJavaVersion: 1.6.0_27
Run by Nookia at 20:34:10 on 2011-10-26
Microsoft Windows XP Professional  5.1.2600.3.874.66.1033.18.3327.2663 [GMT 7:00]
.
.
============== Running Processes ===============
.
C:\WINXP\system32\nvsvc32.exe
C:\WINXP\system32\svchost -k DcomLaunch
svchost.exe
C:\WINXP\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINXP\system32\spoolsv.exe
C:\WINXP\Explorer.EXE
C:\WINXP\system32\RUNDLL32.EXE
C:\WINXP\RTHDCPL.EXE
C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe
svchost.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINXP\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\SddSUpdate\SddSUpdate.exe
C:\WINXP\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINXP\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.th/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: FlashGetBHO: {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - c:\documents and settings\nookia\application data\flashgetbho\FlashGetBHO3.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [CTFMON.EXE] c:\winxp\system32\ctfmon.exe
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [FlashGet 3] "c:\program files\flashget network\flashget 3\FlashGet3.exe" -minimize
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [NvMediaCenter] RUNDLL32.EXE c:\winxp\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\winxp\system32\NvCpl.dll,NvStartup
mRun: [IMJPMIG8.1] "c:\winxp\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\winxp\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\winxp\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Six Engine] "c:\program files\asus\epu-4 engine\FourEngine.exe" -r
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [NeroFilterCheck] c:\winxp\system32\NeroCheck.exe
mRun: [PlusService] c:\program files\yuna software\messenger plus!\PlusService.exe
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
dRun: [CTFMON.EXE] c:\winxp\system32\CTFMON.EXE
IE: Download all by FlashGet3 - c:\documents and settings\nookia\application data\flashgetbho\GetAllUrl.htm
IE: Download by FlashGet3 - c:\documents and settings\nookia\application data\flashgetbho\GetUrl.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
Trusted Zone: com.cn\*.cga
Trusted Zone: kuaiche.com\software
Trusted Zone: ogdev.net
Trusted Zone: sdo.com
DPF: {2B6F3D45-8258-4A13-85B8-58C62DFDB4EA} - hxxps://secure1.playfps.com/play/ava/ax/WebLauncher.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: Interfaces\{74B61D8C-FD92-4099-9703-D4AD44B5EB4C} : NameServer = 192.168.1.2,192.168.1.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~3\office12\GR99D3~1.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\winxp\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\nookia\application data\mozilla\firefox\profiles\msprhzcg.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.th/
FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
.
============= SERVICES / DRIVERS ===============
.
R0 mv61xx;mv61xx;c:\winxp\system32\drivers\mv61xx.sys [2011-3-2 159024]
R0 mv61xxmm;mv61xxmm;c:\winxp\system32\drivers\mv61xxmm.sys [2011-3-2 13616]
R0 mv64xxmm;mv64xxmm;c:\winxp\system32\drivers\mv64xxmm.sys [2011-3-2 5632]
R0 mvxxmm;mvxxmm;c:\winxp\system32\drivers\mvxxmm.sys [2011-3-2 13616]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\winxp\system32\drivers\dtsoftbus01.sys [2011-5-16 218688]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-10-26 366152]
R2 SddSUpdate;SddSUpdate;c:\program files\sddsupdate\SddSUpdate.exe [2011-9-27 466440]
R3 MBAMProtector;MBAMProtector;c:\winxp\system32\drivers\mbam.sys [2011-10-26 22216]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\winxp\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-7-30 136176]
S3 1394hub;1394 Enabled Hub;c:\winxp\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S3 Ambfilt;Ambfilt;c:\winxp\system32\drivers\Ambfilt.sys [2011-5-16 1684736]
S3 dump_wmimmc;dump_wmimmc;\??\d:\games\ea sports\fifa online 2\gameguard\dump_wmimmc.sys --> d:\games\ea sports\fifa online 2\gameguard\dump_wmimmc.sys [?]
S3 EagleXNt;EagleXNt;\??\c:\winxp\system32\drivers\eaglexnt.sys --> c:\winxp\system32\drivers\EagleXNt.sys [?]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\garena classic\safedrv.sys --> c:\program files\garena classic\safedrv.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-7-30 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\winxp\system32\drivers\mbamswissarmy.sys --> c:\winxp\system32\drivers\mbamswissarmy.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\winxp\system32\gamemon.des -service --> c:\winxp\system32\GameMon.des -service [?]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\winxp\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S3 XDva385;XDva385;\??\c:\winxp\system32\xdva385.sys --> c:\winxp\system32\XDva385.sys [?]
S3 XDva387;XDva387;\??\c:\winxp\system32\xdva387.sys --> c:\winxp\system32\XDva387.sys [?]
.
=============== Created Last 30 ================
.
2011-10-26 11:35:40   --------   d-----w-   c:\winxp\pss
2011-10-26 09:33:00   --------   d-----w-   c:\documents and settings\nookia\application data\Malwarebytes
2011-10-26 09:32:54   --------   d-----w-   c:\documents and settings\all users\application data\Malwarebytes
2011-10-26 09:32:51   22216   ----a-w-   c:\winxp\system32\drivers\mbam.sys
2011-10-26 09:32:51   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2011-10-25 12:30:45   --------   d-----w-   C:\Log
2011-10-25 10:19:29   --------   d-----w-   c:\winxp\EA Sports FIFA Online 2
2011-10-25 10:19:29   --------   d-----w-   C:\Joy2Key
2011-10-24 11:10:25   --------   d-----w-   c:\program files\KONAMI
2011-10-18 02:29:14   39424   ----a-w-   c:\winxp\LZService.exe
2011-10-18 02:28:45   132880   ----a-w-   c:\winxp\system32\MSINET.OCX
2011-10-16 17:06:49   74072   ----a-w-   c:\winxp\system32\XAPOFX1_5.dll
2011-10-16 17:06:49   527192   ----a-w-   c:\winxp\system32\XAudio2_7.dll
2011-10-16 17:06:49   239960   ----a-w-   c:\winxp\system32\xactengine3_7.dll
2011-10-16 17:06:49   2106216   ----a-w-   c:\winxp\system32\D3DCompiler_43.dll
2011-10-16 17:06:48   470880   ----a-w-   c:\winxp\system32\d3dx10_43.dll
2011-10-16 17:06:48   248672   ----a-w-   c:\winxp\system32\d3dx11_43.dll
2011-10-16 17:06:48   1868128   ----a-w-   c:\winxp\system32\d3dcsx_43.dll
2011-10-16 17:06:47   1998168   ----a-w-   c:\winxp\system32\D3DX9_43.dll
2011-10-16 16:40:09   --------   d-----w-   c:\documents and settings\nookia\application data\NVIDIA
2011-10-11 15:47:15   74072   ----a-w-   c:\winxp\system32\XAPOFX1_4.dll
2011-10-11 15:47:15   528216   ----a-w-   c:\winxp\system32\XAudio2_6.dll
2011-10-11 15:47:15   238936   ----a-w-   c:\winxp\system32\xactengine3_6.dll
2011-10-11 15:47:14   22360   ----a-w-   c:\winxp\system32\X3DAudio1_7.dll
2011-10-10 04:09:40   4550304   ----a-w-   c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
2011-10-07 05:33:50   --------   d-----w-   c:\program files\HHD Software
2011-10-06 03:54:14   --------   d-----w-   c:\documents and settings\nookia\application data\fretsonfire
2011-10-06 03:53:56   --------   d-----w-   c:\program files\Frets on Fire
2011-10-04 03:14:25   --------   d-----w-   c:\program files\Activision
2011-10-04 02:58:01   --------   d-----w-   c:\documents and settings\nookia\local settings\application data\Activision
2011-10-04 02:41:11   --------   d-sh--w-   c:\winxp\ftpcache
2011-10-02 08:56:03   --------   d-----w-   c:\documents and settings\all users\application data\NexonUS
2011-10-02 04:17:27   --------   d-----w-   c:\program files\Acoustica Shared Effects
2011-10-02 04:08:09   --------   d-----w-   c:\documents and settings\all users\application data\Acoustica
2011-10-02 04:07:33   --------   d-----w-   c:\program files\Acoustica Mixcraft 5
2011-10-01 15:51:06   --------   d-----w-   c:\program files\ASIO4ALL v2
2011-10-01 15:50:50   225280   ----a-w-   c:\winxp\system32\rewire.dll
2011-10-01 15:50:50   --------   d-----w-   c:\program files\VstPlugins
2011-10-01 15:50:43   1554944   ----a-w-   c:\winxp\system32\vorbis.acm
2011-10-01 15:50:39   --------   d-----w-   c:\program files\Outsim
2011-10-01 15:47:09   --------   d-----w-   c:\program files\Image-Line
2011-10-01 15:47:04   1700352   ----a-w-   c:\winxp\system32\gdiplus.dll
2011-10-01 15:44:42   --------   d-----w-   c:\program files\FL Studio
2011-09-30 13:34:35   --------   d-----w-   c:\documents and settings\all users\application data\Electronic Arts
2011-09-30 13:34:35   --------   d-----w-   c:\documents and settings\all users\application data\EA Core
2011-09-30 13:32:51   447752   ----a-r-   c:\winxp\system32\vp6vfw.dll
2011-09-30 13:32:50   --------   d-----w-   c:\program files\Microsoft WSE
2011-09-29 10:46:57   --------   d-----w-   c:\documents and settings\nookia\local settings\application data\Firaxis Games
2011-09-29 09:39:02   --------   d-----w-   c:\winxp\system32\XPSViewer
2011-09-29 01:58:32   89088   ----a-w-   c:\winxp\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-09-29 01:58:10   89088   -c----w-   c:\winxp\system32\dllcache\filterpipelineprintproc.dll
2011-09-29 01:58:10   117760   ------w-   c:\winxp\system32\prntvpt.dll
2011-09-29 01:58:09   597504   -c----w-   c:\winxp\system32\dllcache\printfilterpipelinesvc.exe
2011-09-29 01:58:09   597504   ------w-   c:\winxp\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-09-29 01:58:09   575488   -c----w-   c:\winxp\system32\dllcache\xpsshhdr.dll
2011-09-29 01:58:09   575488   ------w-   c:\winxp\system32\xpsshhdr.dll
2011-09-29 01:58:09   1676288   -c----w-   c:\winxp\system32\dllcache\xpssvcs.dll
2011-09-29 01:58:09   1676288   ------w-   c:\winxp\system32\xpssvcs.dll
2011-09-29 01:58:09   --------   d-----w-   C:\3f9d14be43711397db9ffd31043f28bc
2011-09-29 01:54:54   --------   d-----w-   C:\cc6b51d250c0cea3656f1fb210
2011-09-29 01:54:37   --------   d-----w-   C:\02798d8739b357d4a4b0e2
2011-09-28 17:31:03   --------   d-----w-   C:\7beff02027e3d28540fca470
2011-09-26 16:11:53   --------   d-----w-   c:\program files\common files\Steam
.
==================== Find3M  ====================
.
2011-10-23 02:12:11   414368   ----a-w-   c:\winxp\system32\FlashPlayerCPLApp.cpl
2011-10-16 18:20:04   444952   ----a-w-   c:\winxp\system32\wrap_oal.dll
2011-10-16 18:20:04   109080   ----a-w-   c:\winxp\system32\OpenAL32.dll
2011-09-10 02:42:04   73728   ----a-w-   c:\winxp\system32\javacpl.cpl
2011-09-10 02:42:03   472808   ----a-w-   c:\winxp\system32\deployJava1.dll
.
============= FINISH: 20:34:17.51 ===============
Your computer has keygens, which are a form of software piracy. What is so bad about Cracks, Hacks, Pirated software, warez, or Keygens?

