InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 351. |
Solve : Spy assassin issues with charter internet suite? |
|
Answer» I recently removed my Charter Security Suite (F-Secure) from my computer and tried to reinstall it. It ended up going into a loop trying to prepare the computer for installation. After calling Charter, they said that I had Spy Assassin in my hpkey area in regedit. I'm wondering how to fix the problem and make it so I can have my ISP's security suite installed. Please HELP! |
|
| 352. |
Solve : What is this error message?? |
|
Answer» Running windows ME. This error message keeps popping up from Microsoft Internet Explorer |
|
| 353. |
Solve : destop backround message? |
|
Answer» ok i have a message on my backround of my destop it WONT let change my backround its like its stuck there this is what it says an it only has been detection browser hi jacks Your spyware scanner should not notify you of such events, because the events in question should not even be there. Quote any they just say the samething so any suggestions They all say the same because you're not looking deep enough into the problem. AVG Free -- Anti virus scanner Adaware SE Personal -- Anti spyware scanner Microsoft Antispyware -- Anti spyware scanner. Windows XP Home and Professional only. Spybot Search & Destroy -- Anti spyware scanner ZoneAlarm Free -- Free firewall - more user friendly Sygate Personal -- Free firewall - more configuration options |
|
| 354. |
Solve : Icons on desktop Change? |
|
Answer» What would make my Icons on my desktop just change out of no where?Did this happen on a re-boot!Download, install and CONFIGURE the following applications: |
|
| 355. |
Solve : AVG routine scan? |
|
Answer» Hey Everyone, When the System Areas Test detects a change, the Accept changes button is made available. Click it if you want the amended object to be incorporated in the System Areas Test database. If you do not accept the changes then AVG Free will alert you the next time you run the System Areas Test again. Does anyone know where the button is? DO NOT REMOVE kernel32.dll or shell32.dll, they are not trojans but important windows files.(Marlene should know that becuase of the links) [glb]Flame[/glb] Quote kernel32.dll --- TROJAN! Reading the links is how I found out, I hope Marlene reads them.That's why I put them there! [glb]Flame[/glb]But where's the button to accept the changes |
|
| 356. |
Solve : Comp Restore.. ugh? |
|
Answer» ok.. heres my problem. |
|
| 357. |
Solve : Can't delete infect file? help please? |
| Answer» UM i have windows XP home and installed norton antivirus 2004 on it. for some reason auto protect keeps detecting a downloader.trojan something like that in a file called ms3fs.dll and so i SEARCHED the file but it wont let me delete it manually either ive searched bunch of .dll download sites and cant FIND it need soem help PLEASE having this thing pop up eveyr 5 mins is annoyingYou could shutdown the pc.......disconnect form the net ......restart pc in safe MODE and delete it.....download spysweeper......norton is not that good.....at trojans.........or trojanhunter or swatit | |
| 358. |
Solve : Conflicting Software?? |
|
Answer» Hello all! I recently saw in the newspaper that having two firewalls OR virus protection applications could be dangerous, becuase they will ocnflict with each other... Is this true, or just the usual crap that they put in the newspapers? What I mean is this... The new computer cam with McAfee Virus scan... I'm going to install norton, but do not want to uninstall McAfee, becuase it raised *censored* on my old computer... So If I leave Norton and McAfee on at the same time, will they conflict? The paper says that they might weaken each other, making you less secure. Will that happen with Norton and McAfee if they are both on at the same time? Anti-virus programs are loners......so to speak .....They tend to be more effective on their own. Sometimes they do not peacefully co-exist . As far as McAfee raising *censored* with your old pc.........I suspect that it was something you removed ... (ie a shared file which was being used by another app ) . I have removed both McAfee and Norton from a number of machines and have never had any problems .....other than they both leave remnants all over the place .....That is for example why Norton has a separate removal app to cleanup bits and pieces . If you go into the registry and do a search for either of these applications ......I'll bet you , you will find a number of entries still left behind. ( But then that happens with many programs) As far as Norton charging you to "chat" ....... They do not charge for issues which are directly related to their software . They will however charge for calls which are just general in nature.....( this is done to attempt to avoid niusense calls) . I have had occassion to phone Norton re software issues with their products and they are very upfront about what support they will provide . If you have a legit problem with their products .......you WILL NOT be charged ......... The issue of charging was put in place to attempt to discourage users from simply picking up the phone and tieing up their techs to correct issues which have nothing to do with Norton products. In case you havent noticed .........people are lazy , instead of doing a bit of research into the problem they simply throw up their hands and reach for the phone ..... Norton , as well as McAfee have websites , which are there to help . Granted they are not always the easiest to navigate but in many instances the info is there ........ So , in conclusion , I would suggest using just one anti- virus . You decide which one you want and then remove the other. ( completely ) dl65 yeah. I'll just uninstal McAfee... Hate it LOL ... I like the firewall, but hate the virus protection... Thanks! I'll give this a quick shot [glb]Flame[/glb]You should try the AVG & Sygate combination, I'm sure you'd never go back to Norton or McAfee. A lot of people swear by ZoneAlarm too but I find it a little confusing to use.Thanks for the replies guys! I asked Dell, and of course, tehy want me to just uninstall McAfee... What I'll do is uninstall The virus scan and keep the firewall. Thanks guys! [glb]Flame[/glb] Quote You should try the AVG & Sygate combination, I'm sure you'd never go back to Norton or McAfee. ZoneAlarm is less comprehensive than Sygate. |
|
| 359. |
Solve : cannnot get rid of this crap!? |
|
Answer» did a bunch of scans and cant GET rid of this crap. i did virus scans and i got this: it says its deleted but its not cuz when i restart its back. You will have to locate and remove the source that causes the threats to reoccur. AVG Free -- Anti virus scanner Adaware SE Personal -- Anti spyware scanner Microsoft Antispyware -- Anti spyware scanner. Windows XP Home and Professional only. Spybot Search & Destroy -- Anti spyware scanner ZoneAlarm Free -- Free firewall - more user friendly Sygate Personal -- Free firewall - more configuration options disable system RESTORE and scan again.....or safe mode info....when you empty the trashcan....a folder called recycler keeps it....just in case you have deleted a file...that winxp may need..... |
|
| 360. |
Solve : Windows xp and norton internet security? |
|
Answer» I just installed windows XP. An upgrade from ME. I cannot start Norton Internet Security now. Do I need to re-install Norton?You SHOULD, yes. |
|
| 361. |
Solve : Active Protection? |
|
Answer» What active protection are people using and why? I had it neutered. Woof. LOL ...... I had mine spayed ........... Doesn't bark as much now . dl65 |
|
| 362. |
Solve : Mcafee: suspicious script detected.? |
|
Answer» I use mcafee security and there is a problem with the HELP file HELPCTR.EXE at C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\HELPCTR.EXE |
|
| 363. |
Solve : Unwanted up keeps opening on my navigators? |
|
Answer» Hello, I have been having some problems with my navigators recently (safari and chrome). It all started when I downloaded several third-party apps to try to recover some important files I deleted accidentally. The apps were all safe, except for one that Google warned me about (I don't remember its name or where I downloaded it from, I was desperate at the moment). |
|
| 364. |
Solve : Is there an Anti Virus that uses minimal amount of memory?? |
|
Answer» Hello |
|
| 365. |
Solve : What is flash32_29_0_0_171.ocx?? |
|
Answer» Hello, |
|
| 366. |
Solve : Router, wifi and PC? |
|
Answer» Hi! I really need to make sure, by tomorrow, that my wired connection and PC are safe when I give out wifi PW(I have to..) |
|
| 367. |
Solve : Russians Hacking Routers in the (Failing) News? |
|
Answer» POWERING off and changing my password doesn't SEEM like it's enough, if this is straight-up LEGIT. Any thoughts? https://www.nytimes.com/2018/05/27/technology/router-fbi-reboot-malware.htmlWell, on the surface it does SOUND legit. |
|
| 368. |
Solve : Random files with pictures I have never seen appearing on my desktop? |
|
Answer» For about a year now, I have been finding files with photos of people and art. I don’t know if this is a malware from a game with a virus or just from social sites. I FOUND photos of a woman and her son in ONE file and PICTURES of cartoon characters in another. Please help! |
|
| 369. |
Solve : I've got some problems with the Firefox browser.? |
|
Answer» Hi all! I'm Tommy ! |
|
| 370. |
Solve : How to registrer AVG PV tuneup? |
|
Answer» I have finished my trial PERIOD and now I want to register the program with my key. But where do I enter this licence key ?You should CONTACT AVG. |
|
| 371. |
Solve : Will extracting a virus infect my computer?? |
|
Answer» Let's say there is a virus called virus.exe in a zip file, extracting it will trigger the antivirus and av will quarantine it. If I disable my antivirus (which somehow also disables windows defender), EXTRACT virus.exe (without double clicking or running the exe) and upload it to virustotal for a scan, will my computer still get infected? |
|
| 372. |
Solve : Is this a scam.? |
|
Answer» Hi, this came up while I was looking at the TV guide. |
|
| 373. |
Solve : Can virus/malware infect offline disks?? |
|
Answer» As per the subject: |
|
| 374. |
Solve : Anti-trackers? |
|
Answer» What are they ? Which one(s) should i have ?You can learn more here.Thanks for info, SuperDave. I do have Ad BlockPlus -like it, it does the job.Maybe it's ENOUGH, I don't have annoying ads popping up anymore. Probably could use more protection of some kind. We NEVER can be over protected, can we !Download Security Check by screen317 from the following link and save it to your desktop. |
|
| 375. |
Solve : CHROMIUM Malware - What is it?? |
|
Answer» A Google search goes to web sites that want to give me even more malware. This is a tutorial on how to completely remove the "Chromium" malware. This is not the only method, but I found this to be the most effective. ... I did remove it, but hot that way! Question: Why did my AV program not find it? (I am running Windows 10 pro 32 bit on my Dell 755.)Hello and welcome to GeekPolice.Net My name is Dave. I will be helping you out with your particular problem on your computer. 1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine. 2. The fixes are specific to your problem and should only be used for this issue on this machine. 3. If you don't know or understand something, please don't hesitate to ask. 4. Please DO NOT run any other tools or scans while I am helping you. 5. It is important that you reply to this thread. Do not start a new topic. 6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe. 7. Absence of symptoms does not mean that everything is clear. If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line. ***************************************************************** Quote IMO, any program that will not uninstall is likely malware -Am I right?That's one good indication but not always. Quote Question: Why did my AV program not find it?Because it is not a virus. It is malware. Please download AdwareCleaner onto your Desktop. AdwCleaner Before starting AdwCleaner, close all open programs and internet browsers, then double-click on the AdwCleaner icon. If Windows prompts you as to whether or not you wish to run AdwCleaner, please allow it to run. When the AdwCleaner program will open, click on the Scan button as shown below. AdwCleaner will now start to search for malicious files that may be installed on your computer. To remove the files that were detected in the previous step, please click on the Clean button. AdwCleaner will now prompt you to save any open files or data as the program will need to reboot the computer. Please do so and then click on the OK button. AdwCleaner will now delete all detected adware from your computer. When it is done it will display an alert that explains what PUPs (Potentially Unwanted Programs) and Adware are. Please read through this information and then press the OK button. You will now be presented with an alert that states AdwCleaner needs to reboot your computer. Please click on the OK button to allow AdwCleaner reboot your computer.A log will be produced. Please copy and paste this log in your next reply. ********************************************* Download and install: Please download Malwarebytes' scanner to your desktop. Double Click mbam-setup.exe to install the application.
Download Security Check by screen317 from the following link and save it to your desktop. Security Check * Double-click Security Check.bat * Follow the on-screen instructions inside of the black box. * A Notepad document should open automatically called checkup.txt * Post the contents of that document in your next reply. Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so. Wow! Van not believe how much stuff there was! Reports: Ad Cleaner: +++++++++++++++ # ------------------------------- # Malwarebytes AdwCleaner 7.3.0.0 # ------------------------------- # Build: 04-04-2019 # Database: 2019-04-05.4 (Cloud) # Support: https://www.malwarebytes.com/support # # ------------------------------- # Mode: Clean # ------------------------------- # Start: 04-07-2019 # Duration: 00:00:09 # OS: Windows 10 Pro # Cleaned: 31 # Failed: 2 ***** [ Services ] ***** No malicious services cleaned. ***** [ Folders ] ***** Deleted C:\Program Files\Reimage Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reimage repair Deleted C:\ProgramData\Reimage Protector Deleted C:\Windows\System32\config\systemprofile\AppData\Local\WebDiscoverBrowser Deleted C:\rei ***** [ Files ] ***** Deleted C:\Users\geek9\AppData\Roaming\Mozilla\Firefox\Profiles\i8sbflim.default\searchplugins\avg-secure-search.xml Deleted C:\Windows\Reimage.ini Deleted C:\Windows\Temp\reimage.log ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** No malicious tasks cleaned. ***** [ Registry ] ***** Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484} Deleted HKCU\Software\PRODUCTSETUP Deleted HKCU\Software\ProductSetup\Uninstall\0B2U2Z1P0F1P1G1R1P1V0A1Q1Q0O1G Deleted HKCU\Software\ProductSetup\Uninstall\0S1P1T1C1R1MtT0P1C1F2X1L1Q1P1QtT1S2UtT0Y1T1M1F1F Deleted HKCU\Software\Reimage Deleted HKCU\Software\WebDiscoverBrowser Deleted HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL Deleted HKLM\Software\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A} Deleted HKLM\Software\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484} Deleted HKLM\Software\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB} Deleted HKLM\Software\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4} Deleted HKLM\Software\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546} Deleted HKLM\Software\Classes\REI_AxControl.ReiEngine Deleted HKLM\Software\Classes\REI_AxControl.ReiEngine.1 Deleted HKLM\Software\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36} Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Codec Settings UAC Manager Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Codec Settings UAC Manager Deleted HKLM\Software\Reimage Deleted HKLM\Software\WebDiscoverBrowser Deleted HKU\.DEFAULT\Software\WebDiscoverBrowser Deleted HKU\S-1-5-18\Software\WebDiscoverBrowser ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries cleaned. ***** [ Chromium URLs ] ***** No malicious Chromium URLs cleaned. ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries cleaned. ***** [ Firefox URLs ] ***** Deleted https://mysearch.avg.com/?rvt=1&pid=bcu Deleted https://mysearch.avg.com/?rvt=1&pid=bcu Not Deleted webtuneup.avg.com Not Deleted webtuneup.avg.com *************************
************************* AdwCleaner[S00].txt - [1569 octets] - [07/03/2019 12:07:14] AdwCleaner[C00].txt - [1661 octets] - [07/03/2019 12:09:32] AdwCleaner[S01].txt - [4021 octets] - [07/04/2019 12:05:12] ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ########## Malwarebyres: ======================== Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 4/7/19 Scan Time: 12:22 PM Log File: 8aa0a846-596a-11e9-9a9c-00219b6a717e.json -Software Information- Version: 3.7.1.2839 Components Version: 1.0.563 Update Package Version: 1.0.10038 License: Expired -System Information- OS: Windows 10 (Build 18356.1) CPU: x86 File System: NTFS User: DESKTOP-T35LOPR\geek9 -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 181231 Threats Detected: 15 Threats Quarantined: 15 Time Elapsed: 3 min, 15 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 4 PUP.Optional.SearchManager, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\NAHHMPBCKPGDIDFNMFKFGIFLPJIJILCE, Quarantined, [2063], [440037],1.0.10038 PUP.Optional.SearchManager, HKU\S-1-5-21-1999882772-3128741223-438591315-1001\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\nahhmpbckpgdidfnmfkfgiflpjijilce, Quarantined, [2063], [440037],1.0.10038 PUP.Optional.SearchManager, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\PILPLLOABDEDFMIALNFCHJOMJMPJCOEJ, Quarantined, [2063], [183362],1.0.10038 PUP.Optional.SearchManager, HKU\S-1-5-21-1999882772-3128741223-438591315-1001\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\pilplloabdedfmialnfchjomjmpjcoej, Quarantined, [2063], [183362],1.0.10038 Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 2 PUP.Optional.Reimage, C:\ProgramData\ReimageRepair\Results, Quarantined, [340], [651074],1.0.10038 PUP.Optional.Reimage, C:\PROGRAMDATA\REIMAGEREPAIR, Quarantined, [340], [651074],1.0.10038 File: 9 PUP.Optional.SearchManager, C:\USERS\GEEK9\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\chrome-extension_pilplloabdedfmialnfchjomjmpjcoej_0.localstorage, Quarantined, [2063], [453138],1.0.10038 PUP.Optional.SearchModule, C:\USERS\GEEK9\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\chrome-extension_nahhmpbckpgdidfnmfkfgiflpjijilce_0.localstorage, Quarantined, [275], [453492],1.0.10038 PUP.Optional.SearchManager, C:\USERS\GEEK9\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [2063], [183362],1.0.10038 PUP.Optional.Reimage, C:\ProgramData\ReimageRepair\Results\ProtectorPackage.log, Quarantined, [340], [651074],1.0.10038 PUP.Optional.Reimage, C:\ProgramData\ReimageRepair\active_protection.txt, Quarantined, [340], [651074],1.0.10038 PUP.Optional.Reimage, C:\ProgramData\ReimageRepair\cfl.rei, Quarantined, [340], [651074],1.0.10038 PUP.Optional.Reimage, C:\ProgramData\ReimageRepair\scan_agent_result_log.txt, Quarantined, [340], [651074],1.0.10038 PUP.Optional.Reimage, C:\ProgramData\ReimageRepair\url_setting_definitions.txt, Quarantined, [340], [651074],1.0.10038 PUP.Optional.WinYahoo.Generic, C:\USERS\GEEK9\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I8SBFLIM.DEFAULT\SEARCHPLUGINS\SADARAMA.XML, Quarantined, [223], [643052],1.0.10038 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end) Security Check -------------------------- Results of screen317's Security Check version 1.014 --- 12/23/15 x86 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:``````````````[/u] Windows Firewall Enabled! Windows Defender AVG Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:`````````[/u] Adobe Flash Player 32.0.0.156 Mozilla Firefox (66.0.2) Google Chrome (73.0.3683.86) Google Chrome (SetupMetrics...) ````````Process Check: objlist.exe by Laurent````````[/u] Malwarebytes Anti-Malware mbamservice.exe AVG Antivirus AVGSvc.exe AVG Antivirus aswidsagent.exe AVG Antivirus AVGUI.exe Malwarebytes Anti-Malware mbamtray.exe `````````````````System Health check`````````````````[/u] Total Fragmentation on Drive C: % ````````````````````End of Log``````````````````````[/u] That's all ;D The Security log show you have two AV's active on your computer. Windows Defender is the resident AV that comes with Windows 10. I would advise you to uninstall AVG. It is not needed. You should only have one AV active on your computer at any time. ESET Online Scanner Note : If you use Internet Explorer to get the ESET Online Scanner, you won't have to download, nor install the tool, as everything will be ran in a contextual (pop-up) window of Internet Explorer. However, for every other browsers, you will have to download and install ESET Online Scanner. In this set of instruction, I'll use Google Chrome to download it and run it (since a lot of people will do it), however, except for the download and installation procedure, the same instructions applies if you use Internet Explorer. Please note that two or three prompts will appear if you use Internet Explorer asking you to reload the page, authorize the application, execute it, ETC. Accept all of them in order to run ESET Online Scanner. Download and execute ESET OnlineScan (on this window, click on ESET Smart Installer to trigger the download). People accessing this URL via Internet Explorer will start the integration process of ESET Online Scanner in their browser; Once the installation is done (it requires Admin Rights), check the following settings (two of them are under Advanced Settings, click on it to display them) : Enable detection of potentially unwanted applications; Scan archives; Scan for potentially unsafe applications; Optional : If you want to scan more drives, click on CHANGE... and select the drives you want to include in the scan; After you're done CHECKING these options, click on Start and ESET Online Scanner will download it's virus signature database before starting the scan; Once done, the scan will start automatically. Detections will appear at the bottom of the window. ESET Online Scanner can have an EXTREMELY long scan time that can last between 2 or 3 hours. So if you start the scan, do not interrupt it, let it complete until the end; After the scan is finished, a summary window will appear to give you the information about the scan. Then you'll have to the option to see what threads were found and to manage the threats that were quarantined; Click on List of found threats, it'll display every threat identified during that scan, their type and what action was taken against them. Click on Copy to clipboard to copy these results on our clipboard and post them in your next reply; Once you're done, click on the Back button; Check both checkboxes at the bottom: Uninstall application on close and Delete quarantined files before CLICKING on the Finish button; |
|
| 376. |
Solve : I need help I think I am been hacked? |
|
Answer» The reason I think I am being hacked is my phone has been changing settings on it's own apps that i never downloaded got downloaded and some can't be removed my battery dies way to quick it burns up when I only playing music or using maps. I tried to change my settings back to normal but they just change back when i not looking at my phone another strange thing is my resume that I made from scratch had someone else number on it I no longer receive texts or calls from certain people at certain days and TIMES even email has been ACTING up my passwords have been changing and I am just fed up I NEED advice to counter this. I think they got in thru my home internet I have spectrum and I change my Passwords and the SSI Name ID but my sister and brother give away my PASSWORD to my neighbors which makes me mad The reason I think I am being hacked is my phone has been changing settings on it's own apps that i never downloaded got downloaded and some can't be removed my battery dies way to quick it burns up when I only playing music or using maps. I tried to change my settings back to normal but they just change back when i not looking at my phone another strange thing is my resume that I made from scratch had someone else number on it I no longer receive texts or calls from certain people at certain days and times even email has been acting up my passwords have been changing and I am just fed up I need advice to counter this. I think they got in thru my home internet I have spectrum and I change my Passwords and the SSI Name ID but my sister and brother give away my password to my neighbors which makes me madhttps://solitaire.onl/ 9apps.ooo/ https://bluestacks.vip/ my issue got solved!!Good for you. |
|
| 377. |
Solve : .chk file? |
|
Answer» recently my friend TOLD me about his file was....deleted but the capacity of its USB device remain constant. but he CANT see his old files all of his files. then i noticed when i check his USB Flashdrive i noticed there is "found.. named folder and " all files listed as .chk file format. |
|
| 378. |
Solve : Received a eMail FROM "Here my own eMail Yahoo"? |
|
Answer» Received an email from "here my own email Yahoo", and ACTIVE when you pass the MOUSE over, to "here my own email yahoo, as from" |
|
| 379. |
Solve : resource:///components/nsSessionStore.js:402? |
|
