1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Won't let me do anything

Discussion in 'Malware and Virus Removal Archive' started by Jubis, 2010/09/02.

Thread Status:
Not open for further replies.
  1. 2010/09/02
    Jubis

    Jubis Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    58
    Likes Received:
    0
    [Inactive] Won't let me do anything

    Hello, I am currently on my desktop because my laptop cannot even get on the internet to post the required logs. It is a "security suite" thing that keeps popping up telling me I have xxx amount of viruses and I have tried to restore to a previous restore point and it won't even let me do that. Thank you for reading,
    Nick
     
  2. 2010/09/02
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Do you have USB flash drive?
     

  3. to hide this advert.

  4. 2010/09/02
    Jubis

    Jubis Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    58
    Likes Received:
    0
    I have an external hard drive. Will that be okay?
     
  5. 2010/09/02
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    It depends.
    If you have some important stuff there, I don't want you to connect that drive to seriously infected computer.
    You can get 4GB flash drive for about 15 bucks.
     
  6. 2010/09/02
    Jubis

    Jubis Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    58
    Likes Received:
    0
    Okay, I got one.
     
  7. 2010/09/02
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Cool :)

    First, we'll protect your good computer, since we'll be using USB stick to move files between good and bad computer.

    On good computer....
    Download, and run Flash Disinfector, and save it to your desktop.

    *Please disable any AV / ScriptBlockers as they might detect Flash Disinfector to be malicious and block it. Hence, the failure in executing. You can enable them back after the cleaning process*

    • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
    • The utility may ask you to insert your flash drive and/or other removable drives. Please do so and allow the utility to clean up those drives as well.
    • Hold down the Shift key when inserting the drive until Windows detects it to keep autorun.inf from executing if it is present.
    • Wait until it has finished scanning and then exit the program.
    • Reboot your computer when done.
    Note: As part of its routine, Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive that was plugged in when you ran it. Do not delete this folder...it will help protect your drives from future infection by keeping the autorun file from being installed on the root drive and running other malicious files.

    ===============================================================

    Now, download following tools on good computer and transfer them to bad computer, using USB stick.
    All three tools can be run from Safe Mode, if needed.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    * Rkill.com
    * Rkill.scr
    * Rkill.pif
    * Rkill.exe


    • * Double-click on the Rkill desktop icon to run the tool.
      * If using Vista or Windows 7 right-click on it and choose Run As Administrator.
      * A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
      * If not, delete the file, then download and use the one provided in Link 2.
      * If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
      * Do not reboot until instructed.
      * If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run then try to immediately run the following.

    Now download and run exeHelper.


    • * Please download exeHelper from Raktor to your desktop.
      * Double-click on exeHelper.com to run the fix.
      * A black window should pop up, press any key to close once the fix is completed.
      * A log file named log.txt will be created in the directory where you ran exeHelper.com
      * Attach the log.txt file to your next message.

    Note: If the window shows a message that says "Error deleting file ", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    ===================================

    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    [color= "Blue"]**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**[/color]
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on [color= "Red"]this link[/color] to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • [color= "Red"]WARNING:[/color] Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  8. 2010/09/02
    Jubis

    Jubis Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    58
    Likes Received:
    0
    I get an error on Bad Computer when running combofix saying
    Incompatible OS. Combofix only works for workstations with Windows 2000 and XP
     
  9. 2010/09/02
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    My fault.
    You didn't say, I didn't check, but I can see now, you're running Windows 7 64-bit.
    Combofix won't run on your system.

    Instead of Combofix....

    Download MBAM, listed below on good computer, install it on bad computer.
    Before you attempt to run it, run rKill and exehelper first.

    Download Malwarebytes' Anti-Malware (aka MBAM): http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform quick scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    Be sure to restart the computer.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
     
  10. 2010/09/02
    Jubis

    Jubis Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    58
    Likes Received:
    0
    Here you are.
    Thank you so much for taking time out of your night to help me.

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4532

    Windows 6.1.7600 (Safe Mode)
    Internet Explorer 8.0.7600.16385

    9/2/2010 10:32:57 PM
    mbam-log-2010-09-02 (22-32-57).txt

    Scan type: Quick scan
    Objects scanned: 137131
    Time elapsed: 4 minute(s), 51 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 3
    Registry Values Infected: 30
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 27