Most popular cracks or keygens I see, are for Adobe CS3, a lot of different games, Nero, Kaspersky antivirus, and much more. All of these cracks and keygens have what is called "cloaked malware," which is a form of spyware or viruses or trojans that hide themselves inside the keygen or crack files. Most hacks for games that come in the form of a program or installer, will also be infected. It is the opportunity for attackers to present a seemingly safe situation where the opportunity to steal something is in play, while the malware infects your system in the process. Yes, it will install what you were looking for, but also allow malware to potentially take control of your computer.

Lastly, it is illegal. I will counsel you that we do not report such incidents. However, it is not good practice to pirate software.


Please visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here. Quote from: DragonMaster Jay on October 26, 2011, 09:37:41 AM
Your computer has keygens, which are a form of software piracy. What is so bad about Cracks, Hacks, Pirated software, warez, or Keygens?

Most popular cracks or keygens I see, are for Adobe CS3, a lot of different games, Nero, Kaspersky antivirus, and much more. All of these cracks and keygens have what is called "cloaked malware," which is a form of spyware or viruses or trojans that hide themselves inside the keygen or crack files. Most hacks for games that come in the form of a program or installer, will also be infected. It is the opportunity for attackers to present a seemingly safe situation where the opportunity to steal something is in play, while the malware infects your system in the process. Yes, it will install what you were looking for, but also allow malware to potentially take control of your computer.

Lastly, it is illegal. I will counsel you that we do not report such incidents. However, it is not good practice to pirate software.


Please visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here.
Thank You for your effort in replying my issue. I can see now that the cracks and keygen could have malware hidden in them. I will try not to pirate anymore software from now. But I still don't know how does that involves with the System Idle Process eating all the CPU ? Have you ever experienced these kinds of issue before ? I mean issue about the System Idle Process things because I mostly see it goes with svchost.exe instead.