Answer» Hi! My laptop is becoming increasingly slow as if there is a virus. Firefox keeps asking me whether I can to stop a script, GOOGLE chrom says about a PLUGIN that has crashed but in general sometimes I think it has frozen all together.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. ************************************************************************ Download DDS from HERE or HERE and save it to your desktop. Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it) * XP users Double click on dds to run it. * If your antivirus or firewall try to block DDS then please allow it to run. * When finished DDS will open two (2) logs. * Save both reports to your desktop. * The instructions here ask you to attach the Attach.txt. 1) DDS.txt 2) Attach.txt Instead of attaching, please copy/past both logs into your Thread Note: DDS will instruct you to post the Attach.txt log as an attachment. Please just post it as you would any other log by copying and pasting it into the reply. •Close the program window, and delete the program from your desktop. Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE .Then post your DDS logs. (DDS.txt and Attach.txt ) Thanks. This is the SUPERAntiSpyware Scan Log SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 02/26/2012 at 04:52 PM Application Version : 5.0.1144 Core RULES Database Version : 8279 Trace Rules Database Version: 6091 Scan type : Complete Scan Total Scan Time : 09:59:07 Operating System Information Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601) UAC On - Limited User Memory items scanned : 576 Memory threats detected : 0 Registry items scanned : 66358 Registry threats detected : 4 File items scanned : 261118 File threats detected : 556 Browser Hijacker.Deskbar (x86) HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B} (x86) HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid32 (x86) HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib (x86) HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib#Version Adware.Tracking Cookie C:\Users\marina\AppData\Roaming\Microsoft\Windows\Cookies\YVRJ2FYS.txt [ /c.atdmt.com ] C:\Users\marina\AppData\Roaming\Microsoft\Windows\Cookies\V5NB1UG9.txt [ /mywebsearch.com ] C:\Users\marina\AppData\Roaming\Microsoft\Windows\Cookies\CT0ZAN1V.txt [ /atdmt.com ] C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\1I6Y6E7X.txt [ Cookie:[email protected]/ ] C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\WA530UF2.txt [ Cookie:[email protected]/adServe/banners ] C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\H48NWYV4.txt [ Cookie:[email protected]/cgi-bin ] C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\LWOTI6EC.txt [ Cookie:[email protected]/ ] C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZJYAWTEW.txt [ Cookie:[email protected]/ ] C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\YEP7UH7S.txt [ Cookie:[email protected]/ ] C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\XES36DXK.txt [ Cookie:[email protected]/ ] C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\JAILEL10.txt [ Cookie:[email protected]/ ] C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\TM2QR2BS.txt [ Cookie:[email protected]/ ] C:\USERS\MARINA\Cookies\YVRJ2FYS.txt [ Cookie:[email protected]/ ] C:\USERS\MARINA\Cookies\V5NB1UG9.txt [ Cookie:[email protected]/ ] C:\USERS\MARINA\Cookies\CT0ZAN1V.txt [ Cookie:[email protected]/ ] .serving-sys.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .atdmt.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .atdmt.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .serving-sys.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .imrworldwide.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .imrworldwide.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .apmebf.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .mediaplex.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adbrite.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] rotator.adjuggler.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] rotator.adjuggler.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] rotator.adjuggler.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] track.adform.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ru4.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .specificclick.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adviva.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .serving-sys.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .doubleclick.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .apmebf.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adxvalue.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .fastclick.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .casalemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .casalemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .casalemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .casalemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .casalemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .casalemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adinterax.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .zanox.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.zanox.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tradedoubler.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tradedoubler.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tradedoubler.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .uk.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tacoda.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tacoda.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tacoda.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tacoda.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tacoda.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tacoda.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ar.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .tribalfusion.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .pro-market.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adxpose.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adbrite.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .wpni.112.2o7.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] statse.webtrendslive.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .chitika.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .mm.chitika.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adtech.de [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .histats.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .weborama.fr [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .baa.solution.weborama.fr [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .baa.solution.weborama.fr [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .baa.solution.weborama.fr [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .baa.solution.weborama.fr [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .histats.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .lucidmedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .yieldmanager.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adinterax.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] eas.apm.emediate.eu [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] eas.apm.emediate.eu [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .questionmarket.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] accounts.google.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .virginmedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] server.adformdsp.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adformdsp.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adform.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .bs.serving-sys.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] track.adform.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .adform.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .247realmedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ads.audience2media.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ads.audience2media.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .media6degrees.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .media6degrees.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .media6degrees.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .media6degrees.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .media6degrees.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .media6degrees.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .audience2media.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .serving-sys.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .serving-sys.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .doubleclick.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .247realmedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .247realmedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .ru4.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .mediaplex.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] ad.insightexpressai.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] cdn2.baronsmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] cloud.video.unrulymedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] cloudfront.mediamatters.org [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] content.oddcast.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] content.yieldmanager.edgesuite.net [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] ds.serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] ec.atdmt.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] ia.media-imdb.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] media.buto.tv [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] media.kyte.tv [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] media.mtvnservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] media.npr.org [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] media.scanscout.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] media.socialvibe.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] media1.break.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] media3.break.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] msnbcmedia.msn.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] s0.2mdn.net [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] secure-uk.imrworldwide.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] secure-us.imrworldwide.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] spe.atdmt.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] stat.easydate.biz [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] tracking.onefeed.co.uk [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] www.99counters.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] www.al-anon.alateen.org [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ] .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .getclicky.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .static.getclicky.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] in.getclicky.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] track.solocpm.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] track.solocpm.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] track.solocpm.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adviva.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] eas.apm.emediate.eu [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] eas4.emediate.eu [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .indoormedia.co.uk [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] max.bannermanager.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .tradedoubler.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .tradedoubler.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .tradedoubler.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] openx1.overadmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .accounts.google.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .accounts.google.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] accounts.google.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] accounts.google.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .mjtracking.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .mjtracking.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] islamicinsights.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .islamicinsights.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .islamicinsights.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .richmedia.yahoo.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .apmebf.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .apmebf.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .mediafire.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .mediafire.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .mediafire.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] server.adformdsp.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adformdsp.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] stats.e-go.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] *Blocked Russian URL* [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .game-advertising-online.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] track.adform.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adform.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .statcounter.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] cdmedia.rotator.hadj7.adjuggler.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] cdmedia.rotator.hadj7.adjuggler.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] vidasco.rotator.hadj7.adjuggler.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] vidasco.rotator.hadj7.adjuggler.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adjuggler.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adinterax.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adinterax.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .amazon-adsystem.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .amazon-adsystem.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .zedo.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .zedo.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .zedo.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .zedo.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .zedo.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] uk.sitestat.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] uk.sitestat.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .harrenmedianetwork.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .fastclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .fastclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .ad-emea.doubleclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .ad-emea.doubleclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .doubleclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .doubleclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .www.cdmediallc.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] statse.webtrendslive.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] tracking.hostgator.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] ox.mediabistro.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .find-me-a-gift.co.uk [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .find-me-a-gift.co.uk [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .e-2dj6wjlyundpgeo.stats.esomniture.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .imrworldwide.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .imrworldwide.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] wstat.wibiya.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .atdmt.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .atdmt.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .yieldmanager.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .histats.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .histats.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .legolas-media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .legolas-media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .legolas-media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .tripod.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .tripod.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] leads.383media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] leads.383media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .mm.chitika.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .ads.24media.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .ads.24media.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .service.24media.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .service.24media.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] ads.audience2media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .audience2media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] ads.audience2media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .audience2media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .clickfuse.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .clickfuse.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .clickfuse.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] findnsave.sacbee.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .c.gigcount.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .247realmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .247realmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .247realmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .collective-media.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .collective-media.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .collective-media.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .collective-media.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] doublespeed.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] doublespeed.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] help.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] help.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] my.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adbrite.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adbrite.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adbrite.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adbrite.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adbrite.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] dc.tremormedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .nextag.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .nextag.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .nextag.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .nextag.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .womanmediagroup.es [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] ad.zanox.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .zanox.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adxpose.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] ads.saymedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] ads.saymedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] clickztrax.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] clickztrax.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .clicksor.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .clicksor.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .smartadserver.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www4.smartadserver.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .unrulymedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .eyewonder.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .eyewonder.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .technoratimedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .lucidmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] publishers.clickbooth.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.findaproperty.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .findaproperty.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .findaproperty.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .findaproperty.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] ad2.adfarm1.adition.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .specificclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .revenuemantra.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .xm.xtendmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] accounts.youtube.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .lfstmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .lfstmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .lfstmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .lfstmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .pro-market.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .overture.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .overture.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .perf.overture.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] network.clickbanner.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .kantarmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .kantarmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .files.bannersnack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .files.bannersnack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adxvalue.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .interclick.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .interclick.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .a1.interclick.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .a1.interclick.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .interclick.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .interclick.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .ru4.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .ru4.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .mediaplex.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .mediaplex.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] *Blocked Russian URL* [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] *Blocked Russian URL* [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adtechus.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adserver.adtechus.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.burstnet.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .www.burstnet.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .burstnet.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] www.burstnet.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .at.atwola.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .uk.at.atwola.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .uk.at.atwola.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .uk.at.atwola.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .bs.serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .hearstmagazines.112.2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .wpni.112.2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .highbeam.122.2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .112.2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .opodo.122.2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .traveladvertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .traveladvertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .questionmarket.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .questionmarket.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] adfarm1.adition.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] eas.apm.emediate.eu [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] eas.apm.emediate.eu [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .tribalfusion.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .adinterax.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .mediaplex.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ] Malwarebytes Anti-Malware (Trial) 1.60.1.1000 www.malwarebytes.org Database version: v2012.02.26.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 marina :: SAMMADHITTI [administrator] Protection: Enabled 26/02/2012 17:54:58 mbam-log-2012-02-26 (17-54-58).txt Scan type: Full scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 535028 Time elapsed: 5 hour(s), 8 minute(s), 7 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 2 C:\Program Files (x86)\27res.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Users\marina\AppData\LocalLow\OurBabyMaker_27EI\Installr\Cache\023EC878.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully. (end) I will need to see the DDS logs; both of them.Thanks. Here is the first (the DDS) . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31 Run by marina at 3:49:45 on 2012-02-27 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.3999.1335 [GMT 0:00] . AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\IDT\WDM\STacSV64.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskhost.exe C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\IDT\WDM\AESTSr64.exe C:\Windows\SysWOW64\svchost.exe -k Akamai C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\SysWOW64\svchost.exe -k netsvcs C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files (x86)\Giraffic\Veoh_Giraffic.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe C:\Windows\System32\StikyNot.exe C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe C:\Program Files (x86)\Skype\Phone\Skype.exe C:\Users\marina\AppData\Local\Akamai\netsession_win.exe C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe C:\Users\marina\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files (x86)\SecureW2\sw2_tray.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVH.EXE C:\Users\marina\AppData\Local\Akamai\netsession_win.exe C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe C:\Program Files (x86)\real\realplayer\Update\realsched.exe C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Windows\system32\NOTEPAD.EXE Q:\140062.enu\Office14\ONENOTEM.EXE C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe C:\Program Files (x86)\Nero\Update\NASvc.exe C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE C:\Windows\splwow64.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe Q:\140062.enu\Office14\WINWORD.EXE C:\Windows\system32\svchost.exe -k defragsvc C:\Windows\system32\taskeng.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://start.facemoods.com/?a=axl uInternet Settings,ProxyOverride = 127.0.0.1:9421;*.local mSearchAssistant = hxxp://start.facemoods.com/?a=axl&s={searchTerms}&f=4 BHO: Shopping Assistant Plugin: {1631550f-191d-4826-b069-d9439253d926} - C:\Program Files (x86)\PriceGong\2.5.2\PriceGongIE.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Babylon toolbar helper: {2eecd738-5844-4a99-b4b6-146bf802613b} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll BHO: Norton Identity Protection: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll BHO: CescrtHlpr Object: {64182481-4f71-486b-a045-b233bd0da8fc} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\IPS\IPSBHO.DLL BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - C:\Program Files (x86)\WOT\WOT.dll BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO: TBLA06779 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - C:\Program Files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll TB: ListenArabic Toolbar: {f569cf08-edf6-4fab-8c8a-eec184358372} - C:\Program Files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll TB: C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - C:\Program Files (x86)\WOT\WOT.dll TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarTlbr.dll TB: facemoods Toolbar: {db4e9724-f518-4dfd-9c7c-78b52103cab9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden uRun: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe uRun: [VeohPlugin] "C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized uRun: [Akamai NetSession Interface] "C:\Users\marina\AppData\Local\Akamai\netsession_win.exe" mRun: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start mRun: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe mRun: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe mRun: [SecureW2 Tray] C:\Program Files (x86)\SecureW2\sw2_tray.exe mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [NBAgent] "C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" /WinStart mRun: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe mRun: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe" /md I mRun: [TkBellExe] "C:\Program Files (x86)\real\realplayer\update\realsched.exe" -osboot mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe mRun: [] mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray StartupFolder: C:\Users\marina\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\BBCIPL~1.LNK - StartupFolder: C:\Users\marina\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\marina\AppData\Roaming\Dropbox\bin\Dropbox.exe StartupFolder: C:\Users\marina\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE StartupFolder: C:\Users\marina\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\FLIPTO~1.LNK - C:\Program Files (x86)\Fliptoast\fliptoast.exe StartupFolder: C:\Users\marina\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVH.EXE StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: HideFastUserSwitching = 0 (0x0) mPolicies-system: EnableLinkedConnections = 1 (0x1) IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll IE: {F569CF08-EDF6-4FAB-8C8A-EEC184358372} - {F569CF08-EDF6-4FAB-8C8A-EEC184358372} - C:\Program Files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab TCP: DhcpNameServer = 194.168.4.100 194.168.8.100 TCP: Interfaces\{6BA18F65-FA7D-4561-B466-FF1BDBAC958E} : DhcpNameServer = 193.63.73.32 TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B} : DhcpNameServer = 194.168.4.100 194.168.8.100 TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B}\249627B6265636B6D27514D4 : DhcpNameServer = 193.61.1.250 TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B}\24F646C6569616E6D2C49626271627965637 : DhcpNameServer = 163.1.2.1 129.67.1.1 129.67.1.180 TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B}\36F6374716 : DhcpNameServer = 192.168.0.1 TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B}\478656169627C696E656 : DhcpNameServer = 10.81.93.254 10.81.93.254 TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B}\9435D434D214B455 : DhcpNameServer = 217.13.1.28 83.218.143.36 TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B}\B49405F4350234146454 : DhcpNameServer = 192.168.1.1 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll SEH: EasyBits ShellExecute Hook: {e54729e8-bb3d-4270-9d49-7389ea579090} - C:\Windows\SysWow64\EZUPBH~1.DLL mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe" BHO-X64: Shopping Assistant Plugin: {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.5.2\PriceGongIE.dll BHO-X64: PriceGong - No File BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: Babylon toolbar helper: {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll BHO-X64: Babylon toolbar helper - No File BHO-X64: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll BHO-X64: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll BHO-X64: Norton Identity Protection - No File BHO-X64: CescrtHlpr Object: {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll BHO-X64: facemoods Helper - No File BHO-X64: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\IPS\IPSBHO.DLL BHO-X64: Norton Vulnerability Protection - No File BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll BHO-X64: Search Helper - No File BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL BHO-X64: URLRedirectionBHO - No File BHO-X64: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll BHO-X64: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO-X64: TBLA06779 Class: {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll BHO-X64: TBLA06779 - No File TB-X64: ListenArabic Toolbar: {F569CF08-EDF6-4FAB-8C8A-EEC184358372} - C:\Program Files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll TB-X64: C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll TB-X64: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll TB-X64: Babylon Toolbar: {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarTlbr.dll TB-X64: facemoods Toolbar: {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll mRun-x64: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start mRun-x64: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe mRun-x64: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe mRun-x64: [SecureW2 Tray] C:\Program Files (x86)\SecureW2\sw2_tray.exe mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun-x64: [NBAgent] "C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" /WinStart mRun-x64: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe mRun-x64: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe" /md I mRun-x64: [TkBellExe] "C:\Program Files (x86)\real\realplayer\update\realsched.exe" -osboot mRun-x64: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe mRun-x64: [(Default)] mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray SEH-X64: EasyBits ShellExecute Hook: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWow64\EZUPBH~1.DLL . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\marina\AppData\Roaming\Mozilla\Firefox\Profiles\2y9b2iki.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=3&q={searchTerms} FF - prefs.js: browser.startup.homepage - hxxp://www.soas.ac.uk/ FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=2&q= FF - prefs.js: network.proxy.gopher - FF - prefs.js: network.proxy.type - 4 FF - plugin: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\npBrowserPlugin.dll FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\bin\new_plugin\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll FF - plugin: C:\Users\marina\AppData\Roaming\Move Networks\plugins\npqmp071700000016.dll FF - plugin: C:\Users\marina\AppData\Roaming\Mozilla\Firefox\Profiles\2y9b2iki.default\extensions\[email protected]\plugins\NPLoaderFF.dll FF - plugin: C:\Users\marina\AppData\Roaming\Mozilla\plugins\np-mswmp.dll FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll . ---- FIREFOX POLICIES ---- FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true . ============= SERVICES / DRIVERS =============== . R0 NBVol;Nero Backup Volume Filter Driver;C:\Windows\system32\DRIVERS\NBVol.sys --> C:\Windows\system32\DRIVERS\NBVol.sys [?] R0 NBVolUp;Nero Backup Volume Upper Filter Driver;C:\Windows\system32\DRIVERS\NBVolUp.sys --> C:\Windows\system32\DRIVERS\NBVolUp.sys [?] R0 SymDS;Symantec Data Store;C:\Windows\system32\drivers\NISx64\1305000.091\SYMDS64.SYS --> C:\Windows\system32\drivers\NISx64\1305000.091\SYMDS64.SYS [?] R0 SymEFA;Symantec Extended File Attributes;C:\Windows\system32\drivers\NISx64\1305000.091\SYMEFA64.SYS --> C:\Windows\system32\drivers\NISx64\1305000.091\SYMEFA64.SYS [?] R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\BASHDefs\20120215.001\BHDrvx64.sys [2012-2-16 1157240] R1 ccSet_NIS;Norton Internet Security Settings Manager;C:\Windows\system32\drivers\NISx64\1305000.091\ccSetx64.sys --> C:\Windows\system32\drivers\NISx64\1305000.091\ccSetx64.sys [?] R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\IPSDefs\20120224.002\IDSviA64.sys [2012-2-24 488568] R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928] R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368] R1 SymIRON;Symantec Iron Driver;C:\Windows\system32\drivers\NISx64\1305000.091\Ironx64.SYS --> C:\Windows\system32\drivers\NISx64\1305000.091\Ironx64.SYS [?] R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\system32\Drivers\NISx64\1305000.091\SYMNETS.SYS --> C:\Windows\system32\Drivers\NISx64\1305000.091\SYMNETS.SYS [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928] R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2010-6-30 89600] R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-13 20992] R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624] R2 ezSharedSvc;Easybits Shared Services for Windows;C:\Windows\system32\svchost.exe -k netsvcs [2009-7-13 20992] R2 Giraffic;Veoh Giraffic Video Accelerator;C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe --service --> C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe --service [?] R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-3-28 94264] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-5-4 652360] R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-9-23 641832] R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\ccsvchst.exe [2012-1-31 138248] R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2011-10-12 4700824] R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776] R3 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-11-7 227896] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-2-7 138360] R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;C:\Windows\system32\drivers\IntcHdmi.sys --> C:\Windows\system32\drivers\IntcHdmi.sys [?] R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?] R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys --> C:\Windows\system32\DRIVERS\Sftfslh.sys [?] R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys --> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?] R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys --> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?] R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys --> C:\Windows\system32\DRIVERS\Sftvollh.sys [?] R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-31 136176] S2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-9-9 86072] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-31 136176] S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-1-15 227232] S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys --> C:\Windows\system32\DRIVERS\netw5v64.sys [?] S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS --> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?] S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS --> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?] S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS --> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?] . =============== Created Last 30 ================ . 2012-02-26 17:00:58 -------- d-----w- C:\Users\marina\AppData\Local\{D99E6408-6589-41E0-BA0D-B098D5082C64} 2012-02-26 17:00:30 -------- d-----w- C:\Users\marina\AppData\Local\{017CAE32-ABCB-4464-B7BD-71CF6398EBC9} 2012-02-26 06:42:25 -------- d-----w- C:\Users\marina\AppData\Roaming\SUPERAntiSpyware.com 2012-02-26 06:41:56 -------- d-----w- C:\Program Files\SUPERAntiSpyware 2012-02-26 06:41:55 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com 2012-02-26 00:32:43 -------- d-----w- C:\Users\marina\AppData\Local\{7B3394B8-F42F-43EC-B37C-0808475E0F16} 2012-02-26 00:32:16 -------- d-----w- C:\Users\marina\AppData\Local\{9A0DD797-9B50-4819-A68C-C6B440A483E8} 2012-02-23 08:39:58 -------- d-----w- C:\Users\marina\AppData\Local\{B43DA613-BCA4-40B9-AD3B-188ABD753A68} 2012-02-23 08:39:42 -------- d-----w- C:\Users\marina\AppData\Local\{D4045162-63B9-4EE8-B67B-8A5461CFD840} 2012-02-22 12:39:28 -------- d-----w- C:\Users\marina\AppData\Local\{97F142C7-5B8D-4A3E-A2A5-F3E075451A80} 2012-02-22 12:39:12 -------- d-----w- C:\Users\marina\AppData\Local\{BA3EEA9B-68BC-4BF4-9CF2-5A6ACEE01010} 2012-02-21 22:08:25 -------- d-----w- C:\Users\marina\AppData\Local\{1AB97308-BA12-4912-B470-90ACD4BF5D01} 2012-02-21 22:08:24 -------- d-----w- C:\Users\marina\AppData\Local\{C5C365A5-EFDF-4565-B8BC-CC390EF098B3} 2012-02-21 10:07:54 -------- d-----w- C:\Users\marina\AppData\Local\{12C36157-1412-492B-B45A-CE97FC6F213D} 2012-02-20 22:07:14 -------- d-----w- C:\Users\marina\AppData\Local\{4E76EBDC-2BA3-485B-ADA7-9850A2986377} 2012-02-20 10:06:37 -------- d-----w- C:\Users\marina\AppData\Local\{D2663F44-A3B5-49E7-A18C-4584E6E55E7C} 2012-02-20 10:06:26 -------- d-----w- C:\Users\marina\AppData\Local\{8E61D92A-2012-4E61-92B0-36ED0DD0551B} 2012-02-20 10:06:14 -------- d-----w- C:\Users\marina\AppData\Local\{C41EBCCA-1024-4F31-A7DE-4182EA5AEE21} 2012-02-19 22:05:36 -------- d-----w- C:\Users\marina\AppData\Local\{D596DBB8-6166-4F26-A3CC-97BA84205D87} 2012-02-19 10:04:58 -------- d-----w- C:\Users\marina\AppData\Local\{CE09F457-4120-4A65-A4CA-1330AD011899} 2012-02-19 10:04:35 -------- d-----w- C:\Users\marina\AppData\Local\{587E0FB2-D6A6-4338-A830-DA39D588B73A} 2012-02-18 22:04:06 -------- d-----w- C:\Users\marina\AppData\Local\{BD466FBC-807A-4DD3-9FEE-011813B72995} 2012-02-18 22:03:43 -------- d-----w- C:\Users\marina\AppData\Local\{2618F9A5-29EA-4A4D-84C0-E1567B27660E} 2012-02-18 10:02:48 -------- d-----w- C:\Users\marina\AppData\Local\{126B6BC5-CA38-4B1B-93A4-963E230286A2} 2012-02-18 10:02:33 -------- d-----w- C:\Users\marina\AppData\Local\{AC00071A-AF7F-4B73-9953-97B1F8E36CDF} 2012-02-17 20:43:15 -------- d-----w- C:\Users\marina\AppData\Local\{C3ECA418-0C05-4FF2-8E0D-B129A50FC09B} 2012-02-17 08:42:38 -------- d-----w- C:\Users\marina\AppData\Local\{C3ADA18E-767E-43C9-A061-A2358AEE4C9E} 2012-02-16 20:36:22 -------- d-----w- C:\Users\marina\AppData\Local\{924BA057-6F9B-4A3A-A8B1-4D8C90EE447B} 2012-02-16 20:35:59 -------- d-----w- C:\Users\marina\AppData\Local\{4F9BB7C1-12ED-44B3-B6F0-DE4000F0CB80} 2012-02-16 08:35:11 -------- d-----w- C:\Users\marina\AppData\Local\{77C03757-398F-4C92-944D-7A8BE2F52026} 2012-02-16 08:34:57 -------- d-----w- C:\Users\marina\AppData\Local\{052B150C-50F3-4941-B5FE-72B1518C4B10} 2012-02-15 12:20:37 -------- d-----w- C:\Users\marina\AppData\Local\{74F3AED9-B0F5-4602-B279-BCDAD2BC8E48} 2012-02-15 08:30:29 509952 ----a-w- C:\Windows\System32\ntshrui.dll 2012-02-15 08:30:29 442880 ----a-w- C:\Windows\SysWow64\ntshrui.dll 2012-02-15 08:30:28 515584 ----a-w- C:\Windows\System32\timedate.cpl 2012-02-15 08:30:28 478720 ----a-w- C:\Windows\SysWow64\timedate.cpl 2012-02-15 08:30:27 3145728 ----a-w- C:\Windows\System32\win32k.sys 2012-02-15 08:30:25 498688 ----a-w- C:\Windows\System32\drivers\afd.sys 2012-02-15 08:30:21 690688 ----a-w- C:\Windows\SysWow64\msvcrt.dll 2012-02-15 08:30:21 634880 ----a-w- C:\Windows\System32\msvcrt.dll 2012-02-15 00:19:59 -------- d-----w- C:\Users\marina\AppData\Local\{3BB23024-0975-41F4-984D-02144E1C502E} 2012-02-14 12:19:20 -------- d-----w- C:\Users\marina\AppData\Local\{B724E541-12D0-4293-9234-3F8811FA1436} 2012-02-14 07:24:00 -------- d-----w- C:\ProgramData\{A8DA1505-E615-42BB-BB77-74D5CC91FE7E} 2012-02-14 00:18:20 -------- d-----w- C:\Users\marina\AppData\Local\{D70CBE41-0C86-4C65-B9B0-90EBB3656462} 2012-02-14 00:17:51 -------- d-----w- C:\Users\marina\AppData\Local\{2DF0ACF9-7C36-4BFC-AB1A-F50144FD263A} 2012-02-13 18:22:30 476904 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll 2012-02-13 12:17:20 -------- d-----w- C:\Users\marina\AppData\Local\{78709EDC-D9DF-4FAA-B978-4F0C8EECA182} 2012-02-12 23:46:13 -------- d-----w- C:\Users\marina\AppData\Local\{01E5DAFD-20A9-41A8-8CEB-39D71ADEB301} 2012-02-12 11:45:25 -------- d-----w- C:\Users\marina\AppData\Local\{0DBEC31D-3AD8-4ACF-9125-35026BEEA5FF} 2012-02-11 23:44:44 -------- d-----w- C:\Users\marina\AppData\Local\{03A3DD3A-381D-4766-B47F-963AC65A6073} 2012-02-11 11:44:06 -------- d-----w- C:\Users\marina\AppData\Local\{05DAA6DF-7F93-4CFF-9738-2CA0C9D0F4F1} 2012-02-10 23:43:28 -------- d-----w- C:\Users\marina\AppData\Local\{995C33D3-81ED-4CE6-BDD1-808493D106FE} 2012-02-10 11:42:50 -------- d-----w- C:\Users\marina\AppData\Local\{4AE3DEC7-9062-4007-A279-B66B3E8730FF} 2012-02-10 11:42:27 -------- d-----w- C:\Users\marina\AppData\Local\{3A212164-740A-4E05-917B-A7911CB7F5B3} 2012-02-09 23:41:58 -------- d-----w- C:\Users\marina\AppData\Local\{D0F2561A-ABB6-49FE-AD44-CCFEE1776D1E} 2012-02-09 23:41:35 -------- d-----w- C:\Users\marina\AppData\Local\{820FF5C9-CAD9-4878-916E-9A9693222499} 2012-02-09 11:41:03 -------- d-----w- C:\Users\marina\AppData\Local\{46BB1FD4-FA32-4874-8611-9F03C8ADD4B1} 2012-02-09 11:40:48 -------- d-----w- C:\Users\marina\AppData\Local\{522FD6FD-35B5-4EFA-8956-3EDBF4FC889B} 2012-02-08 23:20:59 -------- d-----w- C:\Users\marina\AppData\Local\{A1515CB7-60EC-4EBE-B810-ACDC8335B1C4} 2012-02-08 11:20:20 -------- d-----w- C:\Users\marina\AppData\Local\{F5B578C9-5CD3-4634-BD10-1748A17622E3} 2012-02-08 11:19:57 -------- d-----w- C:\Users\marina\AppData\Local\{844A91F3-4EAC-4F93-AB07-90FD02E213DC} 2012-02-07 23:19:39 -------- d-----w- C:\Users\marina\AppData\Local\{E311FC56-9106-431B-ABBF-541F55441850} 2012-02-07 23:19:38 -------- d-----w- C:\Users\marina\AppData\Local\{ED473BA8-D36B-4CC6-AF40-E7E825D5E9E0} 2012-02-07 11:14:57 -------- d-----w- C:\Users\marina\AppData\Local\{2F574A1E-401A-4DC7-8152-AFCB215E36BE} 2012-02-06 23:14:21 -------- d-----w- C:\Users\marina\AppData\Local\{F11D66AB-3D23-4C4F-AAE6-2CDE923A2BB4} 2012-02-06 11:13:56 -------- d-----w- C:\Users\marina\AppData\Local\{413950EE-612C-4232-9FE2-54DAD651D1BC} 2012-02-05 23:04:19 -------- d-----w- C:\Users\marina\AppData\Local\{EC815D95-A1D6-4FB4-8621-5720BC3965F3} 2012-02-05 11:03:53 -------- d-----w- C:\Users\marina\AppData\Local\{B4A3F3B2-0DEB-429E-A68B-21657163FA17} 2012-02-04 23:03:17 -------- d-----w- C:\Users\marina\AppData\Local\{72C8D4C3-737F-48F8-BBC9-C124517ABFEC} 2012-02-04 11:02:40 -------- d-----w- C:\Users\marina\AppData\Local\{21DED89F-1A40-4A58-A0E2-3C12C91921A8} 2012-02-03 23:02:02 -------- d-----w- C:\Users\marina\AppData\Local\{D9BB0D6C-88D8-4667-A835-8B12002AB044} 2012-02-03 11:01:25 -------- d-----w- C:\Users\marina\AppData\Local\{DAE1B859-76F7-49A2-B171-7F77C912D2DC} 2012-02-02 22:15:39 -------- d-----w- C:\Users\marina\AppData\Local\{A08348E7-39C5-4B5A-83F3-FE03786D12A3} 2012-02-02 10:17:37 -------- d-----w- C:\Program Files\iTunes 2012-02-02 10:14:57 -------- d-----w- C:\Users\marina\AppData\Local\{38D86300-CED2-4D9E-B700-48EE7B230496} 2012-02-02 10:14:31 -------- d-----w- C:\Users\marina\AppData\Local\{7ADF098C-749A-4355-BBB2-89940D6641E5} 2012-02-02 10:08:43 -------- d-----w- C:\Program Files\Bonjour 2012-02-02 10:08:43 -------- d-----w- C:\Program Files (x86)\Bonjour 2012-02-02 02:37:00 120368 ----a-w- C:\Windows\SysWow64\ezuninst.exe 2012-02-02 02:37:00 117808 ----a-w- C:\Windows\SysWow64\ezshellstart.exe 2012-02-01 22:14:01 -------- d-----w- C:\Users\marina\AppData\Local\{960D9650-F51E-4D72-BEFC-87632EED221A} 2012-02-01 10:13:20 -------- d-----w- C:\Users\marina\AppData\Local\{9DE140E0-297F-4FBD-A374-A23F604D51D3} 2012-02-01 10:12:56 -------- d-----w- C:\Users\marina\AppData\Local\{7B3F2776-4D10-4B94-A3A7-A66F73565F63} 2012-01-31 22:13:17 -------- d-----w- C:\Users\marina\AppData\Local\WiredRed 2012-01-31 22:12:37 -------- d-----w- C:\Users\marina\AppData\Local\{1C8565F4-D7F5-45C3-A854-ADBD047AF93D} 2012-01-31 22:12:36 -------- d-----w- C:\Users\marina\AppData\Local\{45514A8E-1666-445B-AB59-B94A6B1EEB21} 2012-01-31 12:52:20 738936 ----a-w- C:\Windows\System32\drivers\NISx64\1305000.091\srtsp64.sys 2012-01-31 12:52:20 451192 ----a-r- C:\Windows\System32\drivers\NISx64\1305000.091\symds64.sys 2012-01-31 12:52:20 405624 ----a-w- C:\Windows\System32\drivers\NISx64\1305000.091\symnets.sys 2012-01-31 12:52:20 37496 ----a-w- C:\Windows\System32\drivers\NISx64\1305000.091\srtspx64.sys 2012-01-31 12:52:20 190072 ----a-w- C:\Windows\System32\drivers\NISx64\1305000.091\ironx64.sys 2012-01-31 12:52:20 1092728 ----a-w- C:\Windows\System32\drivers\NISx64\1305000.091\symefa64.sys 2012-01-31 12:52:19 167048 ----a-w- C:\Windows\System32\drivers\NISx64\1305000.091\ccsetx64.sys 2012-01-31 12:52:04 -------- d-----w- C:\Windows\System32\drivers\NISx64\1305000.091 2012-01-31 10:12:09 -------- d-----w- C:\Users\marina\AppData\Local\{CE0C35F1-DC5D-4FA3-A1F5-2F652B6631D9} 2012-01-30 22:11:30 -------- d-----w- C:\Users\marina\AppData\Local\{DB1F1FBB-08BB-483D-BA17-96358785683C} 2012-01-30 10:10:54 -------- d-----w- C:\Users\marina\AppData\Local\{55263DC9-BDC6-40F4-9C9B-6B4998AF84A2} 2012-01-29 22:10:17 -------- d-----w- C:\Users\marina\AppData\Local\{2EF1D81D-ADE2-469F-84EC-EE9BD5A71825} 2012-01-29 10:09:41 -------- d-----w- C:\Users\marina\AppData\Local\{A1EB882C-65CE-403B-BB40-45048E796CB6} 2012-01-28 21:26:45 -------- d-----w- C:\Users\marina\AppData\Local\{E4CC6B2D-86DD-4570-9292-89EAB488CFFD} 2012-01-28 09:26:09 -------- d-----w- C:\Users\marina\AppData\Local\{66588035-62A9-4C49-970B-F5D68FD54D62} . ==================== Find3M ==================== . 2012-02-25 21:15:15 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll 2012-02-07 11:43:54 60 ----a-w- C:\Windows\wpd99.drv 2012-01-31 12:52:30 175736 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS 2012-01-22 21:13:10 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-12-14 07:11:03 2308096 ----a-w- C:\Windows\System32\jscript9.dll 2011-12-14 07:04:30 1390080 ----a-w- C:\Windows\System32\wininet.dll 2011-12-14 07:03:38 1493504 ----a-w- C:\Windows\System32\inetcpl.cpl 2011-12-14 06:57:28 2382848 ----a-w- C:\Windows\System32\mshtml.tlb 2011-12-14 03:04:54 1798656 ----a-w- C:\Windows\SysWow64\jscript9.dll 2011-12-14 02:57:18 1127424 ----a-w- C:\Windows\SysWow64\wininet.dll 2011-12-14 02:56:58 1427456 ----a-w- C:\Windows\SysWow64\inetcpl.cpl 2011-12-14 02:50:04 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb 2011-12-10 15:24:08 23152 ----a-w- C:\Windows\System32\drivers\mbam.sys 2011-12-01 08:18:06 499712 ----a-w- C:\Windows\SysWow64\msvcp71.dll 2011-12-01 08:18:06 348160 ----a-w- C:\Windows\SysWow64\msvcr71.dll . ============= FINISH: 3:50:48.48 =============== And the attach . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 01/04/2010 11:52:49 System Uptime: 27/02/2012 00:17:23 (3 hours ago) . Motherboard: Hewlett-Packard | | 3069 Processor: Pentium(R) Dual-Core CPU T4300 2.10GHz | CPU | 2100/800mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 285 GiB total, 161.411 GiB free. D: is FIXED (NTFS) - 12 GiB total, 2.048 GiB free. E: is CDROM (CDFS) . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP229: 13/02/2012 18:20:55 - Installed Java(TM) 6 Update 30 RP230: 14/02/2012 07:24:16 - Installed HP Support Assistant RP231: 14/02/2012 07:28:34 - Windows Modules Installer RP232: 14/02/2012 07:29:44 - Windows Modules Installer RP233: 14/02/2012 18:08:47 - HPSF Applying updates RP234: 16/02/2012 08:35:27 - Windows Update RP235: 16/02/2012 16:30:43 - Windows Update RP236: 18/02/2012 16:48:22 - Windows Update RP237: 25/02/2012 21:02:52 - Installed Java(TM) 6 Update 31 . ==== Installed Programs ====================== . 7-Zip 9.20 Acrobat.com Adobe AIR Adobe Flash Player 11 ActiveX Adobe Reader X (10.1.2) Adobe Shockwave Player Akamai NetSession Interface Akamai NetSession Interface Service Apple Application Support Apple Software Update Babylon toolbar on IE BBC iPlayer Desktop Bing Bar Bing Bar Platform Camera Access Library Camera Support Core Library Camera Window DS Camera Window DVC Camera Window MC Canon Camera Access Library Canon Camera Support Core Library Canon Camera Window DC_DV 5 for ZoomBrowser EX Canon Camera Window DC_DV 6 for ZoomBrowser EX Canon Camera Window DSLR 5 for ZoomBrowser EX Canon Camera Window MC 6 for ZoomBrowser EX CANON iMAGE GATEWAY Task CANON iMAGE GATEWAY Task for ZoomBrowser EX Canon Internet Library for ZoomBrowser EX Canon MovieEdit Task for ZoomBrowser EX Canon PhotoRecord Canon RAW Image Task for ZoomBrowser EX Canon Utilities PhotoStitch 3.1 Canon ZoomBrowser EX (E) Compatibility Pack for the 2007 Office system CyberLink DVD Suite CyberLink MediaShow CyberLink PowerDVD 8 CyberLink YouCam D3DX10 Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition Dropbox Dudeism.com Relaxer Easy Burner EndNote ERUNT 1.1j ESET Online Scanner v3 Facemoods Toolbar FreeMind FYZip 1.00 GamePlayLabs Plugin Google Chrome Google Update Helper Hewlett-Packard ACLM.NET v1.1.2.0 High-Definition Video Playback HP Advisor HP Customer Experience Enhancements HP Games HP Quick Launch Buttons HP Setup HP Support Assistant HP Update HP User Guides 0148 HP Wireless Assistant Huawei modem IDT Audio Internet Library ISI ResearchSoft - Export Helper Java Auto Updater Java(TM) 6 Update 31 Junk Mail filter update KeePass Password Safe 1.19b LabelPrint LightScribe System Software ListenArabic Toolbar Magic Desktop Malwarebytes Anti-Malware version 1.60.1.1000 McAfee Security Scan Plus Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (English) 2010 Microsoft Office Access Setup Metadata MUI (English) 2010 Microsoft Office Click-to-Run 2010 Microsoft Office Excel MUI (English) 2010 Microsoft Office Home and Business 2010 - English Microsoft Office Home and Student 2010 Microsoft Office Live Add-in 1.5 Microsoft Office OneNote MUI (English) 2010 Microsoft Office Outlook MUI (English) 2010 Microsoft Office PowerPoint MUI (English) 2010 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (Spanish) 2010 Microsoft Office Proofing (English) 2010 Microsoft Office Publisher MUI (English) 2010 Microsoft Office Shared MUI (English) 2010 Microsoft Office Shared Setup Metadata MUI (English) 2010 Microsoft Office Single Image 2010 Microsoft Office Suite Activation Assistant Microsoft Office Word MUI (English) 2010 Microsoft Search Enhancement Pack Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Works Moozy Move Media Player MovieEdit Task Mozilla Firefox 10.0.2 (x86 en-US) MSVCRT MSVCRT_amd64 muvee Reveal Nero 11 Nero 11 Disc Menus Basic Nero 11 Effects Basic Nero 11 Image Samples Nero 11 Kwik Themes Basic Nero 11 PiP Effects Basic Nero Audio Pack 1 Nero BackItUp 11 Nero BackItUp 11 Help (CHM) Nero Burning ROM 11 Nero Burning ROM 11 Help (CHM) Nero ControlCenter 11 Nero ControlCenter 11 Help (CHM) Nero Core Components 11 Nero CoverDesigner 11 Nero CoverDesigner 11 Help (CHM) Nero Express 11 Nero Express 11 Help (CHM) Nero Kwik Media Nero Kwik Media Help (CHM) Nero Recode 11 Nero Recode 11 Help (CHM) Nero RescueAgent 11 Nero RescueAgent 11 Help (CHM) Nero SoundTrax 11 Nero SoundTrax 11 Help (CHM) Nero Update Nero Video 11 Nero Video 11 Help (CHM) Nero WaveEditor 11 Nero WaveEditor 11 Help (CHM) nero.prerequisites.msi Norton Internet Security Norton Online Backup Pdf995 PhotoStitch Power2Go PowerDirector PriceGong 2.5.2 QLBCASL QuickTime RAW Image Task 2.2 RealNetworks - Microsoft Visual C++ 2008 Runtime RealPlayer Realtek 8136 8168 8169 Ethernet Driver Realtek USB 2.0 Card Reader RealUpgrade 1.1 Recovery Manager Safari SecureW2 Enterprise Client 3.4.6 Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft Office 2010 (KB2553091) Security Update for Microsoft Office 2010 (KB2553096) Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition Security Update for Microsoft SharePoint Workspace 2010 (KB2566445) Security Update for Microsoft Visio Viewer 2010 (KB2597170) 32-Bit Edition Signature995 Skype™ 5.5 Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Excel 2010 (KB2553439) 32-Bit Edition Update for Microsoft Office 2010 (KB2494150) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2553385) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2597091) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2553323) 32-Bit Edition Update for Microsoft Outlook Social Connector (KB2583935) Veoh Giraffic Video Accelerator Veoh Web Player welcome Windows iLivid Toolbar Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Mail Windows Live Messenger Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live Sync Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources WOT for Internet Explorer . ==== Event Viewer Messages From Past Week ======== . 27/02/2012 03:44:51, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the NIS service. 26/02/2012 23:18:35, Error: Service Control Manager [7022] - The Windows Update service hung on starting. 26/02/2012 23:13:58, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the HP Support Assistant Service service to connect. 26/02/2012 23:13:58, Error: Service Control Manager [7000] - The HP Support Assistant Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 26/02/2012 06:05:24, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the iphlpsvc service. 26/02/2012 06:04:54, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the RasMan service. 26/02/2012 00:31:37, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Presentation Foundation Font Cache 3.0.0.0 service to connect. 26/02/2012 00:31:37, Error: Service Control Manager [7000] - The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 26/02/2012 00:27:43, Error: Service Control Manager [7001] - The Client Virtualization Handler service depends on the Application Virtualization Client service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion. 26/02/2012 00:27:40, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Application Virtualization Client service to connect. 26/02/2012 00:27:40, Error: Service Control Manager [7000] - The Application Virtualization Client service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 24/02/2012 09:46:38, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Error Reporting Service service to connect. 24/02/2012 04:25:31, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Browser service. 24/02/2012 04:25:31, Error: Service Control Manager [7000] - The Computer Browser service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. . ==== End Of File =========================== One thing that might be of significance is that I did not disable Norton Internet security while I was running the DDSs. If you think this will affect the result please let me know and I will do it again with the Norton disabled Download OTL to your desktop. * Open OTL * Copy and Paste the following text in the codebox into the Custom Scans/Fixes window. Code: [Select]:OTL BHO: Shopping Assistant Plugin: {1631550f-191d-4826-b069-d9439253d926} - C:\Program Files (x86)\PriceGong\2.5.2\PriceGongIE.dll BHO: Babylon toolbar helper: {2eecd738-5844-4a99-b4b6-146bf802613b} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll BHO: CescrtHlpr Object: {64182481-4f71-486b-a045-b233bd0da8fc} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarTlbr.dll TB: facemoods Toolbar: {db4e9724-f518-4dfd-9c7c-78b52103cab9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll mRun: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe" /md I BHO-X64: PriceGong - No File BHO-X64: AcroIEHelperStub - No File BHO-X64: Babylon toolbar helper: {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll BHO-X64: Babylon toolbar helper - No File BHO-X64: CescrtHlpr Object: {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll BHO-X64: facemoods Helper - No File BHO-X64: Search Helper - No File BHO-X64: URLRedirectionBHO - No File BHO-X64: TBLA06779 - No File TB-X64: facemoods Toolbar: {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll mRun-x64: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe" /md I :folders C:\Program Files (x86)\PriceGong C:\Program Files (x86)\BabylonToolbar\BabylonToolbar C:\Program Files (x86)\facemoods.com\facemoods :COMMANDS [resethosts] [purity] [start explorer] * Click Run Fix * OTLI2 may ask to reboot the machine. Please do so if asked. * Click OK * A report will open. Copy and Paste that report in your next reply. ************************************************************ Download Combofix from any of the links below, and save it to your desktop. Link 1 Link 2 Link 3 To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.