And here are the combofix log

ComboFix 11-10-26.03 - Nookia 10/26/2011  23:07:22.2.2 - x86
Microsoft Windows XP Professional  5.1.2600.3.874.66.1033.18.3327.2604 [GMT 7:00]
Running from: c:\documents and settings\Nookia\Desktop\ComboFix.exe
.
.
(((((((((((((((((((((((((   Files Created from 2011-09-26 to 2011-10-26  )))))))))))))))))))))))))))))))
.
.
2011-10-26 14:01 . 2011-10-26 14:01   --------   d-----w-   c:\program files\Defraggler
2011-10-26 09:33 . 2011-10-26 09:33   --------   d-----w-   c:\documents and settings\Nookia\Application Data\Malwarebytes
2011-10-26 09:32 . 2011-10-26 09:32   --------   d-----w-   c:\documents and settings\All Users\Application Data\Malwarebytes
2011-10-26 09:32 . 2011-10-26 09:32   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2011-10-26 09:32 . 2011-08-31 10:00   22216   ----a-w-   c:\winxp\system32\drivers\mbam.sys
2011-10-26 09:09 . 2011-10-26 09:09   --------   d-----w-   c:\documents and settings\Guest\Local Settings\Application Data\Activision
2011-10-26 08:59 . 2011-10-26 08:59   --------   d-----w-   c:\documents and settings\Guest\Local Settings\Application Data\SKIDROW
2011-10-26 08:57 . 2011-10-26 08:57   --------   d-----w-   c:\documents and settings\Guest\Local Settings\Application Data\My Games
2011-10-25 12:30 . 2011-10-25 12:30   --------   d-----w-   C:\Log
2011-10-25 10:19 . 2011-10-25 10:19   --------   d-----w-   c:\winxp\EA Sports FIFA Online 2
2011-10-25 10:19 . 2011-10-25 10:19   --------   d-----w-   C:\Joy2Key
2011-10-24 11:10 . 2011-10-25 08:18   --------   d-----w-   c:\program files\KONAMI
2011-10-18 02:29 . 2011-10-18 02:29   39424   ----a-w-   c:\winxp\LZService.exe
2011-10-18 02:28 . 2009-10-05 19:47   132880   ----a-w-   c:\winxp\system32\MSINET.OCX
2011-10-16 17:06 . 2010-06-01 21:55   74072   ----a-w-   c:\winxp\system32\XAPOFX1_5.dll
2011-10-16 17:06 . 2010-06-01 21:55   527192   ----a-w-   c:\winxp\system32\XAudio2_7.dll
2011-10-16 17:06 . 2010-06-01 21:55   239960   ----a-w-   c:\winxp\system32\xactengine3_7.dll
2011-10-16 17:06 . 2010-05-26 04:41   2106216   ----a-w-   c:\winxp\system32\D3DCompiler_43.dll
2011-10-16 17:06 . 2010-05-26 04:41   470880   ----a-w-   c:\winxp\system32\d3dx10_43.dll
2011-10-16 17:06 . 2010-05-26 04:41   248672   ----a-w-   c:\winxp\system32\d3dx11_43.dll
2011-10-16 17:06 . 2010-05-26 04:41   1868128   ----a-w-   c:\winxp\system32\d3dcsx_43.dll
2011-10-16 17:06 . 2010-05-26 04:41   1998168   ----a-w-   c:\winxp\system32\D3DX9_43.dll
2011-10-16 16:40 . 2011-10-16 16:40   --------   d-----w-   c:\documents and settings\Nookia\Application Data\NVIDIA
2011-10-11 15:47 . 2010-02-04 03:01   74072   ----a-w-   c:\winxp\system32\XAPOFX1_4.dll
2011-10-11 15:47 . 2010-02-04 03:01   528216   ----a-w-   c:\winxp\system32\XAudio2_6.dll
2011-10-11 15:47 . 2010-02-04 03:01   238936   ----a-w-   c:\winxp\system32\xactengine3_6.dll
2011-10-11 15:47 . 2010-02-04 03:01   22360   ----a-w-   c:\winxp\system32\X3DAudio1_7.dll
2011-10-10 04:09 . 2011-10-10 04:09   4550304   ----a-w-   c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2011-10-07 05:33 . 2011-10-07 05:33   --------   d-----w-   c:\program files\HHD Software
2011-10-06 03:54 . 2011-10-06 03:56   --------   d-----w-   c:\documents and settings\Nookia\Application Data\fretsonfire
2011-10-06 03:53 . 2011-10-06 03:54   --------   d-----w-   c:\program files\Frets on Fire
2011-10-04 03:14 . 2011-10-04 03:14   --------   d-----w-   c:\program files\Activision
2011-10-04 02:58 . 2011-10-06 00:35   --------   d-----w-   c:\documents and settings\Nookia\Local Settings\Application Data\Activision
2011-10-04 02:41 . 2011-10-04 02:41   --------   d-sh--w-   c:\winxp\ftpcache
2011-10-02 08:56 . 2011-10-02 08:56   --------   d-----w-   c:\documents and settings\All Users\Application Data\NexonUS
2011-10-02 04:17 . 2011-10-02 04:17   --------   d-----w-   c:\program files\Acoustica Shared Effects
2011-10-02 04:08 . 2011-10-02 04:08   --------   d-----w-   c:\documents and settings\All Users\Application Data\Acoustica
2011-10-02 04:07 . 2011-10-02 04:22   --------   d-----w-   c:\program files\Acoustica Mixcraft 5
2011-10-01 15:51 . 2011-10-01 15:51   --------   d-----w-   c:\program files\ASIO4ALL v2
2011-10-01 15:50 . 2011-10-01 15:50   --------   d-----w-   c:\program files\VstPlugins
2011-10-01 15:50 . 2006-06-20 08:56   225280   ----a-w-   c:\winxp\system32\rewire.dll
2011-10-01 15:50 . 2009-09-15 09:14   1554944   ----a-w-   c:\winxp\system32\vorbis.acm
2011-10-01 15:50 . 2011-10-01 15:50   --------   d-----w-   c:\program files\Outsim
2011-10-01 15:47 . 2011-10-01 15:50   --------   d-----w-   c:\program files\Image-Line
2011-10-01 15:47 . 2011-10-01 15:47   1700352   ----a-w-   c:\winxp\system32\gdiplus.dll
2011-10-01 15:44 . 2011-10-01 15:45   --------   d-----w-   c:\program files\FL Studio
2011-09-30 13:34 . 2011-09-30 13:34   --------   d-----w-   c:\documents and settings\All Users\Application Data\Electronic Arts
2011-09-30 13:34 . 2011-09-30 13:34   --------   d-----w-   c:\documents and settings\All Users\Application Data\EA Core
2011-09-30 13:32 . 2010-11-23 00:09   447752   ----a-r-   c:\winxp\system32\vp6vfw.dll
2011-09-30 13:32 . 2011-09-30 13:32   --------   d-----w-   c:\program files\Microsoft WSE
2011-09-29 10:46 . 2011-09-29 10:46   --------   d-----w-   c:\documents and settings\Nookia\Local Settings\Application Data\Firaxis Games
2011-09-29 09:39 . 2011-09-29 09:39   --------   d-----w-   c:\winxp\system32\XPSViewer
2011-09-29 01:58 . 2011-09-29 01:58   --------   d-----w-   c:\program files\Reference Assemblies
2011-09-29 01:58 . 2008-07-06 12:06   89088   ----a-w-   c:\winxp\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-09-29 01:58 . 2008-07-06 12:06   89088   -c----w-   c:\winxp\system32\dllcache\filterpipelineprintproc.dll
2011-09-29 01:58 . 2008-07-06 12:06   117760   ------w-   c:\winxp\system32\prntvpt.dll
2011-09-29 01:58 . 2011-09-29 01:58   --------   d-----w-   C:\3f9d14be43711397db9ffd31043f28bc
2011-09-29 01:58 . 2008-07-06 12:06   575488   -c----w-   c:\winxp\system32\dllcache\xpsshhdr.dll
2011-09-29 01:58 . 2008-07-06 12:06   575488   ------w-   c:\winxp\system32\xpsshhdr.dll
2011-09-29 01:58 . 2008-07-06 12:06   1676288   -c----w-   c:\winxp\system32\dllcache\xpssvcs.dll
2011-09-29 01:58 . 2008-07-06 12:06   1676288   ------w-   c:\winxp\system32\xpssvcs.dll
2011-09-29 01:58 . 2008-07-06 10:50   597504   -c----w-   c:\winxp\system32\dllcache\printfilterpipelinesvc.exe
2011-09-29 01:58 . 2008-07-06 10:50   597504   ------w-   c:\winxp\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-09-29 01:54 . 2011-09-29 01:54   --------   d-----w-   C:\cc6b51d250c0cea3656f1fb210
2011-09-29 01:54 . 2011-09-29 04:17   --------   d-----w-   C:\02798d8739b357d4a4b0e2
2011-09-28 17:31 . 2011-09-28 17:53   --------   d-----w-   C:\7beff02027e3d28540fca470
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-23 02:12 . 2011-09-10 01:59   414368   ----a-w-   c:\winxp\system32\FlashPlayerCPLApp.cpl
2011-10-16 18:20 . 2011-06-24 13:11   444952   ----a-w-   c:\winxp\system32\wrap_oal.dll
2011-10-16 18:20 . 2011-06-24 13:11   109080   ----a-w-   c:\winxp\system32\OpenAL32.dll
2011-09-10 02:42 . 2011-09-10 02:42   73728   ----a-w-   c:\winxp\system32\javacpl.cpl
2011-09-10 02:42 . 2011-09-10 02:42   472808   ----a-w-   c:\winxp\system32\deployJava1.dll
2011-10-02 23:36 . 2011-05-16 09:54   134104   ----a-w-   c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-09-16 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\winxp\system32\dllcache\tcpip.sys
[-] 2010-09-16 . A5BC817BB84DCB9E71719FF868144124 . 361600 . . [5.1.2600.5625] . . c:\winxp\system32\drivers\tcpip.sys
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\KzShlobj]
="{AAA0C5B8-933F-4200-93AD-B143D7FFF9F2}"
[HKEY_CLASSES_ROOT\CLSID\{AAA0C5B8-933F-4200-93AD-B143D7FFF9F2}]
2011-08-31 02:21   224288   ----a-w-   c:\program files\ฟ์ัน\KZipShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"FlashGet 3"="c:\program files\FlashGet Network\FlashGet 3\FlashGet3.exe" [2009-12-22 2127408]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\winxp\system32\NvMcTray.dll" [2010-10-16 110696]
"NvCplDaemon"="c:\winxp\system32\NvCpl.dll" [2010-10-16 13851752]
"IMJPMIG8.1"="c:\winxp\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"PHIME2002ASync"="c:\winxp\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\winxp\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"RTHDCPL"="RTHDCPL.EXE" [2008-11-17 17676288]
"Six Engine"="c:\program files\ASUS\EPU-4 Engine\FourEngine.exe" [2008-07-23 5625344]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-29 30248]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-29 46632]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"NeroFilterCheck"="c:\winxp\system32\NeroCheck.exe" [2001-07-09 155648]
"PlusService"="c:\program files\Yuna Software\Messenger Plus!\PlusService.exe" [2011-09-20 801792]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-12 663552]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-08-18 421736]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-30 499608]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-21 406992]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\winxp\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\FlashGet Network\\FlashGet 3\\FlashGet3.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Nookia\\My Documents\\Downloads\\Software\\Setup-MsgPlus-501.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\Starcraft\\StarCraft.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\KONAMI\\Pro Evolution Soccer 2012\\pes2012.exe"=
"d:\\Games\\EA Sports\\FIFA Online 2\\FF2Client.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:Thaicybergames
.
R0 mv61xx;mv61xx;c:\winxp\system32\drivers\mv61xx.sys [3/2/2011 3:45 PM 159024]
R0 mv61xxmm;mv61xxmm;c:\winxp\system32\drivers\mv61xxmm.sys [3/2/2011 3:45 PM 13616]
R0 mv64xxmm;mv64xxmm;c:\winxp\system32\drivers\mv64xxmm.sys [3/2/2011 3:45 PM 5632]
R0 mvxxmm;mvxxmm;c:\winxp\system32\drivers\mvxxmm.sys [3/2/2011 3:45 PM 13616]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\winxp\system32\drivers\dtsoftbus01.sys [5/16/2011 5:19 PM 218688]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [10/26/2011 4:32 PM 366152]
R2 SddSUpdate;SddSUpdate;c:\program files\SddSUpdate\SddSUpdate.exe [9/27/2011 9:47 AM 466440]
R3 MBAMProtector;MBAMProtector;c:\winxp\system32\drivers\mbam.sys [10/26/2011 4:32 PM 22216]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\winxp\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/30/2011 1:18 PM 136176]
S3 1394hub;1394 Enabled Hub;c:\winxp\system32\svchost.exe -k netsvcs [4/14/2008 5:00 PM 14336]
S3 Ambfilt;Ambfilt;c:\winxp\system32\drivers\Ambfilt.sys [5/16/2011 10:45 PM 1684736]
S3 dump_wmimmc;dump_wmimmc;\??\d:\games\EA Sports\FIFA Online 2\GameGuard\dump_wmimmc.sys --> d:\games\EA Sports\FIFA Online 2\GameGuard\dump_wmimmc.sys [?]
S3 EagleXNt;EagleXNt;\??\c:\winxp\system32\drivers\EagleXNt.sys --> c:\winxp\system32\drivers\EagleXNt.sys [?]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena Classic\safedrv.sys --> c:\program files\Garena Classic\safedrv.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [7/30/2011 1:18 PM 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\winxp\system32\drivers\mbamswissarmy.sys --> c:\winxp\system32\drivers\mbamswissarmy.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\winxp\system32\GameMon.des -service --> c:\winxp\system32\GameMon.des -service [?]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 1:37 PM 517096]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\winxp\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S3 XDva385;XDva385;\??\c:\winxp\system32\XDva385.sys --> c:\winxp\system32\XDva385.sys [?]
S3 XDva387;XDva387;\??\c:\winxp\system32\XDva387.sys --> c:\winxp\system32\XDva387.sys [?]
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-01 c:\winxp\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 10:57]
.
2011-10-26 c:\winxp\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-30 06:18]
.
2011-10-26 c:\winxp\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-30 06:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.th/
uInternet Settings,ProxyOverride = *.local
IE: Download all by FlashGet3 - c:\documents and settings\Nookia\Application Data\FlashGetBHO\GetAllUrl.htm
IE: Download by FlashGet3 - c:\documents and settings\Nookia\Application Data\FlashGetBHO\GetUrl.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: com.cn\*.cga
Trusted Zone: kuaiche.com\software
Trusted Zone: ogdev.net
Trusted Zone: sdo.com
TCP: Interfaces\{74B61D8C-FD92-4099-9703-D4AD44B5EB4C}: NameServer = 192.168.1.2,192.168.1.1
DPF: {2B6F3D45-8258-4A13-85B8-58C62DFDB4EA} - hxxps://secure1.playfps.com/play/ava/ax/WebLauncher.cab
FF - ProfilePath - c:\documents and settings\Nookia\Application Data\Mozilla\Firefox\Profiles\msprhzcg.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.th/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-26 23:13
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ... 
.
scanning hidden autostart entries ...
.
scanning hidden files ... 
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\winxp\system32\GameMon.des -service"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(1092)
c:\winxp\system32\WININET.dll
c:\winxp\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\ฟ์ัน\KZipShell.dll
c:\winxp\system32\ieframe.dll
c:\winxp\system32\webcheck.dll
c:\winxp\system32\WPDShServiceObj.dll
c:\winxp\system32\PortableDeviceTypes.dll
c:\winxp\system32\PortableDeviceApi.dll
.
Completion time: 2011-10-26  23:14:49
ComboFix-quarantined-files.txt  2011-10-26 16:14
.
Pre-Run: 37,932,589,056 bytes free
Post-Run: 38,512,857,088 bytes free
.
- - End Of File - - 5ACDDA9150E00B7F4D5779A0A3F8259B

As you can see there's this Chinese threat "KZipShell.dll" which I can't delete it, working under explorer.exe. I'm not sure if it is the reason which effecting my System Idle Process. But I'm quite sure it is some kind of threat to my computer. :/

Here is where I got information from http://www.threatexpert.com/report.aspx?md5=d1975c00385cb9c9d11d17289ae34d0e

I have detected various IPs from Malwarebytes protection log too.
77.78.224.33
89.28.85.132
208.91.207.10
91.197.237.17
109.235.55.11
194.54.80.150
62.45.3.198
222.65.184.25
212.117.164.209

There are MANY more but I'm tired of copying and paste them. D:

Thank You so far by the way, appreciated 'cheers' The System Idle Process indicates there are no more runnable threads for the CPU. It sticks up at highest usage, because it is considered "ready". It goes down automatically when new threads are created. It does not matter how high or low the System Idle Process runs, because all that shows is that your system is at an idle state.

Let's check one more thing...

Please download TDSSKiller from here and save it to your Desktop.
  • Doubleclick TDSSKiller.exe to run the tool
  • Click the Start Scan button
  • After the scan has finished, click the Close button
  • Click the Report button and copy/paste the contents of it into your next reply
Note:It will also create a log in the C:\ directory.So in other words, you are saying my computer was always in an idle state even though I run a program which needs RAM, CPU, Memory to be used and instead of working on the current program, it keeps itself as idle. Is that correct ? Because now you see it's not like 50-50 CPU for Sys Idle and the program I'm running anymore. The System Idle Process hogs 99% CPU even though I'm running a huge games or program, it doesn't go down that's my problem.

And here are the logs no threat found

00:16:16.0687 1280   TDSS rootkit removing tool 2.6.13.0 Oct 25 2011 13:56:21
00:16:17.0500 1280   ============================================================
00:16:17.0500 1280   Current date / time: 2011/10/27 00:16:17.0500
00:16:17.0500 1280   SystemInfo:
00:16:17.0500 1280   
00:16:17.0500 1280   OS Version: 5.1.2600 ServicePack: 3.0
00:16:17.0500 1280   Product type: Workstation
00:16:17.0500 1280   ComputerName: LARCTH
00:16:17.0500 1280   UserName: Nookia
00:16:17.0500 1280   Windows directory: C:\WINXP
00:16:17.0500 1280   System windows directory: C:\WINXP
00:16:17.0500 1280   Processor architecture: Intel x86
00:16:17.0500 1280   Number of processors: 2
00:16:17.0500 1280   Page size: 0x1000
00:16:17.0500 1280   Boot type: Normal boot
00:16:17.0500 1280   ============================================================
00:16:18.0484 1280   Initialize success
00:16:33.0609 0852   ============================================================
00:16:33.0609 0852   Scan started
00:16:33.0609 0852   Mode: Manual;
00:16:33.0609 0852   ============================================================
00:16:34.0671 0852   1394hub - ok
00:16:34.0687 0852   Abiosdsk - ok
00:16:34.0687 0852   abp480n5 - ok
00:16:34.0718 0852   ACPI            (8fd99680a539792a30e97944fdaecf17) C:\WINXP\system32\DRIVERS\ACPI.sys
00:16:34.0718 0852   ACPI - ok
00:16:34.0750 0852   ACPIEC          (9859c0f6936e723e4892d7141b1327d5) C:\WINXP\system32\drivers\ACPIEC.sys
00:16:34.0765 0852   ACPIEC - ok
00:16:34.0765 0852   adpu160m - ok
00:16:34.0796 0852   aec             (8bed39e3c35d6a489438b8141717a557) C:\WINXP\system32\drivers\aec.sys
00:16:34.0796 0852   aec - ok
00:16:34.0812 0852   AFD             (4d43e74f2a1239d53929b82600f1971c) C:\WINXP\System32\drivers\afd.sys
00:16:34.0812 0852   AFD - ok
00:16:34.0828 0852   Aha154x - ok
00:16:34.0828 0852   aic78u2 - ok
00:16:34.0843 0852   aic78xx - ok
00:16:34.0843 0852   AliIde - ok
00:16:34.0906 0852   Ambfilt         (f6af59d6eee5e1c304f7f73706ad11d8) C:\WINXP\system32\drivers\Ambfilt.sys
00:16:34.0906 0852   Ambfilt - ok
00:16:34.0921 0852   amsint - ok
00:16:34.0921 0852   asc - ok
00:16:34.0937 0852   asc3350p - ok
00:16:34.0937 0852   asc3550 - ok
00:16:34.0953 0852   AsIO            (2b4e66fac6503494a2c6f32bb6ab3826) C:\WINXP\system32\drivers\AsIO.sys
00:16:34.0953 0852   AsIO - ok
00:16:35.0000 0852   AsyncMac        (b153affac761e7f5fcfa822b9c4e97bc) C:\WINXP\system32\DRIVERS\asyncmac.sys
00:16:35.0000 0852   AsyncMac - ok
00:16:35.0015 0852   atapi           (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINXP\system32\DRIVERS\atapi.sys
00:16:35.0015 0852   atapi - ok
00:16:35.0015 0852   Atdisk - ok
00:16:35.0046 0852   Atmarpc         (9916c1225104ba14794209cfa8012159) C:\WINXP\system32\DRIVERS\atmarpc.sys
00:16:35.0046 0852   Atmarpc - ok
00:16:35.0078 0852   audstub         (d9f724aa26c010a217c97606b160ed68) C:\WINXP\system32\DRIVERS\audstub.sys
00:16:35.0078 0852   audstub - ok
00:16:35.0109 0852   Beep            (da1f27d85e0d1525f6621372e7b685e9) C:\WINXP\system32\drivers\Beep.sys
00:16:35.0109 0852   Beep - ok
00:16:35.0140 0852   BrScnUsb        (92a964547b96d697e5e9ed43b4297f5a) C:\WINXP\system32\DRIVERS\BrScnUsb.sys
00:16:35.0140 0852   BrScnUsb - ok
00:16:35.0218 0852   catchme - ok
00:16:35.0250 0852   cbidf2k         (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINXP\system32\drivers\cbidf2k.sys
00:16:35.0250 0852   cbidf2k - ok
00:16:35.0265 0852   cd20xrnt - ok
00:16:35.0265 0852   Cdaudio         (c1b486a7658353d33a10cc15211a873b) C:\WINXP\system32\drivers\Cdaudio.sys
00:16:35.0265 0852   Cdaudio - ok
00:16:35.0312 0852   Cdfs            (c885b02847f5d2fd45a24e219ed93b32) C:\WINXP\system32\drivers\Cdfs.sys
00:16:35.0312 0852   Cdfs - ok
00:16:35.0359 0852   Cdrom           (1f4260cc5b42272d71f79e570a27a4fe) C:\WINXP\system32\DRIVERS\cdrom.sys
00:16:35.0359 0852   Cdrom - ok
00:16:35.0390 0852   Changer - ok
00:16:35.0390 0852   CmdIde - ok
00:16:35.0406 0852   Cpqarray - ok
00:16:35.0437 0852   cpuz135         (c2eb4539a4f6ab6edd01bdc191619975) C:\WINXP\system32\drivers\cpuz135_x32.sys
00:16:35.0437 0852   cpuz135 - ok
00:16:35.0437 0852   dac2w2k - ok
00:16:35.0453 0852   dac960nt - ok
00:16:35.0453 0852   Disk            (044452051f3e02e7963599fc8f4f3e25) C:\WINXP\system32\DRIVERS\disk.sys
00:16:35.0453 0852   Disk - ok
00:16:35.0515 0852   dmboot          (d992fe1274bde0f84ad826acae022a41) C:\WINXP\system32\drivers\dmboot.sys
00:16:35.0515 0852   dmboot - ok
00:16:35.0515 0852   dmio            (7c824cf7bbde77d95c08005717a95f6f) C:\WINXP\system32\drivers\dmio.sys
00:16:35.0515 0852   dmio - ok
00:16:35.0546 0852   dmload          (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINXP\system32\drivers\dmload.sys
00:16:35.0546 0852   dmload - ok
00:16:35.0578 0852   DMusic          (8a208dfcf89792a484e76c40e5f50b45) C:\WINXP\system32\drivers\DMusic.sys
00:16:35.0578 0852   DMusic - ok
00:16:35.0593 0852   dpti2o - ok
00:16:35.0593 0852   drmkaud         (8f5fcff8e8848afac920905fbd9d33c8) C:\WINXP\system32\drivers\drmkaud.sys
00:16:35.0593 0852   drmkaud - ok
00:16:35.0640 0852   dtsoftbus01     (555e54ac2f601a8821cef58961653991) C:\WINXP\system32\DRIVERS\dtsoftbus01.sys
00:16:35.0640 0852   dtsoftbus01 - ok
00:16:35.0781 0852   dump_wmimmc - ok
00:16:35.0781 0852   EagleXNt - ok
00:16:35.0843 0852   Fastfat         (38d332a6d56af32635675f132548343e) C:\WINXP\system32\drivers\Fastfat.sys
00:16:35.0843 0852   Fastfat - ok
00:16:35.0859 0852   Fdc             (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINXP\system32\drivers\Fdc.sys
00:16:35.0859 0852   Fdc - ok
00:16:35.0875 0852   FIPS            (d45926117eb9fa946a6af572fbe1caa3) C:\WINXP\system32\drivers\Fips.sys
00:16:35.0890 0852   Fips - ok
00:16:35.0890 0852   Flpydisk        (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINXP\system32\drivers\Flpydisk.sys
00:16:35.0890 0852   Flpydisk - ok
00:16:35.0921 0852   FltMgr          (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINXP\system32\DRIVERS\fltMgr.sys
00:16:35.0921 0852   FltMgr - ok
00:16:35.0953 0852   Fs_Rec          (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINXP\system32\drivers\Fs_Rec.sys
00:16:35.0953 0852   Fs_Rec - ok
00:16:35.0953 0852   Ftdisk          (6ac26732762483366c3969c9e4d2259d) C:\WINXP\system32\DRIVERS\ftdisk.sys
00:16:35.0953 0852   Ftdisk - ok
00:16:35.0984 0852   GEARAspiWDM     (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINXP\system32\DRIVERS\GEARAspiWDM.sys
00:16:35.0984 0852   GEARAspiWDM - ok
00:16:36.0015 0852   GGSAFERDriver - ok
00:16:36.0062 0852   Gpc             (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINXP\system32\DRIVERS\msgpc.sys
00:16:36.0062 0852   Gpc - ok
00:16:36.0093 0852   HDAudBus        (573c7d0a32852b48f3058cfd8026f511) C:\WINXP\system32\DRIVERS\HDAudBus.sys
00:16:36.0093 0852   HDAudBus - ok
00:16:36.0140 0852   hidusb          (ccf82c5ec8a7326c3066de870c06daf1) C:\WINXP\system32\DRIVERS\hidusb.sys
00:16:36.0140 0852   hidusb - ok
00:16:36.0156 0852   hpn - ok
00:16:36.0187 0852   HTTP            (937031c085718c1c04a9c0864625ec6b) C:\WINXP\system32\Drivers\HTTP.sys
00:16:36.0187 0852   HTTP - ok
00:16:36.0187 0852   i2omgmt - ok
00:16:36.0203 0852   i2omp - ok
00:16:36.0218 0852   i8042prt        (4a0b06aa8943c1e332520f7440c0aa30) C:\WINXP\system32\DRIVERS\i8042prt.sys