Click I Agree to start the program. ComboFix will then extract the necessary files and you will see this: As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7 It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. If you did not have it installed, you will see the prompt below. Choose YES. Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console. **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: Click on Yes, to continue scanning for malware. When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt). Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so. Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.Still problem with the script. While I was trying to talk on Skype the following appeared A script on this page may be busy, or it may have stopped responding. You can stop the script now, or you can continue to see if the script will complete. Script: http://mail.yimg.com/zz/combo?nq/3909/yui/yui-min.js&nq/3909/oop/oop-min.js&nq/3909/dom/dom-min.js&nq/3909/event/event-min.js&nq/3909/event-custom/event-custom-min.js&nq/3909/base/base-base-min.js&nq/3909/plugin/plugin-min.js&nq/3909/pluginhost/pluginhost-min.js&nq/3909/node/node-min.js&nq/3909/attribute/attribute-min.js&nq/3909/json/json-min.js&nq/3909/intl/intl-min.js&nq/3909/datatype/lang/datatype-date.js&nq/3909/datatype/datatype-date-min.js&nq/3909/datatype/datatype-xml-min.js&nq/3909/cookie/cookie-min.js&nq/3909/async-queue/async-queue-min.js&nq/3909/collection/array-extras-min.js&nq/3909/querystring/querystring-parse-simple-min.js&nq/3909/querystring/querystring-stringify-simple-min.js&nq/3909/loader/loader-min.js:13OTL did not ask me to reboot. This is the log. Is there something wrong? I will try to do it once again ========== OTL ========== Error: Unable to interpret <:folders> in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! ========== COMMANDS ========== C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.33.2 log created on 02272012_224127 I tried again. Same message. Hope is fineThat's ok. Please uninstall these programs Babylon toolbar on IE Facemoods Toolbar PriceGong 2.5.2 They are malicious. Then, please proceed with ComboFix. Thanks. I deleted the programs you told me and run ComboFix (it took several attempts, quite some time and a reboot) When I tried to open any of the different browsers so that I could send you the log the following message appeared "c:\Program Files (x86) Mozilla Firefox/firefox.exe Illegal Operation attempted on a registry item that has been marked to delete" The same with IE and Google Chrone Fortunately it worked OK after another reboot but I just thought I will tell you anyway Also: while I have been trying to write this the following message appeared "A script on this page may be busy, or it may have stopped responding. You can stop the script now, or you can continue to see if the script will complete. Script: http://d3lvr7yuk4uaui.cloudfront.net/items/it/js/itn.js:46" I get those messages daily sometimes several times. I am tired of them. Any suggestions as to what to do?And the Combo Fix log ComboFix 12-02-27.02 - marina 28/02/2012 20:50:35.10.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.3999.1950 [GMT 0:00] Running from: c:\users\marina\Desktop\ComboFix.exe AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\boost_interprocess\20120228140443.359599 c:\programdata\boost_interprocess\20120228140443.359599\Nobu64AgentService c:\programdata\boost_interprocess\20120228140443.359599\Nobu64TrayIcon . . ((((((((((((((((((((((((( Files Created from 2012-01-28 to 2012-02-28 ))))))))))))))))))))))))))))))) . . 2012-02-28 21:18 . 2012-02-28 21:18 -------- d-----w- c:\users\Public\AppData\Local\temp 2012-02-28 21:18 . 2012-02-28 21:18 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-02-27 22:41 . 2012-02-27 22:41 -------- d-----w- C:\_OTL 2012-02-26 06:42 . 2012-02-26 06:42 -------- d-----w- c:\users\marina\AppData\Roaming\SUPERAntiSpyware.com 2012-02-26 06:41 . 2012-02-26 06:44 -------- d-----w- c:\program files\SUPERAntiSpyware 2012-02-26 06:41 . 2012-02-26 06:41 -------- d-----w- c:\programdata\SUPERAntiSpyware.com 2012-02-25 21:17 . 2012-02-25 21:17 -------- d-----w- c:\program files (x86)\Common Files\Java 2012-02-15 08:30 . 2012-01-04 10:44 509952 ----a-w- c:\windows\system32\ntshrui.dll 2012-02-15 08:30 . 2012-01-04 08:58 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll 2012-02-15 08:30 . 2011-12-30 06:26 515584 ----a-w- c:\windows\system32\timedate.cpl 2012-02-15 08:30 . 2011-12-30 05:27 478720 ----a-w- c:\windows\SysWow64\timedate.cpl 2012-02-15 08:30 . 2012-01-14 04:06 3145728 ----a-w- c:\windows\system32\win32k.sys 2012-02-15 08:30 . 2011-12-28 03:59 498688 ----a-w- c:\windows\system32\drivers\afd.sys 2012-02-15 08:30 . 2011-12-16 08:46 634880 ----a-w- c:\windows\system32\msvcrt.dll 2012-02-15 08:30 . 2011-12-16 07:52 690688 ----a-w- c:\windows\SysWow64\msvcrt.dll 2012-02-14 07:24 . 2012-02-14 07:24 -------- d-----w- c:\programdata\{A8DA1505-E615-42BB-BB77-74D5CC91FE7E} 2012-02-13 18:22 . 2012-02-25 21:15 476904 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll 2012-02-02 10:12 . 2012-02-02 10:12 159744 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll 2012-02-02 10:08 . 2012-02-02 10:08 -------- d-----w- c:\program files\Bonjour 2012-02-02 10:08 . 2012-02-02 10:08 -------- d-----w- c:\program files (x86)\Bonjour 2012-02-02 02:37 . 2012-02-02 02:37 120368 ----a-w- c:\windows\SysWow64\ezuninst.exe 2012-02-02 02:37 . 2012-02-02 02:37 117808 ----a-w- c:\windows\SysWow64\ezshellstart.exe 2012-01-31 22:13 . 2012-02-22 20:20 -------- d-----w- c:\users\marina\AppData\Local\WiredRed 2012-01-31 12:52 . 2012-02-01 00:44 -------- d-----w- c:\windows\system32\drivers\NISx64\1305000.091 . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-02-25 21:15 . 2010-05-02 11:55 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll 2012-01-31 12:52 . 2011-05-12 15:12 175736 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS 2012-01-22 21:13 . 2011-06-12 05:22 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-12-10 15:24 . 2011-05-04 13:55 23152 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-12-01 08:18 . 2011-12-01 08:18 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll 2011-12-01 08:18 . 2011-12-01 08:18 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{F569CF08-EDF6-4FAB-8C8A-EEC184358372}"= "c:\program files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll" [2009-06-02 2695168] . [HKEY_CLASSES_ROOT\clsid\{f569cf08-edf6-4fab-8c8a-eec184358372}] [HKEY_CLASSES_ROOT\TBLA06779.TBLA06779.3] [HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}] [HKEY_CLASSES_ROOT\TBLA06779.TBLA06779] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] ="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] ="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] ="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] ="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2011-03-04 2741616] "HPADVISOR"="c:\program files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2010-06-30 1689144] "VeohPlugin"="c:\program files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2011-08-25 2816328] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 17351304] "Akamai NetSession Interface"="c:\users\marina\AppData\Local\Akamai\netsession_win.exe" [2012-02-02 3329824] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "QlbCtrl.exe"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2010-02-25 323640] "Easybits Recovery"="c:\program files (x86)\EasyBits For Kids\ezRecover.exe" [2009-09-02 60464] "WirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2010-03-23 500792] "SecureW2 Tray"="c:\program files (x86)\SecureW2\sw2_tray.exe" [2010-07-28 200584] "AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-11-02 59240] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "NBAgent"="c:\program files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" [2011-09-20 1493288] "Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2011-10-12 3151000] "TkBellExe"="c:\program files (x86)\real\realplayer\update\realsched.exe" [2011-12-01 296056] "HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-01-16 421736] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-31 460872] . c:\users\marina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ BBC iPlayer Desktop.lnk - [N/A] Dropbox.lnk - c:\users\marina\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-2-14 24246216] ERUNT AutoBackup.lnk - c:\program files (x86)\ERUNT\AUTOBACK.EXE [2005-10-20 38912] fliptoast.lnk - c:\program files (x86)\Fliptoast\fliptoast.exe [N/A] OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVH.EXE [2012-1-4 3208032] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "HideFastUserSwitching"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) . [hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks] . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] ="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] ="Driver" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-31 136176] R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-09 86072] R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-02-25 227896] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-31 136176] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys S0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\DRIVERS\NBVol.sys S0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\DRIVERS\NBVolUp.sys S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1305000.091\SYMDS64.SYS S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1305000.091\SYMEFA64.SYS S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\BASHDefs\20120215.001\BHDrvx64.sys [2012-02-07 1157240] S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NISx64\1305000.091\ccSetx64.sys S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\IPSDefs\20120225.004\IDSvia64.sys [2011-12-15 488568] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1305000.091\Ironx64.SYS S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1305000.091\SYMNETS.SYS S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2010-06-30 89600] S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624] S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2009-07-14 27136] S2 Giraffic;Veoh Giraffic Video Accelerator;c:\program files (x86)\Giraffic\Veoh_GirafficWatchdog.exe [2012-01-22 2230416] S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-28 94264] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-31 652360] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-09-23 641832] S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe [2011-11-30 138248] S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-02-07 138360] S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] Akamai REG_MULTI_SZ Akamai . HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs ezSharedSvc . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2011-03-04 11:29 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe . Contents of the 'Scheduled Tasks' folder . 2012-02-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-31 15:52] . 2012-02-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-31 15:52] . 2012-02-26 c:\windows\Tasks\HPCeeScheduleFormarina.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-13 22:15] . . --------- x86-64 ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] ="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 ----a-w- c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] ="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 ----a-w- c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] ="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 ----a-w- c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] ="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 ----a-w- c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-10 165912] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-10 387608] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-10 365592] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-06-30 487424] . ------- Supplementary Scan ------- . uStart Page = hxxp://www.alwaraq.net/Core/index.jsp?option=1 uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = 127.0.0.1:9421;*.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105 IE: {{F569CF08-EDF6-4FAB-8C8A-EEC184358372} - {F569CF08-EDF6-4FAB-8C8A-EEC184358372} - c:\program files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll TCP: DhcpNameServer = 193.63.73.32 FF - ProfilePath - c:\users\marina\AppData\Roaming\Mozilla\Firefox\Profiles\2y9b2iki.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=3&q={searchTerms} FF - prefs.js: browser.startup.homepage - hxxp://www.soas.ac.uk/ FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=2&q= FF - prefs.js: network.proxy.gopher - FF - prefs.js: network.proxy.type - 4 FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe Toolbar-10 - (no file) WebBrowser-{F569CF08-EDF6-4FAB-8C8A-EEC184358372} - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe AddRemove-Searchqu 406 MediaBar - c:\program files (x86)\Windows iLivid Toolbar\uninstall.exe AddRemove-{6F44AF95-3CDE-4513-AD3F-6D45F17BF324} - c:\program files (x86)\InstallShield Installation Information\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}\setup.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\NIS] "ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\19.5.0.145\diMaster.dll\" /prefetch:1" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\Akamai] "ServiceDll"="c:\program files (x86)\common files\akamai/netsession_win_7de0ed9.dll" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] Denied: (A 2) (Everyone) ="FlashBroker" "LocalizedString"="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] Denied: (A 2) (Everyone) ="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] ="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] ="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] ="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] ="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] ="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] Denied: (A 2) (Everyone) ="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] ="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] ="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] ="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] ="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] Denied: (A 2) (Everyone) ="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] ="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] Denied: (Full) (Everyone) . ------------------------ Other Running Processes ------------------------ . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe c:\program files (x86)\CyberLink\Shared files\RichVideo.exe c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files (x86)\Giraffic\Veoh_Giraffic.exe c:\program files (x86)\Canon\CAL\CALMAIN.exe . ************************************************************************** . Completion time: 2012-02-28 21:33:45 - machine was rebooted ComboFix-quarantined-files.txt 2012-02-28 21:33 . Pre-Run: 174,577,553,408 bytes free Post-Run: 177,564,450,816 bytes free . - - End Of File - - FE017AF54B38363089461AA075AD570E |
|
| 380. |
Solve : Gmail hack, returned and....? |
|
Answer» I was wondering if you would mind helping me (I am very anxious for my problem) Today on a computer (without any especial AntiVirus) which is in a public place for everyone I checked my Gmail account by IE and I received a bunch of strange emails. by opening of one of them I was diverted to another person's email and then when I tried to sign in with my username, gmail said you are trying to use your old password. you password has been changed for 33 days. So I was frustrated because even I did not know the security questions; I could not sign in for around 2-3 hours andIs that what happened? A. Do not rely on public terminals. A mean kind of malicious software called "DNS changer**" might have been present. B. If you can sign in later on your own PC, the account was not hacked & the password not changed by some other person. **DNS Changer often picks on Google, but it does not hurt Google directly, it victimizes the user who want to use Google. Tue infection is local to the PC the user has in front of him. This may be of some interest. About three months ago FBI tackles DNSChanger malware scam Hello Thank you very much for answering and giving some information. So do you believe that by clicking on that email my DNS changed and I was diverted to another person's email address? Yes the story is exactly the same thing I described. When I opened (From a public computer which did not any especially Anti viruses) one of the strange emails , I had received, I was directed to another person's email address and after that when I tried to sign in, Google said "You are trying to use your old password. Your password has been changed for 33 days" and I could not sign in to my account for 2-3 hours and even after that I tried from my PC which has an ESET Smart Security and again I could not sign in. However after awhile again I tried and finally my password worked; once I entered my account, I changed my password and I got an email from Gmail saying that my password has been changed 3 times during that day (One when I was hacked and one when I changed by myself and one in between). So now my question is, if it had been a DNS changer, I would have been able to sign in to my account (the first times that I tried) when I tried it from my personal PC (because this one was not infected). Right? So it could not be a DNS changer. Am I right? My another question is how come my password after around 4 hours changed to the first password? And finally My LAST question: Could you please let me know what you think had happened? Was I hacked? Is my Gmail account safe now? Can I still use it? Was it dangerous? ..... Your help is totally appreciated.The problem described in the article only infects the one computer. Nothing is done to Google Gmail. This problem has been widely reported. And nothing GOES into n your home computer. The scam gives people the impression that something is wrong and asks for your password. But you changed your password. So you are out of danger. Be sure and update your security questions.Oh great! Thank you so much So only the public computer was infected and my Gmail account is safe? So why even at home I could not log in with my password for around 1-2 hours and then it worked? Also I had two other emails saying that my Gmail password was changed in between (between that time I was infected and the time I accessed to my email)?! Also, could you please let me know based on what you believe is my information ( I mean emails I received or sent) read by a third party? I do appreciate your help You get locked out of our account when there are a number of attempts to get in. That is a safety feature. It is a good idea from time to time to change our password and review your security questions. Others recommend use of acrostic phrase password. Numbers exceptional. Example: My Bad Dog Has 12 Red Fleas. would be: MBDH12RF Of cause, you have to use another one. That one is mine. Do not use qwerty Which is so obvious. I stopped using it. |
|
| 381. |
Solve : Access is denied.? |
|
Answer» The problem I'm having pertains to a virus/malware problem, I guess. I used the procedure listed here http://tinyurl.com/5sjq6 by myself. I don't have the patience for forums, sadly. The efforts were in vain, end I eventually ended up messing up my hosts file like an idiot. I reversed it by using a system restore point, but now I can't install any PROGRAMS. The only "error" I RECEIVE is a "Access is Denied." However, I'm sole user of this system (so I use an administrator account), went as FAR as TRYING to take "ownership" of my ENTIRE C:\* Drive. But, the problem persists. |
|
| 382. |
Solve : Remove and Reinstall AVG? |
|
Answer» The AVG on my netbook suddenly doesn't work this morning. The TRAY icon doesn't show up, and when I click the Start Menu shortcut to the AVG User Interface, nothing happen. Same thing when I try to launch from the installed directory. download AVAST or AVIRA as they are better than AVG, not as many false possitives and they use less system resorces.I've been using AVG for more than 5 years without any major issue or infection. I didn't like AVAST because the scan will pause at every threat detected hence I cannot leave it running scan without attending to it. Never tried AVIRA. |
|
| 383. |
Solve : How do I use MSE to scan internal and external drives?? |
|
Answer» Hello everyone, Go into Setting and chose Advanced. Check the box for external devices. Hey Dave, I sent you a thank. I'm not sure if it went through? Anyway, thank you. I have another question for you below? I have AVG Tune UP, and I have CC Cleaner. Should I get rid one of them? Or both of them? Or keep them both? I have both in addition to MSE. If I get rid of them, do I need something in replace that would work with MSE without a conflict? My Internet should be back on shortly since a payment was made last week by mail. I could get tools once I'm online again, so I could get the names of some tools, and then download them when I'm online again. I am on an iPhone 4, but it's not the 4S with Siri, so I can't ask her. I am using my phone for the Internet right now. Lol. Quote I have AVG Tune UP, and I have CC Cleaner. Should I get rid one of them? Or both of them? Or keep them both?You can keep AVG Tune Up but don't run the Registry Cleaner for the reasons listed below. Not a problem with CCleaner. Registry cleaners are extremely powerful applications and their potential for harming your OS far outweighs any small potential for improving your computer's performance. There are a number of them available and some are more safe than others. Keep in mind that no two registry cleaners work entirely the same way. Each vendor uses different criteria as to what constitutes a "bad" entry. One cleaner may find entries on your SYSTEM that will not cause a problem when removed, another may not find the same entries, and still another may want to remove entries required for a program to work. Without research into what the registry entry selected for deletion is, a registry cleaner can end up being an automated method to cause problems with the registry. For routine use by those not familiar with the registry, the benefits to your computer are negligible while the potential risks are great. Further reading: XP Fixes Myth #1: Registry Cleaners Quote do I need something in replace that would work with MSE without a conflict?The only thing that will conflict with MSE is another AV program. |
|
| 384. |
Solve : what else do i need?? |
|
Answer» i have ESET NOD 32 (subscription) and ccleaner (the free one). i had xoft spy SE for a long time but i have let my subscription lapse. is that something i need STILL, or do i have enough security coverage? i RUN the ccleaner about twice a week and the ESET about every 2 weeks. i use this machine as a toy....games mostly and e-mails occasionally. what do you recommend for me?ccleaner has nothing to do with system security. |
|
| 385. |
Solve : Very basic question about securing my fresh old computer? |
|
Answer» This is probably a super basic question, but I hope that someone can answer for me. I'm about to reformat my PC and reinstall Vista, which means reinstalling everything. One thing I'm never quite certain about is what order to do everything in. When I finish installing the OS, it prompts me to go online and validate it and update it and all that, but I need to have an antivirus up and running before I do that, don't I?You can download a free AV from the list below and save it on a memory stick or DVD using another computer then install it on your computer. Then get your updates. You should have a good, updated AV, turn on Windows Defender and Windows firewall. If your doing on-line banking you should install a third-party firewall. Remember to only install one antivirus! 1) AVAST! Home Edition 2) AVG Free Edition 3) Avira AntiVir Personal 4) Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download 4-a) Microsoft Security Essentials for Windows XP 5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my DEFAULT search provider" and "Make Comodo Search my homepage" if you choose this one) 6) PC Tools AntiVirus Free Edition It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, SPAM, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Thanks again, SuperDave! Why doesn't every PC come with a set of instructions like this? I wish I knew this stuff years ago. This site is the best! You're welcome.Just signed up a few minutes ago & came about this thread. I noticed that with anti virus, you only mention AVG though I've seen also others. Is this what you really recommend? Do you have any feedbacks or review on AVAST? By the way, I'm using Windows 7. thank you. |
|
| 386. |
Solve : Hackers steal Norton Source Code - What do we do?? |
|
Answer» For those of us who have Norton Antivirus, what would be the best procedure in view of the recent theft of their source code? If we decide to download a different antivirus program, do we download it, GO off line, turn off Norton (or delete it), RUN the new program and then go back on line to get the updates for the new program? Of the free antivirus programs, which one(s) are the most effective? I am definitely paranoid when it COMES to security. Thank youWow, paranoid is right . |
|
| 387. |
Solve : Malware issue (logs here)? |
|
Answer» I accidentally clicked on some stupid link and have had a fun few hours, I can only use my computer if I consistantly close iexplorer that is being run in the background every minute or so. In short the malware removed by desktop, blocked task manager and cleared all menus on my computer. I could not update java, so if that matters I apologize. This will be the second time you guys help me, thank you in advance I really appreciate your programs/knowledge! R3 dump_wmimmc;dump_wmimmc;c:\program files (x86)\NCsoft\Lineage II\system\GameGuard\dump_wmimmc.sys R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-26 1124848] R3 vcd10bus;Virtual CD v10 Bus Enumerator;c:\windows\system32\DRIVERS\vcd10bus.sys R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe R3 X6va001;X6va001;c:\users\DAVIDC~1\AppData\Local\Temp\0019F35.tmp R4 Apache2.2;Apache2.2;c:\xampp\apache\bin\apache.exe [2008-01-17 24635] R4 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-12-18 155648] R4 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe [2008-02-01 65536] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672] S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-03-31 92160] S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2009-08-17 656624] S3 netr28ux;RT2870 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr28ux.sys S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys . . . --------- x86-64 ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-05-23 7833120] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-26 16327712] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-04-13 2399632] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ------- Supplementary Scan ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.ask.com?o=15179&l=dis mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 192.168.1.254 FF - ProfilePath - c:\users\David Crawford\AppData\Roaming\Mozilla\Firefox\Profiles\w41bhm11.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - www.google.com . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Toolbar-Locked - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe AddRemove-KingAgnostic's Minecraft 1.1.2_01 - c:\users\David Crawford\AppData\Roaming\Uninstal.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va001] "ImagePath"="\??\c:\users\DAVIDC~1\AppData\Local\Temp\0019F35.tmp" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-1420202529-2994384463-3620377272-1000\Software\SecuROM\License information*] "datasecu"=hex:ab,c1,18,de,39,40,5d,ca,5c,da,52,8e,98,99,1a,67,5a,1b,66,15,97, 13,8e,64,16,8a,5e,3f,e3,be,50,3f,cb,3d,6e,ae,6d,c5,65,75,b7,2b,0a,15,fd,a1,\ "rkeysecu"=hex:25,4f,b3,cc,e4,e2,cb,56,0d,50,05,5e,1b,f7,d9,c6 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] Denied: (A 2) (Everyone) ="FlashBroker" "LocalizedString"="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10w_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10w_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] Denied: (A 2) (Everyone) ="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] ="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] ="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] ="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] ="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] ="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] Denied: (A 2) (Everyone) ="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] ="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] ="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] ="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] ="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] Denied: (A 2) (Everyone) ="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] ="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] Denied: (Full) (Everyone) . ------------------------ Other Running Processes ------------------------ . c:\program files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe c:\program files (x86)\Dell Support Center\bin\sprtsvc.exe c:\program files (x86)\Internet Explorer\iexplore.exe c:\program files (x86)\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe c:\program files (x86)\Windows Live\Toolbar\wltuser.exe . ************************************************************************** . Completion time: 2011-10-28 12:37:26 - machine was rebooted ComboFix-quarantined-files.txt 2011-10-28 16:37 . Pre-Run: 806,115,491,840 bytes free Post-Run: 805,085,458,432 bytes free . - - End Of File - - AAE2156689C8FB6ED407442E9F018477Log should be fine. ESET Online Scan Please run a free online scan with the ESET Online Scanner
all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=7434ac6c61704f42b7b1f9b2749fb2da # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-10-30 06:13:57 # local_time=2011-10-30 02:13:57 (-0500, Eastern Daylight Time) # country="United States" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=768 16777215 100 0 0 0 0 0 # compatibility_mode=5893 16776573 100 94 0 71495178 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=268024 # found=4 # cleaned=4 # scan_time=3508 C:\Users\David Crawford\Desktop\Games\Cipsoft Project 0.3.5\Crying Damson.exe a variant of Win32/GameServer.AA application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\David Crawford\Desktop\Games\Cipsoft Project 0.3.5\OT\The Forgotten Server v0.2.7 MYSTIC Spirit console\The Forgotten Server.exe a variant of Win32/GameServer.AA application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Users\David Crawford\Desktop\Games\Cipsoft Project 0.3.5\OT\The Forgotten Server v0.2.7 Mystic Spirit GUI\The Forgotten Server.exe a variant of Win32/GameServer.AA application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Windows\InternetExplorer.exe probably a variant of Win32/Autorun.KYOHRBW worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C Havent checked to see if the problem is resolved, I will update tomorrow if necessary. Thank you for all the help so far, especially considering it was over the weekend!Update me on how it is running...It seems there is still something on my computer. I let iexplorer run itself to about 350 mb's and then it caused an error and a few popups came up. One mentioned a file with what looked like a virus name, and another mentioned something about creating something and access denied. The virus was in a "temp" folder, though I couldnt find it manually.Please download DrWeb-CureIt and save it to your Desktop. Do NOT perform a scan yet
If so, click it, then click the next icon right below and select Move incurable. (This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
I googled the link location and accessed the ftp server or whatever that was and am downloading this:"http://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe" file at 30 kb/s. If you know a better place to download this file from I would appreciate it.The report came up with nothing. Quote dds.scr;C:\Documents and Settings\David Crawford\Desktop;Trojan.MulDrop3.6866;;If this has any impact, the negative effects of it now are the constant running of IE in the background, searches being hijacked (and generally to blinkx.com), IE windows opening on my screen, and ads playing in the background. Please download aswMBR from here
Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives
aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software I havent clicked fix yetWe need to fix the infection found with aswMBR now
aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software I assume that isnt supposed to happen. |
|
| 388. |
Solve : exe.exe? |
|
Answer» I have downloaded 7 zip which is a "exe.exe" file. I have HEARD that files or softwares with "exe.exe" extensions are harmful. Is it true? If it so please let me KNOW any free SOFTWARE that unzip files and is without "exe.exe" extension.All Windows Applications are EXE files. Yes, but he WONDERS about it's filename which is also named "exe" (the same as the extension)begginer, why are you calling it a "7 zip" if it has the extension exe.exe? |
|
| 389. |
Solve : Errors running merged-mine-proxy? |
|
Answer» So I have added the wxWidgets patch and COMPILED bitcoind I also applied the bitcoin-4diff.txt patch. Downloaded 3.24.60 of namecoind and configured my bitcoin.conf file. |
|
| 390. |
Solve : Virus disabling all security, scans, please help!!? |
|
Answer» Hi there. My Avira auto guard has switched itself off and is unable to get back on. I try to scan with it but I receive multiple error messages.
Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives
|
|
| 391. |
Solve : Anti Virus program useable with Windows ME? |
|
Answer» My wife continues to use a computer with win ME. Up until very recently she has been using Avast. However they have just advised that Avast no longer supports ME. I have done extensive searching for an alternative. So far the only one i was able to find is "ClamWin". However it has a very major drawback--it will only scan folders manually selected. There is no real time scan option with it. Does anyone know of any usable real time anti virus SCANNER than will STILL work with Win ME? Thank you,truenorth But i gathered the impression that the only thing that could be scheduled was the update function and scanning--but only insofar as a time. It seemed that the user still had to manually select what was to be scanned at the time chosen at the actual moment of the scan. I could be mistaken about that. Thanks againFor task scheduler, clamwin can be made to scan using it's command line program, "clamscan.exe" via a batch file. I'm sure if you choose to take this route I or another member could help you with such a configuration.BC, Yes because it is an open source program i would imagine that competent people could have it do various things. However i read your gracious offer to "she who must be obeyed" and the immediate response was "FORGET it". I have only very recently been allowed to put my hands on it (but with a very short leash). Were it mine i would certainly accept your offer so as to advance my very limited knowledge in the programming arena. Thanks again,truenorth |
|
| 392. |
Solve : get answers fast!!!? |
|
Answer» hi guys, R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows VISTA 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-09-23 225280] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys S1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files (x86)\F-Secure\HIPS\drivers\fshs.sys [2011-05-19 61008] S1 FSES;F-Secure Email Scanning Driver;c:\windows\system32\drivers\fses.sys S1 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys S1 fsvista;F-Secure Vista Support Driver;c:\program files (x86)\F-Secure\Anti-Virus\minifilter\fsvista.sys [2011-05-19 15856] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208] S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136] S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-07-02 27192] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-04-13 13336] S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920] S3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files (x86)\F-Secure\Anti-Virus\minifilter\fsgk.sys [2011-09-08 198808] S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys S3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] Akamai REG_MULTI_SZ Akamai . Contents of the 'Scheduled Tasks' folder . 2011-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-10 01:37] . 2011-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-10 01:37] . 2011-10-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-71440679-69947657-1278906953-1000Core.job - c:\users\yin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-08 01:06] . 2011-10-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-71440679-69947657-1278906953-1000UA.job - c:\users\yin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-08 01:06] . . --------- x86-64 ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2010-03-13 6234144] "HPWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe" [2010-06-18 8192] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 161304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 415256] "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2726728] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ------- Supplementary Scan ------- . uStart Page = https://login.live.com/login.srf?cbcxt=out&vv=900&wa=wsignin1.0&wtrealm=urn:federation:MicrosoftOnline&wctx=wa%3Dwsignin1.0%26rpsnv%3D2%26ct%3D1298333514%26rver%3D6.1.6206.0%26wp%3DMBI_KEY%26wreply%3Dhttps:%252F%252Fwww.outlook.com%252Fowa%252F%26id%3D260563%26CBCXT%3Dout uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Append to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\yin\AppData\Roaming\Mozilla\Firefox\Profiles\k1t56s8f.default\ FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Browsing Protection: [email protected] - c:\program files (x86)\F-Secure\NRS\[email protected] FF - Ext: Ovi Maps 3D browser plugin: [email protected] - %profile%\extensions\[email protected] . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKCU-Run-MousePolicyPolicy - c:\programdata\MousePolicyPolicy.dll Wow6432Node-HKCU-Run-Mozilla Update - c:\users\yin\AppData\Local\Installer4632\Installer4632Update\Installer4632updt32.DLL HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] Denied: (A 2) (Everyone) ="FlashBroker" "LocalizedString"="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] Denied: (A 2) (Everyone) ="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] ="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] ="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] ="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] ="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] ="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] Denied: (A 2) (Everyone) ="Macromedia Flash FACTORY Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] ="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] ="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] ="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] ="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] ="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] Denied: (A 2) (Everyone) ="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] ="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] Denied: (Full) (Everyone) . ------------------------ Other Running Processes ------------------------ . c:\program files (x86)\Bonjour\mDNSResponder.exe c:\windows\SysWOW64\ezSharedSvcHost.exe c:\program files (x86)\F-Secure\Anti-Virus\fsgk32st.exe c:\program files (x86)\F-Secure\Common\FSMA32.EXE c:\program files (x86)\F-Secure\Anti-Virus\FSGK32.EXE c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe c:\program files (x86)\F-Secure\Anti-Virus\fssm32.exe c:\program files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe c:\program files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe c:\program files (x86)\F-Secure\common\FSLAUNCH.EXE . ************************************************************************** . Completion time: 2011-10-27 11:24:36 - machine was rebooted ComboFix-quarantined-files.txt 2011-10-27 15:24 . Pre-Run: 388,781,756,416 bytes free Post-Run: 388,530,745,344 bytes free . - - End Of File - - 6D9C5D0ADBFFC11BACC6D5776E871A56 Scan for malware Please download Malwarebytes Anti-Malware from Download.CNET.com. Alternate link: BleepingComputer.com. (Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!) Double Click mbam-setup.exe to install the application. (Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
thanks again Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8030 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 10/27/2011 2:20:21 PM mbam-log-2011-10-27 (14-20-21).txt Scan type: Quick scan Objects scanned: 181827 Time elapsed: 2 minute(s), 23 second(s) Memory Processes Infected: 0 Memory MODULES Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) One more scan and I think you'll be good... ESET Online Scan Please run a free online scan with the ESET Online Scanner
|
|
| 393. |
Solve : System Idle Process CPU won't go down? |
|
Answer» Okay, So I am quite stuck with this issue. I know that the System Idle Process is used when there's nothing to do and it will always be 99 around that. But the problem is that when I run a busy program or games which normally would instantly replace the CPU usage from System Idle Process. It doesn't now or it does only 50%, which makes my games lag and barely unplayable.
Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8021 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 10/26/2011 5:47:37 PM mbam-log-2011-10-26 (17-47-37).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 373381 Time elapsed: 1 hour(s), 12 minute(s), 32 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 11 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\documents and settings\Nookia\my documents\cdkeybuddy v1.04\cdkeybuddy.dll (Trojan.Downloader) -> Quarantined and deleted successfully. d:\downloads\guitar pro 6.0.8 r9626 multilingual\Keymaker\keygen.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. d:\downloads\CS5\adobe photoshop cs5 extended\adobe cs5 all products keygens + individual product keygen\adobe creative suite 5 master collection keymaker\adobe_keygen_mc_cs5.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully. d:\downloads\CS5\adobe photoshop cs5 extended\adobe cs5 all products keygens + individual product keygen\adobe dreamweaver cs5 v11.0.4909 keygen\adobe_dw_cs5_keygen.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. d:\downloads\CS5\adobe photoshop cs5 extended\adobe cs5 all products keygens + individual product keygen\adobe flash professional cs5 v11.0.0.485 keygen\adobe_fp_cs5_keygen.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. d:\downloads\CS5\adobe photoshop cs5 extended\adobe cs5 all products keygens + individual product keygen\adobe illustrator cs5 v15.0 keygen\adobe_il_cs5_keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully. d:\downloads\CS5\adobe photoshop cs5 extended\adobe cs5 all products keygens + individual product keygen\adobe indesign cs5 premium v7.0 keygen\adobe_idp_cs5_keygen.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. d:\downloads\CS5\adobe photoshop cs5 extended\adobe cs5 all products keygens + individual product keygen\adobe photoshop cs5 extended v12.0 keygen\adobe_ps_cs5_keygen.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. d:\downloads\CS5\adobe photoshop cs5 extended\adobe cs5 all products keygens + individual product keygen\core adobe master collection cs5\adobe_keygen_mc_cs5.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully. d:\Games\rhythm zone\uninstall.exe (Malware.Packer.Krunchy) -> Quarantined and deleted successfully. d:\system volume information\_restore{65cd1720-a71e-43e1-a698-25902bb3649f}\RP11\A0014272.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully. DDS Log [Both] DDS . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_27 Run by Nookia at 20:34:10 on 2011-10-26 Microsoft Windows XP Professional 5.1.2600.3.874.66.1033.18.3327.2663 [GMT 7:00] . . ============== Running Processes =============== . C:\WINXP\system32\nvsvc32.exe C:\WINXP\system32\svchost -k DcomLaunch svchost.exe C:\WINXP\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINXP\system32\spoolsv.exe C:\WINXP\Explorer.EXE C:\WINXP\system32\RUNDLL32.EXE C:\WINXP\RTHDCPL.EXE C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe svchost.exe C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Brother\ControlCenter3\brccMCtl.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\WINXP\system32\ctfmon.exe C:\Program Files\DAEMON Tools Lite\DTLite.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe C:\Program Files\SddSUpdate\SddSUpdate.exe C:\WINXP\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\WINXP\system32\wscntfy.exe C:\Program Files\iPod\bin\iPodService.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.co.th/ uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: FlashGetBHO: {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - c:\documents and settings\nookia\application data\flashgetbho\FlashGetBHO3.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [CTFMON.EXE] c:\winxp\system32\ctfmon.exe uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun uRun: [FlashGet 3] "c:\program files\flashget network\flashget 3\FlashGet3.exe" -minimize uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background mRun: [NvMediaCenter] RUNDLL32.EXE c:\winxp\system32\NvMcTray.dll,NvTaskbarInit mRun: [NvCplDaemon] RUNDLL32.EXE c:\winxp\system32\NvCpl.dll,NvStartup mRun: [IMJPMIG8.1] "c:\winxp\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [PHIME2002ASync] c:\winxp\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\winxp\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [SIX Engine] "c:\program files\asus\epu-4 engine\FourEngine.exe" -r mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe" mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe" mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [NeroFilterCheck] c:\winxp\system32\NeroCheck.exe mRun: [PlusService] c:\program files\yuna software\messenger plus!\PlusService.exe mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe" mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray dRun: [CTFMON.EXE] c:\winxp\system32\CTFMON.EXE IE: Download all by FlashGet3 - c:\documents and settings\nookia\application data\flashgetbho\GetAllUrl.htm IE: Download by FlashGet3 - c:\documents and settings\nookia\application data\flashgetbho\GetUrl.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL Trusted Zone: com.cn\*.cga Trusted Zone: kuaiche.com\software Trusted Zone: ogdev.net Trusted Zone: sdo.com DPF: {2B6F3D45-8258-4A13-85B8-58C62DFDB4EA} - hxxps://secure1.playfps.com/play/ava/ax/WebLauncher.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: Interfaces\{74B61D8C-FD92-4099-9703-D4AD44B5EB4C} : NameServer = 192.168.1.2,192.168.1.1 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~3\office12\GR99D3~1.DLL Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\winxp\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\nookia\application data\mozilla\firefox\profiles\msprhzcg.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.th/ FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll . ============= SERVICES / DRIVERS =============== . R0 mv61xx;mv61xx;c:\winxp\system32\drivers\mv61xx.sys [2011-3-2 159024] R0 mv61xxmm;mv61xxmm;c:\winxp\system32\drivers\mv61xxmm.sys [2011-3-2 13616] R0 mv64xxmm;mv64xxmm;c:\winxp\system32\drivers\mv64xxmm.sys [2011-3-2 5632] R0 mvxxmm;mvxxmm;c:\winxp\system32\drivers\mvxxmm.sys [2011-3-2 13616] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\winxp\system32\drivers\dtsoftbus01.sys [2011-5-16 218688] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-10-26 366152] R2 SddSUpdate;SddSUpdate;c:\program files\sddsupdate\SddSUpdate.exe [2011-9-27 466440] R3 MBAMProtector;MBAMProtector;c:\winxp\system32\drivers\mbam.sys [2011-10-26 22216] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\winxp\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-7-30 136176] S3 1394hub;1394 Enabled Hub;c:\winxp\system32\svchost.exe -k netsvcs [2008-4-14 14336] S3 Ambfilt;Ambfilt;c:\winxp\system32\drivers\Ambfilt.sys [2011-5-16 1684736] S3 dump_wmimmc;dump_wmimmc;\??\d:\games\ea sports\fifa online 2\gameguard\dump_wmimmc.sys --> d:\games\ea sports\fifa online 2\gameguard\dump_wmimmc.sys [?] S3 EagleXNt;EagleXNt;\??\c:\winxp\system32\drivers\eaglexnt.sys --> c:\winxp\system32\drivers\EagleXNt.sys [?] S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\garena classic\safedrv.sys --> c:\program files\garena classic\safedrv.sys [?] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-7-30 136176] S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\winxp\system32\drivers\mbamswissarmy.sys --> c:\winxp\system32\drivers\mbamswissarmy.sys [?] S3 npggsvc;nProtect GameGuard Service;c:\winxp\system32\gamemon.des -service --> c:\winxp\system32\GameMon.des -service [?] S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\winxp\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S3 XDva385;XDva385;\??\c:\winxp\system32\xdva385.sys --> c:\winxp\system32\XDva385.sys [?] S3 XDva387;XDva387;\??\c:\winxp\system32\xdva387.sys --> c:\winxp\system32\XDva387.sys [?] . =============== Created Last 30 ================ . 2011-10-26 11:35:40 -------- d-----w- c:\winxp\pss 2011-10-26 09:33:00 -------- d-----w- c:\documents and settings\nookia\application data\Malwarebytes 2011-10-26 09:32:54 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes 2011-10-26 09:32:51 22216 ----a-w- c:\winxp\system32\drivers\mbam.sys 2011-10-26 09:32:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-10-25 12:30:45 -------- d-----w- C:\Log 2011-10-25 10:19:29 -------- d-----w- c:\winxp\EA Sports FIFA Online 2 2011-10-25 10:19:29 -------- d-----w- C:\Joy2Key 2011-10-24 11:10:25 -------- d-----w- c:\program files\KONAMI 2011-10-18 02:29:14 39424 ----a-w- c:\winxp\LZService.exe 2011-10-18 02:28:45 132880 ----a-w- c:\winxp\system32\MSINET.OCX 2011-10-16 17:06:49 74072 ----a-w- c:\winxp\system32\XAPOFX1_5.dll 2011-10-16 17:06:49 527192 ----a-w- c:\winxp\system32\XAudio2_7.dll 2011-10-16 17:06:49 239960 ----a-w- c:\winxp\system32\xactengine3_7.dll 2011-10-16 17:06:49 2106216 ----a-w- c:\winxp\system32\D3DCompiler_43.dll 2011-10-16 17:06:48 470880 ----a-w- c:\winxp\system32\d3dx10_43.dll 2011-10-16 17:06:48 248672 ----a-w- c:\winxp\system32\d3dx11_43.dll 2011-10-16 17:06:48 1868128 ----a-w- c:\winxp\system32\d3dcsx_43.dll 2011-10-16 17:06:47 1998168 ----a-w- c:\winxp\system32\D3DX9_43.dll 2011-10-16 16:40:09 -------- d-----w- c:\documents and settings\nookia\application data\NVIDIA 2011-10-11 15:47:15 74072 ----a-w- c:\winxp\system32\XAPOFX1_4.dll 2011-10-11 15:47:15 528216 ----a-w- c:\winxp\system32\XAudio2_6.dll 2011-10-11 15:47:15 238936 ----a-w- c:\winxp\system32\xactengine3_6.dll 2011-10-11 15:47:14 22360 ----a-w- c:\winxp\system32\X3DAudio1_7.dll 2011-10-10 04:09:40 4550304 ----a-w- c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll 2011-10-07 05:33:50 -------- d-----w- c:\program files\HHD Software 2011-10-06 03:54:14 -------- d-----w- c:\documents and settings\nookia\application data\fretsonfire 2011-10-06 03:53:56 -------- d-----w- c:\program files\Frets on Fire 2011-10-04 03:14:25 -------- d-----w- c:\program files\Activision 2011-10-04 02:58:01 -------- d-----w- c:\documents and settings\nookia\local settings\application data\Activision 2011-10-04 02:41:11 -------- d-sh--w- c:\winxp\ftpcache 2011-10-02 08:56:03 -------- d-----w- c:\documents and settings\all users\application data\NexonUS 2011-10-02 04:17:27 -------- d-----w- c:\program files\Acoustica Shared Effects 2011-10-02 04:08:09 -------- d-----w- c:\documents and settings\all users\application data\Acoustica 2011-10-02 04:07:33 -------- d-----w- c:\program files\Acoustica Mixcraft 5 2011-10-01 15:51:06 -------- d-----w- c:\program files\ASIO4ALL v2 2011-10-01 15:50:50 225280 ----a-w- c:\winxp\system32\rewire.dll 2011-10-01 15:50:50 -------- d-----w- c:\program files\VstPlugins 2011-10-01 15:50:43 1554944 ----a-w- c:\winxp\system32\vorbis.acm 2011-10-01 15:50:39 -------- d-----w- c:\program files\Outsim 2011-10-01 15:47:09 -------- d-----w- c:\program files\Image-Line 2011-10-01 15:47:04 1700352 ----a-w- c:\winxp\system32\gdiplus.dll 2011-10-01 15:44:42 -------- d-----w- c:\program files\FL Studio 2011-09-30 13:34:35 -------- d-----w- c:\documents and settings\all users\application data\Electronic Arts 2011-09-30 13:34:35 -------- d-----w- c:\documents and settings\all users\application data\EA Core 2011-09-30 13:32:51 447752 ----a-r- c:\winxp\system32\vp6vfw.dll 2011-09-30 13:32:50 -------- d-----w- c:\program files\Microsoft WSE 2011-09-29 10:46:57 -------- d-----w- c:\documents and settings\nookia\local settings\application data\Firaxis Games 2011-09-29 09:39:02 -------- d-----w- c:\winxp\system32\XPSViewer 2011-09-29 01:58:32 89088 ----a-w- c:\winxp\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll 2011-09-29 01:58:10 89088 -c----w- c:\winxp\system32\dllcache\filterpipelineprintproc.dll 2011-09-29 01:58:10 117760 ------w- c:\winxp\system32\prntvpt.dll 2011-09-29 01:58:09 597504 -c----w- c:\winxp\system32\dllcache\printfilterpipelinesvc.exe 2011-09-29 01:58:09 597504 ------w- c:\winxp\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe 2011-09-29 01:58:09 575488 -c----w- c:\winxp\system32\dllcache\xpsshhdr.dll 2011-09-29 01:58:09 575488 ------w- c:\winxp\system32\xpsshhdr.dll 2011-09-29 01:58:09 1676288 -c----w- c:\winxp\system32\dllcache\xpssvcs.dll 2011-09-29 01:58:09 1676288 ------w- c:\winxp\system32\xpssvcs.dll 2011-09-29 01:58:09 -------- d-----w- C:\3f9d14be43711397db9ffd31043f28bc 2011-09-29 01:54:54 -------- d-----w- C:\cc6b51d250c0cea3656f1fb210 2011-09-29 01:54:37 -------- d-----w- C:\02798d8739b357d4a4b0e2 2011-09-28 17:31:03 -------- d-----w- C:\7beff02027e3d28540fca470 2011-09-26 16:11:53 -------- d-----w- c:\program files\common files\Steam . ==================== Find3M ==================== . 