00:16:36.0218 0852   i8042prt - ok
00:16:36.0234 0852   Imapi           (083a052659f5310dd8b6a6cb05edcf8e) C:\WINXP\system32\DRIVERS\imapi.sys
00:16:36.0234 0852   Imapi - ok
00:16:36.0234 0852   ini910u - ok
00:16:36.0328 0852   IntcAzAudAddService (fb4293b1eab313c28d4a1b8db61aca72) C:\WINXP\system32\drivers\RtkHDAud.sys
00:16:36.0359 0852   IntcAzAudAddService - ok
00:16:36.0437 0852   IntelIde        (b5466a9250342a7aa0cd1fba13420678) C:\WINXP\system32\DRIVERS\intelide.sys
00:16:36.0437 0852   IntelIde - ok
00:16:36.0453 0852   intelppm        (8c953733d8f36eb2133f5bb58808b66b) C:\WINXP\system32\DRIVERS\intelppm.sys
00:16:36.0453 0852   intelppm - ok
00:16:36.0468 0852   Ip6Fw           (3bb22519a194418d5fec05d800a19ad0) C:\WINXP\system32\DRIVERS\Ip6Fw.sys
00:16:36.0468 0852   Ip6Fw - ok
00:16:36.0500 0852   IpFilterDriver  (731f22ba402ee4b62748adaf6363c182) C:\WINXP\system32\DRIVERS\ipfltdrv.sys
00:16:36.0500 0852   IpFilterDriver - ok
00:16:36.0500 0852   IpInIp          (b87ab476dcf76e72010632b5550955f5) C:\WINXP\system32\DRIVERS\ipinip.sys
00:16:36.0500 0852   IpInIp - ok
00:16:36.0515 0852   IpNat           (cc748ea12c6effde940ee98098bf96bb) C:\WINXP\system32\DRIVERS\ipnat.sys
00:16:36.0515 0852   IpNat - ok
00:16:36.0531 0852   IPSec           (23c74d75e36e7158768dd63d92789a91) C:\WINXP\system32\DRIVERS\ipsec.sys
00:16:36.0531 0852   IPSec - ok
00:16:36.0546 0852   IRENUM          (c93c9ff7b04d772627a3646d89f7bf89) C:\WINXP\system32\DRIVERS\irenum.sys
00:16:36.0546 0852   IRENUM - ok
00:16:36.0562 0852   isapnp          (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINXP\system32\DRIVERS\isapnp.sys
00:16:36.0562 0852   isapnp - ok
00:16:36.0593 0852   Kbdclass        (463c1ec80cd17420a542b7f36a36f128) C:\WINXP\system32\DRIVERS\kbdclass.sys
00:16:36.0593 0852   Kbdclass - ok
00:16:36.0625 0852   kmixer          (692bcf44383d056aed41b045a323d378) C:\WINXP\system32\drivers\kmixer.sys
00:16:36.0625 0852   kmixer - ok
00:16:36.0640 0852   KSecDD          (c6ebf1d6ad71df30db49b8d3287e1368) C:\WINXP\system32\drivers\KSecDD.sys
00:16:36.0640 0852   KSecDD - ok
00:16:36.0656 0852   L1e             (fa46f5d09edf93e0c71fe6500fe3f4ae) C:\WINXP\system32\DRIVERS\l1e51x86.sys
00:16:36.0656 0852   L1e - ok
00:16:36.0656 0852   lbrtfdc - ok
00:16:36.0671 0852   MBAMProtector   (69a6268d7f81e53d568ab4e7e991caf3) C:\WINXP\system32\drivers\mbam.sys
00:16:36.0671 0852   MBAMProtector - ok
00:16:36.0687 0852   MBAMSwissArmy - ok
00:16:36.0703 0852   mnmdd           (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINXP\system32\drivers\mnmdd.sys
00:16:36.0703 0852   mnmdd - ok
00:16:36.0718 0852   Modem           (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINXP\system32\drivers\Modem.sys
00:16:36.0718 0852   Modem - ok
00:16:36.0750 0852   Monfilt         (9fa7207d1b1adead88ae8eed9cdbbaa5) C:\WINXP\system32\drivers\Monfilt.sys
00:16:36.0765 0852   Monfilt - ok
00:16:36.0796 0852   Mouclass        (35c9e97194c8cfb8430125f8dbc34d04) C:\WINXP\system32\DRIVERS\mouclass.sys
00:16:36.0796 0852   Mouclass - ok
00:16:36.0828 0852   mouhid          (b1c303e17fb9d46e87a98e4ba6769685) C:\WINXP\system32\DRIVERS\mouhid.sys
00:16:36.0828 0852   mouhid - ok
00:16:36.0843 0852   MountMgr        (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINXP\system32\drivers\MountMgr.sys
00:16:36.0843 0852   MountMgr - ok
00:16:36.0859 0852   mraid35x - ok
00:16:36.0859 0852   MRxDAV          (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINXP\system32\DRIVERS\mrxdav.sys
00:16:36.0859 0852   MRxDAV - ok
00:16:36.0875 0852   MRxSmb          (d09b9f0b9960dd41e73127b7814c115f) C:\WINXP\system32\DRIVERS\mrxsmb.sys
00:16:36.0875 0852   MRxSmb - ok
00:16:36.0890 0852   Msfs            (c941ea2454ba8350021d774daf0f1027) C:\WINXP\system32\drivers\Msfs.sys
00:16:36.0890 0852   Msfs - ok
00:16:36.0921 0852   MSKSSRV         (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINXP\system32\drivers\MSKSSRV.sys
00:16:36.0921 0852   MSKSSRV - ok
00:16:36.0953 0852   MSPCLOCK        (325bb26842fc7ccc1fcce2c457317f3e) C:\WINXP\system32\drivers\MSPCLOCK.sys
00:16:36.0953 0852   MSPCLOCK - ok
00:16:36.0968 0852   MSPQM           (bad59648ba099da4a17680b39730cb3d) C:\WINXP\system32\drivers\MSPQM.sys
00:16:36.0968 0852   MSPQM - ok
00:16:37.0015 0852   mssmbios        (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINXP\system32\DRIVERS\mssmbios.sys
00:16:37.0015 0852   mssmbios - ok
00:16:37.0031 0852   MTsensor        (d48659bb24c48345d926ecb45c1ebdf5) C:\WINXP\system32\DRIVERS\ASACPI.sys
00:16:37.0031 0852   MTsensor - ok
00:16:37.0046 0852   Mup             (2f625d11385b1a94360bfc70aaefdee1) C:\WINXP\system32\drivers\Mup.sys
00:16:37.0046 0852   Mup - ok
00:16:37.0046 0852   mv61xx          (a4a61d30097c8adaad648ebe204d61ef) C:\WINXP\system32\DRIVERS\mv61xx.sys
00:16:37.0046 0852   mv61xx - ok
00:16:37.0078 0852   mv61xxmm        (4578f2d91309bc360b4f67c8a513bc77) C:\WINXP\system32\drivers\mv61xxmm.sys
00:16:37.0078 0852   mv61xxmm - ok
00:16:37.0078 0852   mv64xxmm        (6090786daa545a3ec7d34a46a8cd1661) C:\WINXP\system32\drivers\mv64xxmm.sys
00:16:37.0078 0852   mv64xxmm - ok
00:16:37.0093 0852   mvxxmm          (f3376efec7d3fd00f577067ad2a0b194) C:\WINXP\system32\drivers\mvxxmm.sys
00:16:37.0093 0852   mvxxmm - ok
00:16:37.0093 0852   NDIS            (1df7f42665c94b825322fae71721130d) C:\WINXP\system32\drivers\NDIS.sys
00:16:37.0109 0852   NDIS - ok
00:16:37.0109 0852   NdisTapi        (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINXP\system32\DRIVERS\ndistapi.sys
00:16:37.0109 0852   NdisTapi - ok
00:16:37.0125 0852   Ndisuio         (f927a4434c5028758a842943ef1a3849) C:\WINXP\system32\DRIVERS\ndisuio.sys
00:16:37.0125 0852   Ndisuio - ok
00:16:37.0140 0852   NdisWan         (edc1531a49c80614b2cfda43ca8659ab) C:\WINXP\system32\DRIVERS\ndiswan.sys
00:16:37.0140 0852   NdisWan - ok
00:16:37.0140 0852   NDProxy         (816460bd4b4acd27937d1d0813e2e9e9) C:\WINXP\system32\drivers\NDProxy.sys
00:16:37.0140 0852   NDProxy - ok
00:16:37.0156 0852   NetBIOS         (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINXP\system32\DRIVERS\netbios.sys
00:16:37.0156 0852   NetBIOS - ok
00:16:37.0171 0852   NetBT           (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINXP\system32\DRIVERS\netbt.sys
00:16:37.0171 0852   NetBT - ok
00:16:37.0187 0852   Npfs            (3182d64ae053d6fb034f44b6def8034a) C:\WINXP\system32\drivers\Npfs.sys
00:16:37.0187 0852   Npfs - ok
00:16:37.0218 0852   NPPTNT2         (9131fe60adfab595c8da53ad6a06aa31) C:\WINXP\system32\npptNT2.sys
00:16:37.0234 0852   NPPTNT2 - ok
00:16:37.0250 0852   Ntfs            (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINXP\system32\drivers\Ntfs.sys
00:16:37.0265 0852   Ntfs - ok
00:16:37.0296 0852   Null            (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINXP\system32\drivers\Null.sys
00:16:37.0296 0852   Null - ok
00:16:37.0484 0852   nv              (b9b1bb146eb9a83dcf0f5635b09d3d43) C:\WINXP\system32\DRIVERS\nv4_mini.sys
00:16:37.0531 0852   nv - ok
00:16:37.0546 0852   NwlnkFlt        (b305f3fad35083837ef46a0bbce2fc57) C:\WINXP\system32\DRIVERS\nwlnkflt.sys
00:16:37.0546 0852   NwlnkFlt - ok
00:16:37.0562 0852   NwlnkFwd        (c99b3415198d1aab7227f2c88fd664b9) C:\WINXP\system32\DRIVERS\nwlnkfwd.sys
00:16:37.0562 0852   NwlnkFwd - ok
00:16:37.0578 0852   Parport         (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINXP\system32\drivers\Parport.sys
00:16:37.0578 0852   Parport - ok
00:16:37.0609 0852   PartMgr         (beb3ba25197665d82ec7065b724171c6) C:\WINXP\system32\drivers\PartMgr.sys
00:16:37.0609 0852   PartMgr - ok
00:16:37.0640 0852   ParVdm          (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINXP\system32\drivers\ParVdm.sys
00:16:37.0640 0852   ParVdm - ok
00:16:37.0656 0852   PCI             (a219903ccf74233761d92bef471a07b1) C:\WINXP\system32\DRIVERS\pci.sys
00:16:37.0656 0852   PCI - ok
00:16:37.0656 0852   PCIDump - ok
00:16:37.0671 0852   PCIIde          (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINXP\system32\drivers\PCIIde.sys
00:16:37.0671 0852   PCIIde - ok
00:16:37.0687 0852   Pcmcia          (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINXP\system32\drivers\Pcmcia.sys
00:16:37.0687 0852   Pcmcia - ok
00:16:37.0703 0852   PDCOMP - ok
00:16:37.0703 0852   PDFRAME - ok
00:16:37.0703 0852   PDRELI - ok
00:16:37.0718 0852   PDRFRAME - ok
00:16:37.0718 0852   perc2 - ok
00:16:37.0734 0852   perc2hib - ok
00:16:37.0750 0852   PptpMiniport    (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINXP\system32\DRIVERS\raspptp.sys
00:16:37.0750 0852   PptpMiniport - ok
00:16:37.0765 0852   PSched          (09298ec810b07e5d582cb3a3f9255424) C:\WINXP\system32\DRIVERS\psched.sys
00:16:37.0765 0852   PSched - ok
00:16:37.0765 0852   Ptilink         (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINXP\system32\DRIVERS\ptilink.sys
00:16:37.0765 0852   Ptilink - ok
00:16:37.0796 0852   PxHelp20        (40fedd328f98245ad201cf5f9f311724) C:\WINXP\system32\Drivers\PxHelp20.sys
00:16:37.0796 0852   PxHelp20 - ok
00:16:37.0796 0852   ql1080 - ok
00:16:37.0812 0852   Ql10wnt - ok
00:16:37.0812 0852   ql12160 - ok
00:16:37.0812 0852   ql1240 - ok
00:16:37.0828 0852   ql1280 - ok
00:16:37.0843 0852   RasAcd          (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINXP\system32\DRIVERS\rasacd.sys
00:16:37.0843 0852   RasAcd - ok
00:16:37.0859 0852   Rasl2tp         (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINXP\system32\DRIVERS\rasl2tp.sys
00:16:37.0859 0852   Rasl2tp - ok
00:16:37.0875 0852   RasPppoe        (5bc962f2654137c9909c3d4603587dee) C:\WINXP\system32\DRIVERS\raspppoe.sys
00:16:37.0875 0852   RasPppoe - ok
00:16:37.0875 0852   Raspti          (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINXP\system32\DRIVERS\raspti.sys
00:16:37.0875 0852   Raspti - ok
00:16:37.0890 0852   Rdbss           (7ad224ad1a1437fe28d89cf22b17780a) C:\WINXP\system32\DRIVERS\rdbss.sys
00:16:37.0890 0852   Rdbss - ok
00:16:37.0906 0852   RDPCDD          (4912d5b403614ce99c28420f75353332) C:\WINXP\system32\DRIVERS\RDPCDD.sys
00:16:37.0906 0852   RDPCDD - ok
00:16:37.0937 0852   rdpdr           (15cabd0f7c00c47c70124907916af3f1) C:\WINXP\system32\DRIVERS\rdpdr.sys
00:16:37.0937 0852   rdpdr - ok
00:16:37.0968 0852   RDPWD           (6728e45b66f93c08f11de2e316fc70dd) C:\WINXP\system32\drivers\RDPWD.sys
00:16:37.0968 0852   RDPWD - ok
00:16:38.0000 0852   redbook         (f828dd7e1419b6653894a8f97a0094c5) C:\WINXP\system32\DRIVERS\redbook.sys
00:16:38.0000 0852   redbook - ok
00:16:38.0046 0852   Secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\WINXP\system32\DRIVERS\secdrv.sys
00:16:38.0046 0852   Secdrv - ok
00:16:38.0046 0852   serenum         (0f29512ccd6bead730039fb4bd2c85ce) C:\WINXP\system32\DRIVERS\serenum.sys
00:16:38.0046 0852   serenum - ok
00:16:38.0062 0852   Serial          (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINXP\system32\DRIVERS\serial.sys
00:16:38.0062 0852   Serial - ok
00:16:38.0093 0852   Sfloppy         (8e6b8c671615d126fdc553d1e2de5562) C:\WINXP\system32\drivers\Sfloppy.sys
00:16:38.0093 0852   Sfloppy - ok
00:16:38.0093 0852   Simbad - ok
00:16:38.0125 0852   SONYPVU1        (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINXP\system32\DRIVERS\SONYPVU1.SYS
00:16:38.0125 0852   SONYPVU1 - ok
00:16:38.0125 0852   Sparrow - ok
00:16:38.0156 0852   splitter        (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINXP\system32\drivers\splitter.sys
00:16:38.0156 0852   splitter - ok
00:16:38.0203 0852   sr              (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINXP\system32\DRIVERS\sr.sys
00:16:38.0203 0852   sr - ok
00:16:38.0218 0852   Srv             (70cd8b8dd2a680b128617c19eb0ab94f) C:\WINXP\system32\DRIVERS\srv.sys
00:16:38.0218 0852   Srv - ok
00:16:38.0250 0852   swenum          (3941d127aef12e93addf6fe6ee027e0f) C:\WINXP\system32\DRIVERS\swenum.sys
00:16:38.0250 0852   swenum - ok
00:16:38.0265 0852   swmidi          (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINXP\system32\drivers\swmidi.sys
00:16:38.0265 0852   swmidi - ok
00:16:38.0265 0852   symc810 - ok
00:16:38.0281 0852   symc8xx - ok
00:16:38.0281 0852   sym_hi - ok
00:16:38.0281 0852   sym_u3 - ok
00:16:38.0312 0852   sysaudio        (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINXP\system32\drivers\sysaudio.sys
00:16:38.0312 0852   sysaudio - ok
00:16:38.0375 0852   Tcpip           (a5bc817bb84dcb9e71719ff868144124) C:\WINXP\system32\DRIVERS\tcpip.sys
00:16:38.0375 0852   Tcpip - ok
00:16:38.0390 0852   TDPIPE          (6471a66807f5e104e4885f5b67349397) C:\WINXP\system32\drivers\TDPIPE.sys
00:16:38.0390 0852   TDPIPE - ok
00:16:38.0437 0852   TDTCP           (c56b6d0402371cf3700eb322ef3aaf61) C:\WINXP\system32\drivers\TDTCP.sys
00:16:38.0437 0852   TDTCP - ok
00:16:38.0453 0852   TermDD          (88155247177638048422893737429d9e) C:\WINXP\system32\DRIVERS\termdd.sys
00:16:38.0453 0852   TermDD - ok
00:16:38.0468 0852   TosIde - ok
00:16:38.0500 0852   Udfs            (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINXP\system32\drivers\Udfs.sys
00:16:38.0500 0852   Udfs - ok
00:16:38.0500 0852   ultra - ok
00:16:38.0515 0852   Update          (402ddc88356b1bac0ee3dd1580c76a31) C:\WINXP\system32\DRIVERS\update.sys
00:16:38.0515 0852   Update - ok
00:16:38.0562 0852   USBAAPL         (83cafcb53201bbac04d822f32438e244) C:\WINXP\system32\Drivers\usbaapl.sys
00:16:38.0562 0852   USBAAPL - ok
00:16:38.0593 0852   usbccgp         (173f317ce0db8e21322e71b7e60a27e8) C:\WINXP\system32\DRIVERS\usbccgp.sys
00:16:38.0593 0852   usbccgp - ok
00:16:38.0609 0852   usbehci         (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINXP\system32\DRIVERS\usbehci.sys
00:16:38.0609 0852   usbehci - ok
00:16:38.0640 0852   usbhub          (1ab3cdde553b6e064d2e754efe20285c) C:\WINXP\system32\DRIVERS\usbhub.sys
00:16:38.0640 0852   usbhub - ok
00:16:38.0640 0852   usbprint        (a717c8721046828520c9edf31288fc00) C:\WINXP\system32\DRIVERS\usbprint.sys
00:16:38.0640 0852   usbprint - ok
00:16:38.0656 0852   usbscan         (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINXP\system32\DRIVERS\usbscan.sys
00:16:38.0656 0852   usbscan - ok
00:16:38.0671 0852   USBSTOR         (a32426d9b14a089eaa1d922e0c5801a9) C:\WINXP\system32\DRIVERS\USBSTOR.SYS
00:16:38.0671 0852   USBSTOR - ok
00:16:38.0671 0852   usbuhci         (26496f9dee2d787fc3e61ad54821ffe6) C:\WINXP\system32\DRIVERS\usbuhci.sys
00:16:38.0671 0852   usbuhci - ok
00:16:38.0703 0852   VgaSave         (0d3a8fafceacd8b7625cd549757a7df1) C:\WINXP\System32\drivers\vga.sys
00:16:38.0703 0852   VgaSave - ok
00:16:38.0703 0852   ViaIde - ok
00:16:38.0718 0852   VolSnap         (4c8fcb5cc53aab716d810740fe59d025) C:\WINXP\system32\drivers\VolSnap.sys
00:16:38.0718 0852   VolSnap - ok
00:16:38.0734 0852   Wanarp          (e20b95baedb550f32dd489265c1da1f6) C:\WINXP\system32\DRIVERS\wanarp.sys
00:16:38.0734 0852   Wanarp - ok
00:16:38.0734 0852   WDICA - ok
00:16:38.0765 0852   wdmaud          (6768acf64b18196494413695f0c3a00f) C:\WINXP\system32\drivers\wdmaud.sys
00:16:38.0765 0852   wdmaud - ok
00:16:38.0812 0852   WudfPf          (f15feafffbb3644ccc80c5da584e6311) C:\WINXP\system32\DRIVERS\WudfPf.sys
00:16:38.0812 0852   WudfPf - ok
00:16:38.0828 0852   WudfRd          (28b524262bce6de1f7ef9f510ba3985b) C:\WINXP\system32\DRIVERS\wudfrd.sys
00:16:38.0828 0852   WudfRd - ok
00:16:38.0828 0852   XDva385 - ok
00:16:38.0843 0852   XDva387 - ok
00:16:38.0859 0852   MBR (0x1B8)     (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
00:16:38.0921 0852   \Device\Harddisk0\DR0 - ok
00:16:38.0921 0852   Boot (0x1200)   (079d83d72b1c92bdb0051ab3dca0f6b6) \Device\Harddisk0\DR0\Partition0
00:16:38.0921 0852   \Device\Harddisk0\DR0\Partition0 - ok
00:16:38.0937 0852   Boot (0x1200)   (1596dca7a70b9a6c10e78b2c1e299963) \Device\Harddisk0\DR0\Partition1
00:16:38.0937 0852   \Device\Harddisk0\DR0\Partition1 - ok
00:16:38.0937 0852   ============================================================
00:16:38.0937 0852   Scan finished
00:16:38.0937 0852   ============================================================
00:16:38.0953 1100   Detected object count: 0
00:16:38.0953 1100   Actual detected object count: 0
For example I'm currently running Civilization V