2011-10-23 02:12:11 414368 ----a-w- c:\winxp\system32\FlashPlayerCPLApp.cpl 2011-10-16 18:20:04 444952 ----a-w- c:\winxp\system32\wrap_oal.dll 2011-10-16 18:20:04 109080 ----a-w- c:\winxp\system32\OpenAL32.dll 2011-09-10 02:42:04 73728 ----a-w- c:\winxp\system32\javacpl.cpl 2011-09-10 02:42:03 472808 ----a-w- c:\winxp\system32\deployJava1.dll . ============= FINISH: 20:34:17.51 =============== DDS Log [Both] Attach . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_27 Run by Nookia at 20:34:10 on 2011-10-26 Microsoft Windows XP Professional 5.1.2600.3.874.66.1033.18.3327.2663 [GMT 7:00] . . ============== Running Processes =============== . C:\WINXP\system32\nvsvc32.exe C:\WINXP\system32\svchost -k DcomLaunch svchost.exe C:\WINXP\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINXP\system32\spoolsv.exe C:\WINXP\Explorer.EXE C:\WINXP\system32\RUNDLL32.EXE C:\WINXP\RTHDCPL.EXE C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe svchost.exe C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Brother\ControlCenter3\brccMCtl.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\WINXP\system32\ctfmon.exe C:\Program Files\DAEMON Tools Lite\DTLite.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe C:\Program Files\SddSUpdate\SddSUpdate.exe C:\WINXP\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\WINXP\system32\wscntfy.exe C:\Program Files\iPod\bin\iPodService.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.co.th/ uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: FlashGetBHO: {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - c:\documents and settings\nookia\application data\flashgetbho\FlashGetBHO3.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [CTFMON.EXE] c:\winxp\system32\ctfmon.exe uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun uRun: [FlashGet 3] "c:\program files\flashget network\flashget 3\FlashGet3.exe" -minimize uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background mRun: [NvMediaCenter] RUNDLL32.EXE c:\winxp\system32\NvMcTray.dll,NvTaskbarInit mRun: [NvCplDaemon] RUNDLL32.EXE c:\winxp\system32\NvCpl.dll,NvStartup mRun: [IMJPMIG8.1] "c:\winxp\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [PHIME2002ASync] c:\winxp\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\winxp\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [Six Engine] "c:\program files\asus\epu-4 engine\FourEngine.exe" -r mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe" mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe" mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [NeroFilterCheck] c:\winxp\system32\NeroCheck.exe mRun: [PlusService] c:\program files\yuna software\messenger plus!\PlusService.exe mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe" mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray dRun: [CTFMON.EXE] c:\winxp\system32\CTFMON.EXE IE: Download all by FlashGet3 - c:\documents and settings\nookia\application data\flashgetbho\GetAllUrl.htm IE: Download by FlashGet3 - c:\documents and settings\nookia\application data\flashgetbho\GetUrl.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL Trusted Zone: com.cn\*.cga Trusted Zone: kuaiche.com\software Trusted Zone: ogdev.net Trusted Zone: sdo.com DPF: {2B6F3D45-8258-4A13-85B8-58C62DFDB4EA} - hxxps://secure1.playfps.com/play/ava/ax/WebLauncher.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: Interfaces\{74B61D8C-FD92-4099-9703-D4AD44B5EB4C} : NameServer = 192.168.1.2,192.168.1.1 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~3\office12\GR99D3~1.DLL Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\winxp\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\nookia\application data\mozilla\firefox\profiles\msprhzcg.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.th/ FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll . ============= SERVICES / DRIVERS =============== . R0 mv61xx;mv61xx;c:\winxp\system32\drivers\mv61xx.sys [2011-3-2 159024] R0 mv61xxmm;mv61xxmm;c:\winxp\system32\drivers\mv61xxmm.sys [2011-3-2 13616] R0 mv64xxmm;mv64xxmm;c:\winxp\system32\drivers\mv64xxmm.sys [2011-3-2 5632] R0 mvxxmm;mvxxmm;c:\winxp\system32\drivers\mvxxmm.sys [2011-3-2 13616] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\winxp\system32\drivers\dtsoftbus01.sys [2011-5-16 218688] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-10-26 366152] R2 SddSUpdate;SddSUpdate;c:\program files\sddsupdate\SddSUpdate.exe [2011-9-27 466440] R3 MBAMProtector;MBAMProtector;c:\winxp\system32\drivers\mbam.sys [2011-10-26 22216] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\winxp\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-7-30 136176] S3 1394hub;1394 Enabled Hub;c:\winxp\system32\svchost.exe -k netsvcs [2008-4-14 14336] S3 Ambfilt;Ambfilt;c:\winxp\system32\drivers\Ambfilt.sys [2011-5-16 1684736] S3 dump_wmimmc;dump_wmimmc;\??\d:\games\ea sports\fifa online 2\gameguard\dump_wmimmc.sys --> d:\games\ea sports\fifa online 2\gameguard\dump_wmimmc.sys [?] S3 EagleXNt;EagleXNt;\??\c:\winxp\system32\drivers\eaglexnt.sys --> c:\winxp\system32\drivers\EagleXNt.sys [?] S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\garena classic\safedrv.sys --> c:\program files\garena classic\safedrv.sys [?] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-7-30 136176] S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\winxp\system32\drivers\mbamswissarmy.sys --> c:\winxp\system32\drivers\mbamswissarmy.sys [?] S3 npggsvc;nProtect GameGuard Service;c:\winxp\system32\gamemon.des -service --> c:\winxp\system32\GameMon.des -service [?] S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\winxp\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S3 XDva385;XDva385;\??\c:\winxp\system32\xdva385.sys --> c:\winxp\system32\XDva385.sys [?] S3 XDva387;XDva387;\??\c:\winxp\system32\xdva387.sys --> c:\winxp\system32\XDva387.sys [?] . =============== Created Last 30 ================ . 2011-10-26 11:35:40 -------- d-----w- c:\winxp\pss 2011-10-26 09:33:00 -------- d-----w- c:\documents and settings\nookia\application data\Malwarebytes 2011-10-26 09:32:54 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes 2011-10-26 09:32:51 22216 ----a-w- c:\winxp\system32\drivers\mbam.sys 2011-10-26 09:32:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-10-25 12:30:45 -------- d-----w- C:\Log 2011-10-25 10:19:29 -------- d-----w- c:\winxp\EA Sports FIFA Online 2 2011-10-25 10:19:29 -------- d-----w- C:\Joy2Key 2011-10-24 11:10:25 -------- d-----w- c:\program files\KONAMI 2011-10-18 02:29:14 39424 ----a-w- c:\winxp\LZService.exe 2011-10-18 02:28:45 132880 ----a-w- c:\winxp\system32\MSINET.OCX 2011-10-16 17:06:49 74072 ----a-w- c:\winxp\system32\XAPOFX1_5.dll 2011-10-16 17:06:49 527192 ----a-w- c:\winxp\system32\XAudio2_7.dll 2011-10-16 17:06:49 239960 ----a-w- c:\winxp\system32\xactengine3_7.dll 2011-10-16 17:06:49 2106216 ----a-w- c:\winxp\system32\D3DCompiler_43.dll 2011-10-16 17:06:48 470880 ----a-w- c:\winxp\system32\d3dx10_43.dll 2011-10-16 17:06:48 248672 ----a-w- c:\winxp\system32\d3dx11_43.dll 2011-10-16 17:06:48 1868128 ----a-w- c:\winxp\system32\d3dcsx_43.dll 2011-10-16 17:06:47 1998168 ----a-w- c:\winxp\system32\D3DX9_43.dll 2011-10-16 16:40:09 -------- d-----w- c:\documents and settings\nookia\application data\NVIDIA 2011-10-11 15:47:15 74072 ----a-w- c:\winxp\system32\XAPOFX1_4.dll 2011-10-11 15:47:15 528216 ----a-w- c:\winxp\system32\XAudio2_6.dll 2011-10-11 15:47:15 238936 ----a-w- c:\winxp\system32\xactengine3_6.dll 2011-10-11 15:47:14 22360 ----a-w- c:\winxp\system32\X3DAudio1_7.dll 2011-10-10 04:09:40 4550304 ----a-w- c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll 2011-10-07 05:33:50 -------- d-----w- c:\program files\HHD Software 2011-10-06 03:54:14 -------- d-----w- c:\documents and settings\nookia\application data\fretsonfire 2011-10-06 03:53:56 -------- d-----w- c:\program files\Frets on Fire 2011-10-04 03:14:25 -------- d-----w- c:\program files\Activision 2011-10-04 02:58:01 -------- d-----w- c:\documents and settings\nookia\local settings\application data\Activision 2011-10-04 02:41:11 -------- d-sh--w- c:\winxp\ftpcache 2011-10-02 08:56:03 -------- d-----w- c:\documents and settings\all users\application data\NexonUS 2011-10-02 04:17:27 -------- d-----w- c:\program files\Acoustica Shared Effects 2011-10-02 04:08:09 -------- d-----w- c:\documents and settings\all users\application data\Acoustica 2011-10-02 04:07:33 -------- d-----w- c:\program files\Acoustica Mixcraft 5 2011-10-01 15:51:06 -------- d-----w- c:\program files\ASIO4ALL v2 2011-10-01 15:50:50 225280 ----a-w- c:\winxp\system32\rewire.dll 2011-10-01 15:50:50 -------- d-----w- c:\program files\VstPlugins 2011-10-01 15:50:43 1554944 ----a-w- c:\winxp\system32\vorbis.acm 2011-10-01 15:50:39 -------- d-----w- c:\program files\Outsim 2011-10-01 15:47:09 -------- d-----w- c:\program files\Image-Line 2011-10-01 15:47:04 1700352 ----a-w- c:\winxp\system32\gdiplus.dll 2011-10-01 15:44:42 -------- d-----w- c:\program files\FL Studio 2011-09-30 13:34:35 -------- d-----w- c:\documents and settings\all users\application data\Electronic Arts 2011-09-30 13:34:35 -------- d-----w- c:\documents and settings\all users\application data\EA Core 2011-09-30 13:32:51 447752 ----a-r- c:\winxp\system32\vp6vfw.dll 2011-09-30 13:32:50 -------- d-----w- c:\program files\Microsoft WSE 2011-09-29 10:46:57 -------- d-----w- c:\documents and settings\nookia\local settings\application data\Firaxis Games 2011-09-29 09:39:02 -------- d-----w- c:\winxp\system32\XPSViewer 2011-09-29 01:58:32 89088 ----a-w- c:\winxp\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll 2011-09-29 01:58:10 89088 -c----w- c:\winxp\system32\dllcache\filterpipelineprintproc.dll 2011-09-29 01:58:10 117760 ------w- c:\winxp\system32\prntvpt.dll 2011-09-29 01:58:09 597504 -c----w- c:\winxp\system32\dllcache\printfilterpipelinesvc.exe 2011-09-29 01:58:09 597504 ------w- c:\winxp\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe 2011-09-29 01:58:09 575488 -c----w- c:\winxp\system32\dllcache\xpsshhdr.dll 2011-09-29 01:58:09 575488 ------w- c:\winxp\system32\xpsshhdr.dll 2011-09-29 01:58:09 1676288 -c----w- c:\winxp\system32\dllcache\xpssvcs.dll 2011-09-29 01:58:09 1676288 ------w- c:\winxp\system32\xpssvcs.dll 2011-09-29 01:58:09 -------- d-----w- C:\3f9d14be43711397db9ffd31043f28bc 2011-09-29 01:54:54 -------- d-----w- C:\cc6b51d250c0cea3656f1fb210 2011-09-29 01:54:37 -------- d-----w- C:\02798d8739b357d4a4b0e2 2011-09-28 17:31:03 -------- d-----w- C:\7beff02027e3d28540fca470 2011-09-26 16:11:53 -------- d-----w- c:\program files\common files\Steam . ==================== Find3M ==================== . 2011-10-23 02:12:11 414368 ----a-w- c:\winxp\system32\FlashPlayerCPLApp.cpl 2011-10-16 18:20:04 444952 ----a-w- c:\winxp\system32\wrap_oal.dll 2011-10-16 18:20:04 109080 ----a-w- c:\winxp\system32\OpenAL32.dll 2011-09-10 02:42:04 73728 ----a-w- c:\winxp\system32\javacpl.cpl 2011-09-10 02:42:03 472808 ----a-w- c:\winxp\system32\deployJava1.dll . ============= FINISH: 20:34:17.51 =============== Your computer has keygens, which are a form of software piracy. What is so bad about Cracks, Hacks, Pirated software, warez, or Keygens? Most popular cracks or keygens I see, are for Adobe CS3, a lot of different games, Nero, Kaspersky antivirus, and much more. All of these cracks and keygens have what is called "cloaked malware," which is a form of spyware or viruses or trojans that hide themselves inside the keygen or crack files. Most hacks for games that come in the form of a program or installer, will also be infected. It is the opportunity for attackers to present a seemingly safe situation where the opportunity to steal something is in play, while the malware infects your system in the process. Yes, it will install what you were looking for, but also allow malware to potentially take control of your computer. Lastly, it is illegal. I will counsel you that we do not report such incidents. However, it is not good practice to pirate software. Please visit this webpage for a tutorial on downloading and running ComboFix: http://www.bleepingcomputer.com/combofix/how-to-use-combofix See the area: Using ComboFix, and when done, post the log back here. Quote from: DragonMaster Jay on October 26, 2011, 09:37:41 AM Your computer has keygens, which are a form of software piracy. What is so bad about Cracks, Hacks, Pirated software, warez, or Keygens?Thank You for your effort in replying my issue. I can see now that the cracks and keygen could have malware hidden in them. I will try not to pirate anymore software from now. But I still don't know how does that involves with the System Idle Process eating all the CPU ? Have you ever experienced these kinds of issue before ? I mean issue about the System Idle Process things because I mostly see it goes with svchost.exe instead. And here are the combofix log ComboFix 11-10-26.03 - Nookia 10/26/2011 23:07:22.2.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.874.66.1033.18.3327.2604 [GMT 7:00] Running from: c:\documents and settings\Nookia\Desktop\ComboFix.exe . . ((((((((((((((((((((((((( Files Created from 2011-09-26 to 2011-10-26 ))))))))))))))))))))))))))))))) . . 2011-10-26 14:01 . 2011-10-26 14:01 -------- d-----w- c:\program files\Defraggler 2011-10-26 09:33 . 2011-10-26 09:33 -------- d-----w- c:\documents and settings\Nookia\Application Data\Malwarebytes 2011-10-26 09:32 . 2011-10-26 09:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2011-10-26 09:32 . 2011-10-26 09:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-10-26 09:32 . 2011-08-31 10:00 22216 ----a-w- c:\winxp\system32\drivers\mbam.sys 2011-10-26 09:09 . 2011-10-26 09:09 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\Activision 2011-10-26 08:59 . 2011-10-26 08:59 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\SKIDROW 2011-10-26 08:57 . 2011-10-26 08:57 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\My Games 2011-10-25 12:30 . 2011-10-25 12:30 -------- d-----w- C:\Log 2011-10-25 10:19 . 2011-10-25 10:19 -------- d-----w- c:\winxp\EA Sports FIFA Online 2 2011-10-25 10:19 . 2011-10-25 10:19 -------- d-----w- C:\Joy2Key 2011-10-24 11:10 . 2011-10-25 08:18 -------- d-----w- c:\program files\KONAMI 2011-10-18 02:29 . 2011-10-18 02:29 39424 ----a-w- c:\winxp\LZService.exe 2011-10-18 02:28 . 2009-10-05 19:47 132880 ----a-w- c:\winxp\system32\MSINET.OCX 2011-10-16 17:06 . 2010-06-01 21:55 74072 ----a-w- c:\winxp\system32\XAPOFX1_5.dll 2011-10-16 17:06 . 2010-06-01 21:55 527192 ----a-w- c:\winxp\system32\XAudio2_7.dll 2011-10-16 17:06 . 2010-06-01 21:55 239960 ----a-w- c:\winxp\system32\xactengine3_7.dll 2011-10-16 17:06 . 2010-05-26 04:41 2106216 ----a-w- c:\winxp\system32\D3DCompiler_43.dll 2011-10-16 17:06 . 2010-05-26 04:41 470880 ----a-w- c:\winxp\system32\d3dx10_43.dll 2011-10-16 17:06 . 2010-05-26 04:41 248672 ----a-w- c:\winxp\system32\d3dx11_43.dll 2011-10-16 17:06 . 2010-05-26 04:41 1868128 ----a-w- c:\winxp\system32\d3dcsx_43.dll 2011-10-16 17:06 . 2010-05-26 04:41 1998168 ----a-w- c:\winxp\system32\D3DX9_43.dll 2011-10-16 16:40 . 2011-10-16 16:40 -------- d-----w- c:\documents and settings\Nookia\Application Data\NVIDIA 2011-10-11 15:47 . 2010-02-04 03:01 74072 ----a-w- c:\winxp\system32\XAPOFX1_4.dll 2011-10-11 15:47 . 2010-02-04 03:01 528216 ----a-w- c:\winxp\system32\XAudio2_6.dll 2011-10-11 15:47 . 2010-02-04 03:01 238936 ----a-w- c:\winxp\system32\xactengine3_6.dll 2011-10-11 15:47 . 2010-02-04 03:01 22360 ----a-w- c:\winxp\system32\X3DAudio1_7.dll 2011-10-10 04:09 . 2011-10-10 04:09 4550304 ----a-w- c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll 2011-10-07 05:33 . 2011-10-07 05:33 -------- d-----w- c:\program files\HHD Software 2011-10-06 03:54 . 2011-10-06 03:56 -------- d-----w- c:\documents and settings\Nookia\Application Data\fretsonfire 2011-10-06 03:53 . 2011-10-06 03:54 -------- d-----w- c:\program files\Frets on Fire 2011-10-04 03:14 . 2011-10-04 03:14 -------- d-----w- c:\program files\Activision 2011-10-04 02:58 . 2011-10-06 00:35 -------- d-----w- c:\documents and settings\Nookia\Local Settings\Application Data\Activision 2011-10-04 02:41 . 2011-10-04 02:41 -------- d-sh--w- c:\winxp\ftpcache 2011-10-02 08:56 . 2011-10-02 08:56 -------- d-----w- c:\documents and settings\All Users\Application Data\NexonUS 2011-10-02 04:17 . 2011-10-02 04:17 -------- d-----w- c:\program files\Acoustica Shared Effects 2011-10-02 04:08 . 2011-10-02 04:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Acoustica 2011-10-02 04:07 . 2011-10-02 04:22 -------- d-----w- c:\program files\Acoustica Mixcraft 5 2011-10-01 15:51 . 2011-10-01 15:51 -------- d-----w- c:\program files\ASIO4ALL v2 2011-10-01 15:50 . 2011-10-01 15:50 -------- d-----w- c:\program files\VstPlugins 2011-10-01 15:50 . 2006-06-20 08:56 225280 ----a-w- c:\winxp\system32\rewire.dll 2011-10-01 15:50 . 2009-09-15 09:14 1554944 ----a-w- c:\winxp\system32\vorbis.acm 2011-10-01 15:50 . 2011-10-01 15:50 -------- d-----w- c:\program files\Outsim 2011-10-01 15:47 . 2011-10-01 15:50 -------- d-----w- c:\program files\Image-Line 2011-10-01 15:47 . 2011-10-01 15:47 1700352 ----a-w- c:\winxp\system32\gdiplus.dll 2011-10-01 15:44 . 2011-10-01 15:45 -------- d-----w- c:\program files\FL Studio 2011-09-30 13:34 . 2011-09-30 13:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts 2011-09-30 13:34 . 2011-09-30 13:34 -------- d-----w- c:\documents and settings\All Users\Application Data\EA Core 2011-09-30 13:32 . 2010-11-23 00:09 447752 ----a-r- c:\winxp\system32\vp6vfw.dll 2011-09-30 13:32 . 2011-09-30 13:32 -------- d-----w- c:\program files\Microsoft WSE 2011-09-29 10:46 . 2011-09-29 10:46 -------- d-----w- c:\documents and settings\Nookia\Local Settings\Application Data\Firaxis Games 2011-09-29 09:39 . 2011-09-29 09:39 -------- d-----w- c:\winxp\system32\XPSViewer 2011-09-29 01:58 . 2011-09-29 01:58 -------- d-----w- c:\program files\Reference Assemblies 2011-09-29 01:58 . 2008-07-06 12:06 89088 ----a-w- c:\winxp\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll 2011-09-29 01:58 . 2008-07-06 12:06 89088 -c----w- c:\winxp\system32\dllcache\filterpipelineprintproc.dll 2011-09-29 01:58 . 2008-07-06 12:06 117760 ------w- c:\winxp\system32\prntvpt.dll 2011-09-29 01:58 . 2011-09-29 01:58 -------- d-----w- C:\3f9d14be43711397db9ffd31043f28bc 2011-09-29 01:58 . 2008-07-06 12:06 575488 -c----w- c:\winxp\system32\dllcache\xpsshhdr.dll 2011-09-29 01:58 . 2008-07-06 12:06 575488 ------w- c:\winxp\system32\xpsshhdr.dll 2011-09-29 01:58 . 2008-07-06 12:06 1676288 -c----w- c:\winxp\system32\dllcache\xpssvcs.dll 2011-09-29 01:58 . 2008-07-06 12:06 1676288 ------w- c:\winxp\system32\xpssvcs.dll 2011-09-29 01:58 . 2008-07-06 10:50 597504 -c----w- c:\winxp\system32\dllcache\printfilterpipelinesvc.exe 2011-09-29 01:58 . 2008-07-06 10:50 597504 ------w- c:\winxp\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe 2011-09-29 01:54 . 2011-09-29 01:54 -------- d-----w- C:\cc6b51d250c0cea3656f1fb210 2011-09-29 01:54 . 