The System idle Process hogs half of the CPU Usage, which shouldn't and never happened before.

Img - http://upic.me/i/j2/cem51.jpg

What strange is that the lag will come only when I'm actually playing the game, you know like when there are movements and graphic ?

But when I'm on the main menu screen of the games, I just don't feel the lag.

While the System Idle Process is hogging the CPU at the same amount in both situation. weird ehh ? :\

This problem goes to all of my game but strangely again it doesn't go with software like Photoshop CS5. It seems to work fine for me even though the System Idle is hogging over half of the CPU.

Could this be some kind of graphic card problem instead ?In that screenshot, it clearly shows that 50% of the CPU is being used by Civilization V, and 50% is used by System Idle Process. The System Idle Process does not hog the CPU by any means. That is showing that 50% of the CPU is free to use.

Start other programs that need to thread objects in the CPU and see if the Idle process goes down. It most likely will.

That processor is lucky enough to even run Civilization V. IMO, that is not good enough.

Civ. V needs either:

A. Quad core processor at 1.8 GHz (required by the game makers)
B. Dual core processor at 4.0 GHz (my own recommendation)

The Minimum requirements on a game is specifically needed for the program to simply install and run at reduced functionality. However, the recommended requirements on a game is what the game is supposed to run at, in full functionality.

If you're not running that game in a high-performance environment...expect trouble!FYI: I think you are seeing only 50% CPU usage because that program is not multithreaded (uses multiple cores).I have tried running Civilization V, Warcraft III, Starcraft all at the same time and during gameplay. The System Idle Process still keeps using 50-50 CPU when it should being used for either Starcraft or Warcraft III, but no luck.

While War3 and Starcraft is running and uses some Memory, The CPU still goes for System Idle Process instead.
http://upic.me/i/63/56wtf.jpg

List by Memory Usage
http://upic.me/i/7k/r0wth.jpg

My Video settings of Civilization V (Default Setting)
http://upic.me/i/m1/87omg.jpg

I have used this setting since I installed the game and it worked just fine (smooth), until now its lag is killing me bad and if no solution could be find, I guess I will have to format my C and see if that works...

If not the System Idle Process, what could be any other ? Because you see when game lags I just find out what's going on from Task Manager first and this is what I got.

Could it be some kind of machine overheating ? I don't know now. ;/

Ps. It happens to Warcraft III also, not only the Civilization V, if you are trying to say my spec is too low for it. D:
and is there anyway to force my computer to uses 99% of CPU on something and don't let it keep in idle state ? Thx alot though so far
Did you notice in this screenshot that Warcraft 3 was not using the CPU: http://upic.me/i/63/56wtf.jpg ??

Explorer.exe is using 1%, System Idle at 49, and Civ V using 50. With 51% of the processor being used for Explorer and Civ V, the other 49% is free to use, occupied by the System Idle Process.

You don't seem to understand this computing method. Either A: you don't believe my expertise, or B: you seriously think something is wrong with the Idle task in the Task Manager.

Allow me to quote for you the explanation of the System Idle process so you kindly understand here:

Quote
...the System Idle Process contains one or more kernel threads which run when no other runnable thread can be scheduled on a CPU. For example, there may be no runnable thread in the system, or all runnable threads are already running on a different CPU. In a multiprocessor system, there is one idle thread associated with each CPU.

The CPU time consumed by the System Idle Process is commonly of interest to end users, as it is a measure of the CPU utilization in their system which is easily accessible through Windows Task Manager. Understanding its function can alleviate concern: the System Idle Process and its threads eliminate the possibility of the scheduler having to deal with the exception to a rule. Its threads are scheduled at a lower priority than any other threads can reach; if no ordinary thread is scheduled to run on a free CPU, then and only then does the scheduler select that CPU's System Idle Process thread for execution. In other words, although it may appear to users that their CPU is being monopolized by the idle process, it is merely acting as a sort of placeholder during "free time" (therefore, whenever the idle process appears to be consuming most of the CPU, it is proof that no other process wants that CPU time).

Read articles for backupo references, please: http://en.wikipedia.org/wiki/System_Idle_Process and http://en.wikipedia.org/wiki/Idle_task
394.

Solve : Bad Image: WIKI.DLL?

Answer» HI DAVE,

Sorry this took so long.  I have completed the steps you suggested and I believe that I am through with the malware problem.  I still have to reinstall the paid-for AVG and activate its firewall (though that evidently didn't help me in the first place?)

I have had several instances where the laptop has not shut down correctly.  I select start\turn off computer\turn off and I get the screen that says that windows is shutting down but then it stalls there.  I wait for 5 or 10 minutes and then just power off the machine.  It doesn't ALWAYS happen but I'd say about every third or fourth time so far.

Thanks for your help.
Mike
I don't believe that the shut-down problem is caused by any infections. If it PERSISTS, start a NEW thread in the proper forum. I will lock this thread.If you need it re-opened, please send me a pm.
395.

Solve : Any effective solution to thwart the 'Malvertising'??

Answer»

Hello There!

Global Malware trend do suggest that 'Malvertising'-(Malicious adverts hosted on a legitimate site), is on rise. Back-to-back incidents have taken place in the UK with first being the London Stock exchange website found hosting a booby-trapped adverts, then Music streaming service- SPOTIFY & now an another Govt. aided website inadvertently hosting a link that re-directed the users to a FAKE Antivirus website, promising fix against the Bogus issues!

The very first instance also suggested that a visitor to the LSE website didn't  EVEN need a click on the affected advert, but mere its loading prompted the users to apply fixes against the bogus issues found on their machines!?

Are the current Anti-malware solutions capable of averting such attacks? I can only think of using Firefox bolstered with EXTENSIONS like Ad-Block Plus & NoScript, as a only SOLUTION to prevent such a vicious breach?

Any Inputs....?

Make sure to check out the following REFERENCES:::

http://www.bbc.co.uk/news/technology-12597819

http://www.bbc.co.uk/news/technology-12891182

http://www.bbc.co.uk/news/technology-12904585

396.

Solve : Could use some help, might be infected but i'm not sure?

Answer»

I hope this will WORK.  I hit save to desktop but i don't know what happened cuz it's not there, so i took this log instead.  if you need the other one, tell me, and i'll rerun the scan.  Also I didn't remove anything with this scan, i just scanned it as suggested (hope that was the right thing to do).

[email protected] as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6425
# api_version=3.0.2
# EOSSerial=e3ebba6efebc6443b945eafc90d838a3
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-03-26 11:42:45
# local_time=2011-03-26 04:42:45 (-0800, Pacific Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 80689562 80689562 0 0
# compatibility_mode=3584 16777175 100 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=198688
# found=6
# cleaned=0
# scan_time=13495
C:\Documents and Settings\Candie\My Documents\Downloads\SetupPlaySushi(2).exe   a variant of Win32/Adware.Gamevance.AS application (unable to clean)   00000000000000000000000000000000   I
C:\Documents and Settings\Candie\My Documents\Downloads\SetupPlaySushi(3).exe   a variant of Win32/Adware.Gamevance.AS application (unable to clean)   00000000000000000000000000000000   I
C:\Documents and Settings\Candie\My Documents\Downloads\SetupPlaySushi.exe   a variant of Win32/Adware.Gamevance.AS application (unable to clean)   00000000000000000000000000000000   I
C:\Program Files\iWonEI\Installr\1.bin\jfEIPlug.dll   a variant of Win32/Toolbar.MyWebSearch application (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1088\A0089734.DLL   a variant of Win32/Toolbar.MyWebSearch application (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1088\A0089877.DLL   Win32/Toolbar.AskSBar application (unable to clean)   00000000000000000000000000000000   I
Hey Super Dave, i'm having a brain malfunction or something, way back when we started you told me to uninstall iwin games, which i did, but i just realized i didn't uninstall all the games the wife has downloaded to play.  Should i have done that or should i do it now, or will it matter.  Sorry for just catching this. Quote

Should i have done that or should i do it now, or will it matter.
No. It's just iWin games.

Please run ESET again and clean the infections and post the log.ok, thanks.  It may be a day before i can run the eset, but i'll GET there....here you go

C:\Documents and Settings\Candie\My Documents\Downloads\SetupPlaySushi(2).exe   a variant of Win32/Adware.Gamevance.AS application   cleaned by deleting - quarantined
C:\Documents and Settings\Candie\My Documents\Downloads\SetupPlaySushi(3).exe   a variant of Win32/Adware.Gamevance.AS application   cleaned by deleting - quarantined
C:\Documents and Settings\Candie\My Documents\Downloads\SetupPlaySushi.exe   a variant of Win32/Adware.Gamevance.AS application   cleaned by deleting - quarantined
C:\Program Files\iWonEI\Installr\1.bin\jfEIPlug.dll   a variant of Win32/Toolbar.MyWebSearch application   cleaned by deleting - quarantined
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1088\A0089734.DLL   a variant of Win32/Toolbar.MyWebSearch application   cleaned by deleting - quarantined
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1088\A0089877.DLL   Win32/Toolbar.AskSBar application   cleaned by deleting - quarantined
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1094\A0090774.dll   a variant of Win32/Toolbar.MyWebSearch application   cleaned by deleting - quarantined
Great. That looks good. If there are no other issues, it's time for some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System RESTORE.
************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
***********************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
**********************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable SHOPPING sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX CONTROLS are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Thanks Super Dave, i'll work on the clean up tonite when i got more time.  Should I also uninstall any of the other programs i used like ESET or SysRoot?  Also i need to delete the mcafee which was downloaded and installed , can i do that thru add/remove programs or is there something special i need to do?  And last question, regarding firewalls, i have norton internet security which has a firewall so do i need to install one?  Your note says to have only one firewall and i don't want to goof things up.  Thanks, for helping me out. Quote
Should I also uninstall any of the other programs i used like ESET or SysRoot?
Yes. Any tools we use can be uninstalled or deleted. You can keep SAS and MBAM, if you wish. Update them and run them on a regular basis.
Quote
Also i need to delete the mcafee which was downloaded and installed , can i do that thru add/remove programs or is there something special i need to do?
Yes. You should do through add/remove programs. If you have problems removing it, use the McAfee Removal Tool below.
McAfee Consumer Products Removal tool (MCPR.exe)

Quote
norton internet security which has a firewall so do i need to install one?
That's considered a third-party firewall.

Quote
Thanks, for helping me out.
You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
397.

Solve : Another Virus? Computer just reboots.?

Answer»

Hello and thank you for looking at my thread TODAY.

While I have been fixing my regular computer, my second computer has decided that it needs my attention as well.
Maybe it is feeling left out.... (I don't Know?)

This computer is a Celeron C.P.U.2 , 2.80 GHz , 1.48 Meg of Ram , running XP Professional SP 3 Version 2002.

My daughter has been using this just recently for her facebook postings. (because dad just has a great internet service and she lives close by).

I really suspect this facebook thing for this problem.

I have tried to do a "System Restore" but that had no impact.

The computer tries to start and gets mostly through the cycle of Start-up, but then EITHER loads with a distorted screen with lines and dots throughout and doesn't complete and locks up, or it cycles through to restart and scans the hard drive as if it has been shut down incorrectly.

I can start this one in "Safe Mode with Netword Support" only at the moment. The USB connections are not working either.
I have verified my Java and have the latest (24) update. Each of the Spyware programs have updated OK today before running the scans.(oops Malwarebytes needed an update).

I have rebooted after quarantining viruses detected and malware items and am able to get here to post, but if I REBOOT to normal it all goes back to fuzzy lines and cycling to reboot.

I have run SAS, HJT and Malwarebytes and here are the logs that they returned.

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6123  ( new version has 6211, see below)

Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702

30/03/2011 4:52:01 PM
mbam-log-2011-03-30 (16-52-01).txt

Scan type: Full scan (C:\|E:\|)
Objects scanned: 194073
Time elapsed: 16 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\documents and settings\administrator\my documents\downloads\cursormania.exe (PUP.FunWebProducts) -> Quarantined and deleted successfully.
 A second scan reports no infections.
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6211

Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702

30/03/2011 6:56:15 PM
mbam-log-2011-03-30 (18-56-15).txt

Scan type: Full scan (C:\|)
Objects scanned: 174854
Time elapsed: 7 minute(s), 20 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:21:47 PM, on 30/03/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.ninemsn.com.au
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFree.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFree.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
O3 - Toolbar: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFree.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Freecorder FLV Service] "C:\Program Files\Freecorder\FLVSrvc.exe" /run
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SUPERANTISPYWARE] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Start-up: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Start-up: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe

--
End of file - 7605 bytes


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 03/30/2011 at 05:47 PM

Application Version : 4.50.1002

Core Rules Database Version : 6708
Trace Rules Database Version: 4520

Scan type       : Complete Scan
Total Scan Time : 00:38:13

Memory items scanned      : 329
Memory threats detected   : 0
Registry items scanned    : 6513
Registry threats detected : 11
File items scanned        : 22509
File threats detected     : 90

Adware.Tracking Cookie
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][3].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][3].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][3].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][3].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][3].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected]com[2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   acvs.mediaonenetwork.net [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\8Z676SZW ]
   media.scanscout.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\8Z676SZW ]
   rmd.atdmt.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\8Z676SZW ]
   keywordelite.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\8Z676SZW ]
   www.pornhub.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\8Z676SZW ]
   cdn4.specificclick.net [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\8Z676SZW ]

Adware.MyWebSearch/FunWebProducts
   HKU\S-1-5-21-2052111302-261478967-1606980848-500\SOFTWARE\FunWebProducts
   HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
   HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid
   HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid32
   HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib
   HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib#Version
   HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
   HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid
   HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid32
   HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib
   HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib#Version

(I'm running out of computers to use SuperDave) At LEAST I still have the laptops.

Well, if you can spare the time to look through the logs and see if there is something (useful) you can suggest to help fix this computer, I would greatly appreciate the help.

Thank you ImnoGuru.


Hmmm ... Stranger things have happened but just not on a regular basis. This computer is now working fine.

The next time I booted up everything was back to normal? ??
Even the USB ports are working fine.
I didnt even get to reinstall any drivers.
Thanks for your input Tashnav.

(I still have a low level of trust for this Facebook thing though.)

398.

Solve : Wife's laptop WiFi will not stay connected to router. I think?

Answer»

My WIFE has a HP9000 laptop running Windows XP.   She is using WiFi connected to a Netgear wirelss  router  in my home network.   My base computer is a desktop running Windows 7 64 bitand is connected to the router via ethernet cable.   For a couple of years now this system has been working satisfactorily....but...    

PROBLEM:   When she clicks on internet explorer, the laptop connects to the internet and tries to  bring up Yahoo or Google home PAGE  a message appears:   "Internet explorer has ENCOUNTERED a problem with an add-on and needs to close". 

the name of the add-on is       yt.dll

If I check my internet connections it appears to have disconnected.
Can any one advise me of  the problem??

NOTE:    Sometimes she can get google but cannot access any of the web sites in her favorites list.
OOOPS my bad.  Her machine is running VISTA. Uninstall the Yahoo Toolbar.Thanks for answering.     OKAY I un-installed Yahoo tool bar which did change the way it acts but did not fix the problem.  Still cannot access any of the sites on favorites list.

399.

Solve : Someone else got password help :)?

Answer»

Hey GUYS I'm new on this forum and I'm here because someone ELSE is using my FACEBOOK, gmail and hotmail accounts. I haven't given my passwords to anybody and I have also just recently changed my password. How do I prevent this from happening again ? I have AVAST Anti Virus and I run Win XP.

Thanks

400.

Solve : Panda USB Vaccine and Digital Cameras?

Answer»

Hi

I have a new Nikon Coolpix digital CAMERA that has its own in-built memory and that I will be ADDING an SD card to as soon as it arrives.

It CONNECTS VIA the USB allowing you to access it as a drive.

Is it safe to use Panda USB Vaccine on this hardware without it, in any way, negatively impacting the functionality of the device ?