2011-09-29 04:17 -------- d-----w- C:\02798d8739b357d4a4b0e2 2011-09-28 17:31 . 2011-09-28 17:53 -------- d-----w- C:\7beff02027e3d28540fca470 . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-10-23 02:12 . 2011-09-10 01:59 414368 ----a-w- c:\winxp\system32\FlashPlayerCPLApp.cpl 2011-10-16 18:20 . 2011-06-24 13:11 444952 ----a-w- c:\winxp\system32\wrap_oal.dll 2011-10-16 18:20 . 2011-06-24 13:11 109080 ----a-w- c:\winxp\system32\OpenAL32.dll 2011-09-10 02:42 . 2011-09-10 02:42 73728 ----a-w- c:\winxp\system32\javacpl.cpl 2011-09-10 02:42 . 2011-09-10 02:42 472808 ----a-w- c:\winxp\system32\deployJava1.dll 2011-10-02 23:36 . 2011-05-16 09:54 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [7] 2010-09-16 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\winxp\system32\dllcache\tcpip.sys [-] 2010-09-16 . A5BC817BB84DCB9E71719FF868144124 . 361600 . . [5.1.2600.5625] . . c:\winxp\system32\drivers\tcpip.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\KzShlobj] ="{AAA0C5B8-933F-4200-93AD-B143D7FFF9F2}" [HKEY_CLASSES_ROOT\CLSID\{AAA0C5B8-933F-4200-93AD-B143D7FFF9F2}] 2011-08-31 02:21 224288 ----a-w- c:\program files\ฟ์ัน\KZipShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408] "FlashGet 3"="c:\program files\FlashGet Network\FlashGet 3\FlashGet3.exe" [2009-12-22 2127408] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvMediaCenter"="c:\winxp\system32\NvMcTray.dll" [2010-10-16 110696] "NvCplDaemon"="c:\winxp\system32\NvCpl.dll" [2010-10-16 13851752] "IMJPMIG8.1"="c:\winxp\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952] "PHIME2002ASync"="c:\winxp\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168] "PHIME2002A"="c:\winxp\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168] "RTHDCPL"="RTHDCPL.EXE" [2008-11-17 17676288] "Six Engine"="c:\program files\ASUS\EPU-4 Engine\FourEngine.exe" [2008-07-23 5625344] "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472] "PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-29 30248] "IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-29 46632] "PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016] "NeroFilterCheck"="c:\winxp\system32\NeroCheck.exe" [2001-07-09 155648] "PlusService"="c:\program files\Yuna Software\Messenger Plus!\PlusService.exe" [2011-09-20 801792] "BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-12 663552] "ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-08-18 421736] "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-30 499608] "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-21 406992] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\winxp\system32\CTFMON.EXE" [2008-04-14 15360] . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\FlashGet Network\\FlashGet 3\\FlashGet3.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Documents and Settings\\Nookia\\My Documents\\Downloads\\Software\\Setup-MsgPlus-501.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "d:\\Starcraft\\StarCraft.exe"= "c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "d:\\Warcraft III\\Warcraft III.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\KONAMI\\Pro Evolution Soccer 2012\\pes2012.exe"= "d:\\Games\\EA Sports\\FIFA Online 2\\FF2Client.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "6112:TCP"= 6112:TCP:Thaicybergames . R0 mv61xx;mv61xx;c:\winxp\system32\drivers\mv61xx.sys [3/2/2011 3:45 PM 159024] R0 mv61xxmm;mv61xxmm;c:\winxp\system32\drivers\mv61xxmm.sys [3/2/2011 3:45 PM 13616] R0 mv64xxmm;mv64xxmm;c:\winxp\system32\drivers\mv64xxmm.sys [3/2/2011 3:45 PM 5632] R0 mvxxmm;mvxxmm;c:\winxp\system32\drivers\mvxxmm.sys [3/2/2011 3:45 PM 13616] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\winxp\system32\drivers\dtsoftbus01.sys [5/16/2011 5:19 PM 218688] R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [10/26/2011 4:32 PM 366152] R2 SddSUpdate;SddSUpdate;c:\program files\SddSUpdate\SddSUpdate.exe [9/27/2011 9:47 AM 466440] R3 MBAMProtector;MBAMProtector;c:\winxp\system32\drivers\mbam.sys [10/26/2011 4:32 PM 22216] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\winxp\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/30/2011 1:18 PM 136176] S3 1394hub;1394 Enabled Hub;c:\winxp\system32\svchost.exe -k netsvcs [4/14/2008 5:00 PM 14336] S3 Ambfilt;Ambfilt;c:\winxp\system32\drivers\Ambfilt.sys [5/16/2011 10:45 PM 1684736] S3 dump_wmimmc;dump_wmimmc;\??\d:\games\EA Sports\FIFA Online 2\GameGuard\dump_wmimmc.sys --> d:\games\EA Sports\FIFA Online 2\GameGuard\dump_wmimmc.sys [?] S3 EagleXNt;EagleXNt;\??\c:\winxp\system32\drivers\EagleXNt.sys --> c:\winxp\system32\drivers\EagleXNt.sys [?] S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena Classic\safedrv.sys --> c:\program files\Garena Classic\safedrv.sys [?] S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [7/30/2011 1:18 PM 136176] S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\winxp\system32\drivers\mbamswissarmy.sys --> c:\winxp\system32\drivers\mbamswissarmy.sys [?] S3 npggsvc;nProtect GameGuard Service;c:\winxp\system32\GameMon.des -service --> c:\winxp\system32\GameMon.des -service [?] S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 1:37 PM 517096] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\winxp\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504] S3 XDva385;XDva385;\??\c:\winxp\system32\XDva385.sys --> c:\winxp\system32\XDva385.sys [?] S3 XDva387;XDva387;\??\c:\winxp\system32\XDva387.sys --> c:\winxp\system32\XDva387.sys [?] . Contents of the 'Scheduled Tasks' folder . 2011-10-01 c:\winxp\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 10:57] . 2011-10-26 c:\winxp\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-07-30 06:18] . 2011-10-26 c:\winxp\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-07-30 06:18] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.co.th/ uInternet Settings,ProxyOverride = *.local IE: Download all by FlashGet3 - c:\documents and settings\Nookia\Application Data\FlashGetBHO\GetAllUrl.htm IE: Download by FlashGet3 - c:\documents and settings\Nookia\Application Data\FlashGetBHO\GetUrl.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 Trusted Zone: com.cn\*.cga Trusted Zone: kuaiche.com\software Trusted Zone: ogdev.net Trusted Zone: sdo.com TCP: Interfaces\{74B61D8C-FD92-4099-9703-D4AD44B5EB4C}: NameServer = 192.168.1.2,192.168.1.1 DPF: {2B6F3D45-8258-4A13-85B8-58C62DFDB4EA} - hxxps://secure1.playfps.com/play/ava/ax/WebLauncher.cab FF - ProfilePath - c:\documents and settings\Nookia\Application Data\Mozilla\Firefox\Profiles\msprhzcg.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.th/ . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-10-26 23:13 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc] "ImagePath"="c:\winxp\system32\GameMon.des -service" . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'explorer.exe'(1092) c:\winxp\system32\WININET.dll c:\winxp\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll c:\program files\ฟ์ัน\KZipShell.dll c:\winxp\system32\ieframe.dll c:\winxp\system32\webcheck.dll c:\winxp\system32\WPDShServiceObj.dll c:\winxp\system32\PortableDeviceTypes.dll c:\winxp\system32\PortableDeviceApi.dll . Completion time: 2011-10-26 23:14:49 ComboFix-quarantined-files.txt 2011-10-26 16:14 . Pre-Run: 37,932,589,056 bytes free Post-Run: 38,512,857,088 bytes free . - - End Of File - - 5ACDDA9150E00B7F4D5779A0A3F8259B As you can see there's this Chinese threat "KZipShell.dll" which I can't delete it, working under explorer.exe. I'm not sure if it is the reason which effecting my System Idle Process. But I'm quite sure it is some kind of threat to my computer. :/ Here is where I got information from http://www.threatexpert.com/report.aspx?md5=d1975c00385cb9c9d11d17289ae34d0e I have detected various IPs from Malwarebytes protection log too. 77.78.224.33 89.28.85.132 208.91.207.10 91.197.237.17 109.235.55.11 194.54.80.150 62.45.3.198 222.65.184.25 212.117.164.209 There are MANY more but I'm tired of copying and paste them. D: Thank You so far by the way, appreciated 'cheers' The System Idle Process indicates there are no more runnable threads for the CPU. It sticks up at highest usage, because it is considered "ready". It goes down automatically when new threads are created. It does not matter how high or low the System Idle Process runs, because all that shows is that your system is at an idle state. Let's check one more thing... Please download TDSSKiller from here and save it to your Desktop.
And here are the logs no threat found 00:16:16.0687 1280 TDSS rootkit removing tool 2.6.13.0 Oct 25 2011 13:56:21 00:16:17.0500 1280 ============================================================ 00:16:17.0500 1280 Current date / time: 2011/10/27 00:16:17.0500 00:16:17.0500 1280 SystemInfo: 00:16:17.0500 1280 00:16:17.0500 1280 OS Version: 5.1.2600 ServicePack: 3.0 00:16:17.0500 1280 Product type: Workstation 00:16:17.0500 1280 ComputerName: LARCTH 00:16:17.0500 1280 UserName: Nookia 00:16:17.0500 1280 Windows directory: C:\WINXP 00:16:17.0500 1280 System windows directory: C:\WINXP 00:16:17.0500 1280 Processor architecture: Intel x86 00:16:17.0500 1280 Number of processors: 2 00:16:17.0500 1280 Page size: 0x1000 00:16:17.0500 1280 Boot type: Normal boot 00:16:17.0500 1280 ============================================================ 00:16:18.0484 1280 Initialize success 00:16:33.0609 0852 ============================================================ 00:16:33.0609 0852 Scan started 00:16:33.0609 0852 Mode: Manual; 00:16:33.0609 0852 ============================================================ 00:16:34.0671 0852 1394hub - ok 00:16:34.0687 0852 Abiosdsk - ok 00:16:34.0687 0852 abp480n5 - ok 00:16:34.0718 0852 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINXP\system32\DRIVERS\ACPI.sys 00:16:34.0718 0852 ACPI - ok 00:16:34.0750 0852 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINXP\system32\drivers\ACPIEC.sys 00:16:34.0765 0852 ACPIEC - ok 00:16:34.0765 0852 adpu160m - ok 00:16:34.0796 0852 aec (8bed39e3c35d6a489438b8141717a557) C:\WINXP\system32\drivers\aec.sys 00:16:34.0796 0852 aec - ok 00:16:34.0812 0852 AFD (4d43e74f2a1239d53929b82600f1971c) C:\WINXP\System32\drivers\afd.sys 00:16:34.0812 0852 AFD - ok 00:16:34.0828 0852 Aha154x - ok 00:16:34.0828 0852 aic78u2 - ok 00:16:34.0843 0852 aic78xx - ok 00:16:34.0843 0852 AliIde - ok 00:16:34.0906 0852 Ambfilt (f6af59d6eee5e1c304f7f73706ad11d8) C:\WINXP\system32\drivers\Ambfilt.sys 00:16:34.0906 0852 Ambfilt - ok 00:16:34.0921 0852 amsint - ok 00:16:34.0921 0852 asc - ok 00:16:34.0937 0852 asc3350p - ok 00:16:34.0937 0852 asc3550 - ok 00:16:34.0953 0852 AsIO (2b4e66fac6503494a2c6f32bb6ab3826) C:\WINXP\system32\drivers\AsIO.sys 00:16:34.0953 0852 AsIO - ok 00:16:35.0000 0852 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINXP\system32\DRIVERS\asyncmac.sys 00:16:35.0000 0852 AsyncMac - ok 00:16:35.0015 0852 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINXP\system32\DRIVERS\atapi.sys 00:16:35.0015 0852 atapi - ok 00:16:35.0015 0852 Atdisk - ok 00:16:35.0046 0852 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINXP\system32\DRIVERS\atmarpc.sys 00:16:35.0046 0852 Atmarpc - ok 00:16:35.0078 0852 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINXP\system32\DRIVERS\audstub.sys 00:16:35.0078 0852 audstub - ok 00:16:35.0109 0852 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINXP\system32\drivers\Beep.sys 00:16:35.0109 0852 Beep - ok 00:16:35.0140 0852 BrScnUsb (92a964547b96d697e5e9ed43b4297f5a) C:\WINXP\system32\DRIVERS\BrScnUsb.sys 00:16:35.0140 0852 BrScnUsb - ok 00:16:35.0218 0852 catchme - ok 00:16:35.0250 0852 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINXP\system32\drivers\cbidf2k.sys 00:16:35.0250 0852 cbidf2k - ok 00:16:35.0265 0852 cd20xrnt - ok 00:16:35.0265 0852 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINXP\system32\drivers\Cdaudio.sys 00:16:35.0265 0852 Cdaudio - ok 00:16:35.0312 0852 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINXP\system32\drivers\Cdfs.sys 00:16:35.0312 0852 Cdfs - ok 00:16:35.0359 0852 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINXP\system32\DRIVERS\cdrom.sys 00:16:35.0359 0852 Cdrom - ok 00:16:35.0390 0852 Changer - ok 00:16:35.0390 0852 CmdIde - ok 00:16:35.0406 0852 Cpqarray - ok 00:16:35.0437 0852 cpuz135 (c2eb4539a4f6ab6edd01bdc191619975) C:\WINXP\system32\drivers\cpuz135_x32.sys 00:16:35.0437 0852 cpuz135 - ok 00:16:35.0437 0852 dac2w2k - ok 00:16:35.0453 0852 dac960nt - ok 00:16:35.0453 0852 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINXP\system32\DRIVERS\disk.sys 00:16:35.0453 0852 Disk - ok 00:16:35.0515 0852 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINXP\system32\drivers\dmboot.sys 00:16:35.0515 0852 dmboot - ok 00:16:35.0515 0852 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINXP\system32\drivers\dmio.sys 00:16:35.0515 0852 dmio - ok 00:16:35.0546 0852 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINXP\system32\drivers\dmload.sys 00:16:35.0546 0852 dmload - ok 00:16:35.0578 0852 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINXP\system32\drivers\DMusic.sys 00:16:35.0578 0852 DMusic - ok 00:16:35.0593 0852 dpti2o - ok 00:16:35.0593 0852 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINXP\system32\drivers\drmkaud.sys 00:16:35.0593 0852 drmkaud - ok 00:16:35.0640 0852 dtsoftbus01 (555e54ac2f601a8821cef58961653991) C:\WINXP\system32\DRIVERS\dtsoftbus01.sys 00:16:35.0640 0852 dtsoftbus01 - ok 00:16:35.0781 0852 dump_wmimmc - ok 00:16:35.0781 0852 EagleXNt - ok 00:16:35.0843 0852 Fastfat (38d332a6d56af32635675f132548343e) C:\WINXP\system32\drivers\Fastfat.sys 00:16:35.0843 0852 Fastfat - ok 00:16:35.0859 0852 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINXP\system32\drivers\Fdc.sys 00:16:35.0859 0852 Fdc - ok 00:16:35.0875 0852 FIPS (d45926117eb9fa946a6af572fbe1caa3) C:\WINXP\system32\drivers\Fips.sys 00:16:35.0890 0852 Fips - ok 00:16:35.0890 0852 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINXP\system32\drivers\Flpydisk.sys 00:16:35.0890 0852 Flpydisk - ok 00:16:35.0921 0852 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINXP\system32\DRIVERS\fltMgr.sys 00:16:35.0921 0852 FltMgr - ok 00:16:35.0953 0852 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINXP\system32\drivers\Fs_Rec.sys 00:16:35.0953 0852 Fs_Rec - ok 00:16:35.0953 0852 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINXP\system32\DRIVERS\ftdisk.sys 00:16:35.0953 0852 Ftdisk - ok 00:16:35.0984 0852 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINXP\system32\DRIVERS\GEARAspiWDM.sys 00:16:35.0984 0852 GEARAspiWDM - ok 00:16:36.0015 0852 GGSAFERDriver - ok 00:16:36.0062 0852 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINXP\system32\DRIVERS\msgpc.sys 00:16:36.0062 0852 Gpc - ok 00:16:36.0093 0852 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINXP\system32\DRIVERS\HDAudBus.sys 00:16:36.0093 0852 HDAudBus - ok 00:16:36.0140 0852 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINXP\system32\DRIVERS\hidusb.sys 00:16:36.0140 0852 hidusb - ok 00:16:36.0156 0852 hpn - ok 00:16:36.0187 0852 HTTP (937031c085718c1c04a9c0864625ec6b) C:\WINXP\system32\Drivers\HTTP.sys 00:16:36.0187 0852 HTTP - ok 00:16:36.0187 0852 i2omgmt - ok 00:16:36.0203 0852 i2omp - ok 00:16:36.0218 0852 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINXP\system32\DRIVERS\i8042prt.sys 00:16:36.0218 0852 i8042prt - ok 00:16:36.0234 0852 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINXP\system32\DRIVERS\imapi.sys 00:16:36.0234 0852 Imapi - ok 00:16:36.0234 0852 ini910u - ok 00:16:36.0328 0852 IntcAzAudAddService (fb4293b1eab313c28d4a1b8db61aca72) C:\WINXP\system32\drivers\RtkHDAud.sys 00:16:36.0359 0852 IntcAzAudAddService - ok 00:16:36.0437 0852 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINXP\system32\DRIVERS\intelide.sys 00:16:36.0437 0852 IntelIde - ok 00:16:36.0453 0852 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINXP\system32\DRIVERS\intelppm.sys 00:16:36.0453 0852 intelppm - ok 00:16:36.0468 0852 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINXP\system32\DRIVERS\Ip6Fw.sys 00:16:36.0468 0852 Ip6Fw - ok 00:16:36.0500 0852 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINXP\system32\DRIVERS\ipfltdrv.sys 00:16:36.0500 0852 IpFilterDriver - ok 00:16:36.0500 0852 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINXP\system32\DRIVERS\ipinip.sys 00:16:36.0500 0852 IpInIp - ok 00:16:36.0515 0852 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINXP\system32\DRIVERS\ipnat.sys 00:16:36.0515 0852 IpNat - ok 00:16:36.0531 0852 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINXP\system32\DRIVERS\ipsec.sys 00:16:36.0531 0852 IPSec - ok 00:16:36.0546 0852 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINXP\system32\DRIVERS\irenum.sys 00:16:36.0546 0852 IRENUM - ok 00:16:36.0562 0852 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINXP\system32\DRIVERS\isapnp.sys 00:16:36.0562 0852 isapnp - ok 00:16:36.0593 0852 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINXP\system32\DRIVERS\kbdclass.sys 00:16:36.0593 0852 Kbdclass - ok 00:16:36.0625 0852 kmixer (692bcf44383d056aed41b045a323d378) C:\WINXP\system32\drivers\kmixer.sys 00:16:36.0625 0852 kmixer - ok 00:16:36.0640 0852 KSecDD (c6ebf1d6ad71df30db49b8d3287e1368) C:\WINXP\system32\drivers\KSecDD.sys 00:16:36.0640 0852 KSecDD - ok 00:16:36.0656 0852 L1e (fa46f5d09edf93e0c71fe6500fe3f4ae) C:\WINXP\system32\DRIVERS\l1e51x86.sys 00:16:36.0656 0852 L1e - ok 00:16:36.0656 0852 lbrtfdc - ok 00:16:36.0671 0852 MBAMProtector (69a6268d7f81e53d568ab4e7e991caf3) C:\WINXP\system32\drivers\mbam.sys 00:16:36.0671 0852 MBAMProtector - ok 00:16:36.0687 0852 MBAMSwissArmy - ok 00:16:36.0703 0852 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINXP\system32\drivers\mnmdd.sys 00:16:36.0703 0852 mnmdd - ok 00:16:36.0718 0852 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINXP\system32\drivers\Modem.sys 00:16:36.0718 0852 Modem - ok 00:16:36.0750 0852 Monfilt (9fa7207d1b1adead88ae8eed9cdbbaa5) C:\WINXP\system32\drivers\Monfilt.sys 00:16:36.0765 0852 Monfilt - ok 00:16:36.0796 0852 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINXP\system32\DRIVERS\mouclass.sys 00:16:36.0796 0852 Mouclass - ok 00:16:36.0828 0852 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINXP\system32\DRIVERS\mouhid.sys 00:16:36.0828 0852 mouhid - ok 00:16:36.0843 0852 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINXP\system32\drivers\MountMgr.sys 00:16:36.0843 0852 MountMgr - ok 00:16:36.0859 0852 mraid35x - ok 00:16:36.0859 0852 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINXP\system32\DRIVERS\mrxdav.sys 00:16:36.0859 0852 MRxDAV - ok 00:16:36.0875 0852 MRxSmb (d09b9f0b9960dd41e73127b7814c115f) C:\WINXP\system32\DRIVERS\mrxsmb.sys 00:16:36.0875 0852 MRxSmb - ok 00:16:36.0890 0852 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINXP\system32\drivers\Msfs.sys 00:16:36.0890 0852 Msfs - ok 00:16:36.0921 0852 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINXP\system32\drivers\MSKSSRV.sys 00:16:36.0921 0852 MSKSSRV - ok 00:16:36.0953 0852 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINXP\system32\drivers\MSPCLOCK.sys 00:16:36.0953 0852 MSPCLOCK - ok 00:16:36.0968 0852 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINXP\system32\drivers\MSPQM.sys 00:16:36.0968 0852 MSPQM - ok 00:16:37.0015 0852 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINXP\system32\DRIVERS\mssmbios.sys 00:16:37.0015 0852 mssmbios - ok 00:16:37.0031 0852 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINXP\system32\DRIVERS\ASACPI.sys 00:16:37.0031 0852 MTsensor - ok 00:16:37.0046 0852 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINXP\system32\drivers\Mup.sys 00:16:37.0046 0852 Mup - ok 00:16:37.0046 0852 mv61xx (a4a61d30097c8adaad648ebe204d61ef) C:\WINXP\system32\DRIVERS\mv61xx.sys 00:16:37.0046 0852 mv61xx - ok 00:16:37.0078 0852 mv61xxmm (4578f2d91309bc360b4f67c8a513bc77) C:\WINXP\system32\drivers\mv61xxmm.sys 00:16:37.0078 0852 mv61xxmm - ok 00:16:37.0078 0852 mv64xxmm (6090786daa545a3ec7d34a46a8cd1661) C:\WINXP\system32\drivers\mv64xxmm.sys 00:16:37.0078 0852 mv64xxmm - ok 00:16:37.0093 0852 mvxxmm (f3376efec7d3fd00f577067ad2a0b194) C:\WINXP\system32\drivers\mvxxmm.sys 00:16:37.0093 0852 mvxxmm - ok 00:16:37.0093 0852 NDIS (1df7f42665c94b825322fae71721130d) C:\WINXP\system32\drivers\NDIS.sys 00:16:37.0109 0852 NDIS - ok 00:16:37.0109 0852 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINXP\system32\DRIVERS\ndistapi.sys 00:16:37.0109 0852 NdisTapi - ok 00:16:37.0125 0852 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINXP\system32\DRIVERS\ndisuio.sys 00:16:37.0125 0852 Ndisuio - ok 00:16:37.0140 0852 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINXP\system32\DRIVERS\ndiswan.sys 00:16:37.0140 0852 NdisWan - ok 00:16:37.0140 0852 NDProxy (816460bd4b4acd27937d1d0813e2e9e9) C:\WINXP\system32\drivers\NDProxy.sys 00:16:37.0140 0852 NDProxy - ok 00:16:37.0156 0852 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINXP\system32\DRIVERS\netbios.sys 00:16:37.0156 0852 NetBIOS - ok 00:16:37.0171 0852 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINXP\system32\DRIVERS\netbt.sys 00:16:37.0171 0852 NetBT - ok 00:16:37.0187 0852 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINXP\system32\drivers\Npfs.sys 00:16:37.0187 0852 Npfs - ok 00:16:37.0218 0852 NPPTNT2 (9131fe60adfab595c8da53ad6a06aa31) C:\WINXP\system32\npptNT2.sys 00:16:37.0234 0852 NPPTNT2 - ok 00:16:37.0250 0852 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINXP\system32\drivers\Ntfs.sys 00:16:37.0265 0852 Ntfs - ok 00:16:37.0296 0852 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINXP\system32\drivers\Null.sys 00:16:37.0296 0852 Null - ok 00:16:37.0484 0852 nv (b9b1bb146eb9a83dcf0f5635b09d3d43) C:\WINXP\system32\DRIVERS\nv4_mini.sys 00:16:37.0531 0852 nv - ok 00:16:37.0546 0852 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINXP\system32\DRIVERS\nwlnkflt.sys 00:16:37.0546 0852 NwlnkFlt - ok 00:16:37.0562 0852 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINXP\system32\DRIVERS\nwlnkfwd.sys 00:16:37.0562 0852 NwlnkFwd - ok 00:16:37.0578 0852 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINXP\system32\drivers\Parport.sys 00:16:37.0578 0852 Parport - ok 00:16:37.0609 0852 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINXP\system32\drivers\PartMgr.sys 00:16:37.0609 0852 PartMgr - ok 00:16:37.0640 0852 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINXP\system32\drivers\ParVdm.sys 00:16:37.0640 0852 ParVdm - ok 00:16:37.0656 0852 PCI (a219903ccf74233761d92bef471a07b1) C:\WINXP\system32\DRIVERS\pci.sys 00:16:37.0656 0852 PCI - ok 00:16:37.0656 0852 PCIDump - ok 00:16:37.0671 0852 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINXP\system32\drivers\PCIIde.sys 00:16:37.0671 0852 PCIIde - ok 00:16:37.0687 0852 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINXP\system32\drivers\Pcmcia.sys 00:16:37.0687 0852 Pcmcia - ok 00:16:37.0703 0852 PDCOMP - ok 00:16:37.0703 0852 PDFRAME - ok 00:16:37.0703 0852 PDRELI - ok 00:16:37.0718 0852 PDRFRAME - ok 00:16:37.0718 0852 perc2 - ok 00:16:37.0734 0852 perc2hib - ok 00:16:37.0750 0852 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINXP\system32\DRIVERS\raspptp.sys 00:16:37.0750 0852 PptpMiniport - ok 00:16:37.0765 0852 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINXP\system32\DRIVERS\psched.sys 00:16:37.0765 0852 PSched - ok 00:16:37.0765 0852 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINXP\system32\DRIVERS\ptilink.sys 00:16:37.0765 0852 Ptilink - ok 00:16:37.0796 0852 PxHelp20 (40fedd328f98245ad201cf5f9f311724) C:\WINXP\system32\Drivers\PxHelp20.sys 00:16:37.0796 0852 PxHelp20 - ok 00:16:37.0796 0852 ql1080 - ok 00:16:37.0812 0852 Ql10wnt - ok 00:16:37.0812 0852 ql12160 - ok 00:16:37.0812 0852 ql1240 - ok 00:16:37.0828 0852 ql1280 - ok 00:16:37.0843 0852 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINXP\system32\DRIVERS\rasacd.sys 00:16:37.0843 0852 RasAcd - ok 00:16:37.0859 0852 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINXP\system32\DRIVERS\rasl2tp.sys 00:16:37.0859 0852 Rasl2tp - ok 00:16:37.0875 0852 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINXP\system32\DRIVERS\raspppoe.sys 00:16:37.0875 0852 RasPppoe - ok 00:16:37.0875 0852 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINXP\system32\DRIVERS\raspti.sys 00:16:37.0875 0852 Raspti - ok 00:16:37.0890 0852 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINXP\system32\DRIVERS\rdbss.sys 00:16:37.0890 0852 Rdbss - ok 00:16:37.0906 0852 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINXP\system32\DRIVERS\RDPCDD.sys 00:16:37.0906 0852 RDPCDD - ok 00:16:37.0937 0852 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINXP\system32\DRIVERS\rdpdr.sys 00:16:37.0937 0852 rdpdr - ok 00:16:37.0968 0852 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINXP\system32\drivers\RDPWD.sys 00:16:37.0968 0852 RDPWD - ok 00:16:38.0000 0852 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINXP\system32\DRIVERS\redbook.sys 00:16:38.0000 0852 redbook - ok 00:16:38.0046 0852 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINXP\system32\DRIVERS\secdrv.sys 00:16:38.0046 0852 Secdrv - ok 00:16:38.0046 0852 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINXP\system32\DRIVERS\serenum.sys 00:16:38.0046 0852 serenum - ok 00:16:38.0062 0852 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINXP\system32\DRIVERS\serial.sys 00:16:38.0062 0852 Serial - ok 00:16:38.0093 0852 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINXP\system32\drivers\Sfloppy.sys 00:16:38.0093 0852 Sfloppy - ok 00:16:38.0093 0852 Simbad - ok 00:16:38.0125 0852 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINXP\system32\DRIVERS\SONYPVU1.SYS 00:16:38.0125 0852 SONYPVU1 - ok 00:16:38.0125 0852 Sparrow - ok 00:16:38.0156 0852 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINXP\system32\drivers\splitter.sys 00:16:38.0156 0852 splitter - ok 00:16:38.0203 0852 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINXP\system32\DRIVERS\sr.sys 00:16:38.0203 0852 sr - ok 00:16:38.0218 0852 Srv (70cd8b8dd2a680b128617c19eb0ab94f) C:\WINXP\system32\DRIVERS\srv.sys 00:16:38.0218 0852 Srv - ok 00:16:38.0250 0852 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINXP\system32\DRIVERS\swenum.sys 00:16:38.0250 0852 swenum - ok 00:16:38.0265 0852 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINXP\system32\drivers\swmidi.sys 00:16:38.0265 0852 swmidi - ok 00:16:38.0265 0852 symc810 - ok 00:16:38.0281 0852 symc8xx - ok 00:16:38.0281 0852 sym_hi - ok 00:16:38.0281 0852 sym_u3 - ok 00:16:38.0312 0852 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINXP\system32\drivers\sysaudio.sys 00:16:38.0312 0852 sysaudio - ok 00:16:38.0375 0852 Tcpip (a5bc817bb84dcb9e71719ff868144124) C:\WINXP\system32\DRIVERS\tcpip.sys 00:16:38.0375 0852 Tcpip - ok 00:16:38.0390 0852 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINXP\system32\drivers\TDPIPE.sys 00:16:38.0390 0852 TDPIPE - ok 00:16:38.0437 0852 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINXP\system32\drivers\TDTCP.sys 00:16:38.0437 0852 TDTCP - ok 00:16:38.0453 0852 TermDD (88155247177638048422893737429d9e) C:\WINXP\system32\DRIVERS\termdd.sys 00:16:38.0453 0852 TermDD - ok 00:16:38.0468 0852 TosIde - ok 00:16:38.0500 0852 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINXP\system32\drivers\Udfs.sys 00:16:38.0500 0852 Udfs - ok 00:16:38.0500 0852 ultra - ok 00:16:38.0515 0852 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINXP\system32\DRIVERS\update.sys 00:16:38.0515 0852 Update - ok 00:16:38.0562 0852 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\WINXP\system32\Drivers\usbaapl.sys 00:16:38.0562 0852 USBAAPL - ok 00:16:38.0593 0852 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINXP\system32\DRIVERS\usbccgp.sys 00:16:38.0593 0852 usbccgp - ok 00:16:38.0609 0852 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINXP\system32\DRIVERS\usbehci.sys 00:16:38.0609 0852 usbehci - ok 00:16:38.0640 0852 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINXP\system32\DRIVERS\usbhub.sys 00:16:38.0640 0852 usbhub - ok 00:16:38.0640 0852 usbprint (a717c8721046828520c9edf31288fc00) C:\WINXP\system32\DRIVERS\usbprint.sys 00:16:38.0640 0852 usbprint - ok 00:16:38.0656 0852 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINXP\system32\DRIVERS\usbscan.sys 00:16:38.0656 0852 usbscan - ok 00:16:38.0671 0852 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINXP\system32\DRIVERS\USBSTOR.SYS 00:16:38.0671 0852 USBSTOR - ok 00:16:38.0671 0852 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINXP\system32\DRIVERS\usbuhci.sys 00:16:38.0671 0852 usbuhci - ok 00:16:38.0703 0852 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINXP\System32\drivers\vga.sys 00:16:38.0703 0852 VgaSave - ok 00:16:38.0703 0852 ViaIde - ok 00:16:38.0718 0852 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINXP\system32\drivers\VolSnap.sys 00:16:38.0718 0852 VolSnap - ok 00:16:38.0734 0852 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINXP\system32\DRIVERS\wanarp.sys 00:16:38.0734 0852 Wanarp - ok 00:16:38.0734 0852 WDICA - ok 00:16:38.0765 0852 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINXP\system32\drivers\wdmaud.sys 00:16:38.0765 0852 wdmaud - ok 00:16:38.0812 0852 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINXP\system32\DRIVERS\WudfPf.sys 00:16:38.0812 0852 WudfPf - ok 00:16:38.0828 0852 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINXP\system32\DRIVERS\wudfrd.sys 00:16:38.0828 0852 WudfRd - ok 00:16:38.0828 0852 XDva385 - ok 00:16:38.0843 0852 XDva387 - ok 00:16:38.0859 0852 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 00:16:38.0921 0852 \Device\Harddisk0\DR0 - ok 00:16:38.0921 0852 Boot (0x1200) (079d83d72b1c92bdb0051ab3dca0f6b6) \Device\Harddisk0\DR0\Partition0 00:16:38.0921 0852 \Device\Harddisk0\DR0\Partition0 - ok 00:16:38.0937 0852 Boot (0x1200) (1596dca7a70b9a6c10e78b2c1e299963) \Device\Harddisk0\DR0\Partition1 00:16:38.0937 0852 \Device\Harddisk0\DR0\Partition1 - ok 00:16:38.0937 0852 ============================================================ 00:16:38.0937 0852 Scan finished 00:16:38.0937 0852 ============================================================ 00:16:38.0953 1100 Detected object count: 0 00:16:38.0953 1100 Actual detected object count: 0 For example I'm currently running Civilization V The System idle Process hogs half of the CPU Usage, which shouldn't and never happened before. Img - http://upic.me/i/j2/cem51.jpg What strange is that the lag will come only when I'm actually playing the game, you know like when there are movements and graphic ? But when I'm on the main menu screen of the games, I just don't feel the lag. While the System Idle Process is hogging the CPU at the same amount in both situation. weird ehh ? :\ This problem goes to all of my game but strangely again it doesn't go with software like Photoshop CS5. It seems to work fine for me even though the System Idle is hogging over half of the CPU. Could this be some kind of graphic card problem instead ?In that screenshot, it clearly shows that 50% of the CPU is being used by Civilization V, and 50% is used by System Idle Process. The System Idle Process does not hog the CPU by any means. That is showing that 50% of the CPU is free to use. Start other programs that need to thread objects in the CPU and see if the Idle process goes down. It most likely will. That processor is lucky enough to even run Civilization V. IMO, that is not good enough. Civ. V needs either: A. Quad core processor at 1.8 GHz (required by the game makers) B. Dual core processor at 4.0 GHz (my own recommendation) The Minimum requirements on a game is specifically needed for the program to simply install and run at reduced functionality. However, the recommended requirements on a game is what the game is supposed to run at, in full functionality. If you're not running that game in a high-performance environment...expect trouble!FYI: I think you are seeing only 50% CPU usage because that program is not multithreaded (uses multiple cores).I have tried running Civilization V, Warcraft III, Starcraft all at the same time and during gameplay. The System Idle Process still keeps using 50-50 CPU when it should being used for either Starcraft or Warcraft III, but no luck. While War3 and Starcraft is running and uses some Memory, The CPU still goes for System Idle Process instead. http://upic.me/i/63/56wtf.jpg List by Memory Usage http://upic.me/i/7k/r0wth.jpg My Video settings of Civilization V (Default Setting) http://upic.me/i/m1/87omg.jpg I have used this setting since I installed the game and it worked just fine (smooth), until now its lag is killing me bad and if no solution could be find, I guess I will have to format my C and see if that works... If not the System Idle Process, what could be any other ? Because you see when game lags I just find out what's going on from Task Manager first and this is what I got. Could it be some kind of machine overheating ? I don't know now. ;/ Ps. It happens to Warcraft III also, not only the Civilization V, if you are trying to say my spec is too low for it. D: and is there anyway to force my computer to uses 99% of CPU on something and don't let it keep in idle state ? Thx alot though so far Did you notice in this screenshot that Warcraft 3 was not using the CPU: http://upic.me/i/63/56wtf.jpg ?? Explorer.exe is using 1%, System Idle at 49, and Civ V using 50. With 51% of the processor being used for Explorer and Civ V, the other 49% is free to use, occupied by the System Idle Process. You don't seem to understand this computing method. Either A: you don't believe my expertise, or B: you seriously think something is wrong with the Idle task in the Task Manager. Allow me to quote for you the explanation of the System Idle process so you kindly understand here: Quote ...the System Idle Process contains one or more kernel threads which run when no other runnable thread can be scheduled on a CPU. For example, there may be no runnable thread in the system, or all runnable threads are already running on a different CPU. In a multiprocessor system, there is one idle thread associated with each CPU. Read articles for backupo references, please: http://en.wikipedia.org/wiki/System_Idle_Process and http://en.wikipedia.org/wiki/Idle_task |
|
| 394. |
Solve : Bad Image: WIKI.DLL? |
|
Answer» HI DAVE, Sorry this took so long. I have completed the steps you suggested and I believe that I am through with the malware problem. I still have to reinstall the paid-for AVG and activate its firewall (though that evidently didn't help me in the first place?) I have had several instances where the laptop has not shut down correctly. I select start\turn off computer\turn off and I get the screen that says that windows is shutting down but then it stalls there. I wait for 5 or 10 minutes and then just power off the machine. It doesn't ALWAYS happen but I'd say about every third or fourth time so far. Thanks for your help. Mike I don't believe that the shut-down problem is caused by any infections. If it PERSISTS, start a NEW thread in the proper forum. I will lock this thread.If you need it re-opened, please send me a pm. |
|
| 395. |
Solve : Any effective solution to thwart the 'Malvertising'?? |
|
Answer» Hello There! |
|
| 396. |
Solve : Could use some help, might be infected but i'm not sure? |
|
Answer» I hope this will WORK. I hit save to desktop but i don't know what happened cuz it's not there, so i took this log instead. if you need the other one, tell me, and i'll rerun the scan. Also I didn't remove anything with this scan, i just scanned it as suggested (hope that was the right thing to do). Should i have done that or should i do it now, or will it matter.No. It's just iWin games. Please run ESET again and clean the infections and post the log.ok, thanks. It may be a day before i can run the eset, but i'll GET there....here you go C:\Documents and Settings\Candie\My Documents\Downloads\SetupPlaySushi(2).exe a variant of Win32/Adware.Gamevance.AS application cleaned by deleting - quarantined C:\Documents and Settings\Candie\My Documents\Downloads\SetupPlaySushi(3).exe a variant of Win32/Adware.Gamevance.AS application cleaned by deleting - quarantined C:\Documents and Settings\Candie\My Documents\Downloads\SetupPlaySushi.exe a variant of Win32/Adware.Gamevance.AS application cleaned by deleting - quarantined C:\Program Files\iWonEI\Installr\1.bin\jfEIPlug.dll a variant of Win32/Toolbar.MyWebSearch application cleaned by deleting - quarantined C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1088\A0089734.DLL a variant of Win32/Toolbar.MyWebSearch application cleaned by deleting - quarantined C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1088\A0089877.DLL Win32/Toolbar.AskSBar application cleaned by deleting - quarantined C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1094\A0090774.dll a variant of Win32/Toolbar.MyWebSearch application cleaned by deleting - quarantined Great. That looks good. If there are no other issues, it's time for some cleanup. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. *********************************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. ********************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable SHOPPING sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX CONTROLS are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!Thanks Super Dave, i'll work on the clean up tonite when i got more time. Should I also uninstall any of the other programs i used like ESET or SysRoot? Also i need to delete the mcafee which was downloaded and installed , can i do that thru add/remove programs or is there something special i need to do? And last question, regarding firewalls, i have norton internet security which has a firewall so do i need to install one? Your note says to have only one firewall and i don't want to goof things up. Thanks, for helping me out. Quote Should I also uninstall any of the other programs i used like ESET or SysRoot?Yes. Any tools we use can be uninstalled or deleted. You can keep SAS and MBAM, if you wish. Update them and run them on a regular basis. Quote Also i need to delete the mcafee which was downloaded and installed , can i do that thru add/remove programs or is there something special i need to do?Yes. You should do through add/remove programs. If you have problems removing it, use the McAfee Removal Tool below. McAfee Consumer Products Removal tool (MCPR.exe) Quote norton internet security which has a firewall so do i need to install one?That's considered a third-party firewall. Quote Thanks, for helping me out.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 397. |
Solve : Another Virus? Computer just reboots.? |
|
Answer» Hello and thank you for looking at my thread TODAY. |
|
| 398. |
Solve : Wife's laptop WiFi will not stay connected to router. I think? |
|
Answer» My WIFE has a HP9000 laptop running Windows XP. She is using WiFi connected to a Netgear wirelss router in my home network. My base computer is a desktop running Windows 7 64 bitand is connected to the router via ethernet cable. For a couple of years now this system has been working satisfactorily....but... |
|
| 399. |
Solve : Someone else got password help :)? |
|
Answer» Hey GUYS I'm new on this forum and I'm here because someone ELSE is using my FACEBOOK, gmail and hotmail accounts. I haven't given my passwords to anybody and I have also just recently changed my password. How do I prevent this from happening again ? I have AVAST Anti Virus and I run Win XP. |
|
| 400. |
Solve : Panda USB Vaccine and Digital Cameras? |
|
Answer» Hi |
|