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CURRENT_USER\Software\Antimalware Doctor Inc (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\wnxmal (Rogue.SecuritySuite) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\izamif (Trojan.Hiloti) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvdeiejlkp (Malware.Packer.Gen) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvdeiejlkp (Malware.Packer.Gen) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqvpc (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqvpc (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mquse (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mquse (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvdeiejlpsc (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvdeiejlpsc (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvdeiejlora (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvdeiejlora (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mquuf (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mquuf (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvdeiejlqf (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvdeiejlqf (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvdeiejlqc (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvdeiejlqc (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvdeiejlud (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvdeiejlud (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqtw+ (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqtw+ (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvdeiejlrf (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvdeiejlrf (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqurb (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqurb (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ounnxcyw (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mediafix70700en02.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\com+ manager (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vteruferosul (Trojan.Agent.U) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Users\Nick\AppData\Local\srke32.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.
    C:\Users\Nick\AppData\Local\Temp\c81u7.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
    C:\Windows\win32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Windows\svchost.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Users\Nick\AppData\Local\Temp\taskmgr.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Users\Nick\AppData\Local\Temp\iexplarer.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Windows\spoolsv.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Users\Nick\AppData\Local\Temp\user.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Users\Nick\AppData\Local\Temp\win.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Users\Nick\AppData\Local\Temp\system.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Windows\nvsvc32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Users\Nick\AppData\Local\Temp\smss.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Windows\taskmgr.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Users\Nick\AppData\Local\vpcyrschs\ovmvuttshdw.exe (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
    C:\Windows\System32\c8urt.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
    C:\Users\Nick\AppData\Local\Temp\1592234928.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Users\Nick\AppData\Local\Temp\iexplorer.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
    C:\Users\Nick\AppData\Local\Temp\lv4kirvr.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
    C:\Users\Nick\AppData\Local\Temp\md3hn1ka8rxesd.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Users\Nick\AppData\Local\Temp\mkcxhunr.exe (Trojan.Hiloti) -> Quarantined and deleted successfully.
    C:\Users\Nick\AppData\Local\Temp\wtpvaae.exe (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
    C:\Users\Nick\AppData\Local\Temp\xsacwmonre.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Users\Nick\AppData\Roaming\AA1FF08C41A91E7357D162DD95CFD307\mediafix70700en02.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Users\Nick\AppData\Local\Temp\skaioejiesfjoee.tmp (Malware.Trace) -> Quarantined and deleted successfully.
    C:\Users\Nick\.COMMgr\complmgr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Users\Nick\Local Settings\Application Data\Windows Server\admin.txt (Malware.Trace) -> Quarantined and deleted successfully.
    C:\Users\Nick\AppData\Local\ecafaxac.dll (Trojan.Agent.U) -> Quarantined and deleted successfully.
     
  11. 2010/09/02
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Very good :)
    Now, I want you to try to restart in normal mode, update MBAM and run it again.
     
  12. 2010/09/02
    Jubis

    Jubis Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    58
    Likes Received:
    0
    Here you are. :)

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4533

    Windows 6.1.7600
    Internet Explorer 8.0.7600.16385

    9/2/2010 11:00:38 PM
    mbam-log-2010-09-02 (23-00-38).txt

    Scan type: Quick scan
    Objects scanned: 137756
    Time elapsed: 3 minute(s), 34 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
     
  13. 2010/09/02
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Wonderful :)
    We're getting somewhere :)

    ================================================================

    Download MBRCheck to your desktop

    Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
    It will show a black screen with some data on it.
    Enter N to exit.
    A report called MBRcheckxxxx.txt will be on your desktop
    Open this report and post its content in your next reply.

    ================================================================

    Download SUPERAntiSpyware Free for Home Users:
    http://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes ". If not, update the definitions before scanning by selecting "Check for Updates ". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * Close SUPERAntiSpyware.

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; pick Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Under "Configuration and Preferences ", click the Preferences button.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are checked (leave all others unchecked):

    • Close browsers before scanning.
      Scan for tracking cookies.
      Terminate memory threats before quarantining.
    * Click the "Close" button to leave the control center screen.
    * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, under "Complete Scan ", choose Perform Complete Scan.
    * Click "Next" to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK ".
    * Make sure everything has a checkmark next to it and click "Next ".
    * A notification will appear that "Quarantine and Removal is Complete ". Click "OK" and then click the "Finish" button to return to the main menu.
    * If asked if you want to reboot, click "Yes ".
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.

    • Click Preferences, then click the Statistics/Logs tab.
      Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
      If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
      Please copy and paste the Scan Log results in your next reply.
    * Click Close to exit the program.
    Post SUPERAntiSpyware log.

    ==============================================================

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Under the Custom Scan box paste this in:


    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\*. /mp /s
    /md5start
    /md5stop
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs


    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  14. 2010/09/04
    Jubis

    Jubis Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    58
    Likes Received:
    0
    Sorry it took me a while... I had to go to work.

    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows 7 Home Premium Edition
    Windows Information: (build 7600), 64-bit
    Base Board Manufacturer: Dell Inc.
    BIOS Manufacturer: Dell Inc.
    System Manufacturer: Dell Inc.
    System Product Name: Studio 1558
    Logical Drives Mask: 0x0100001c

    Kernel Drivers (total 191):
    0x02A11000 \SystemRoot\system32\ntoskrnl.exe
    0x02FED000 \SystemRoot\system32\hal.dll
    0x00BB0000 \SystemRoot\system32\kdcom.dll
    0x00C4B000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
    0x00C8F000 \SystemRoot\system32\PSHED.dll
    0x00CA3000 \SystemRoot\system32\CLFS.SYS
    0x00D01000 \SystemRoot\system32\CI.dll
    0x00E98000 \SystemRoot\system32\drivers\Wdf01000.sys
    0x00F3C000 \SystemRoot\system32\drivers\WDFLDR.SYS
    0x00F4B000 \SystemRoot\system32\DRIVERS\ACPI.sys
    0x00FA2000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
    0x00FAB000 \SystemRoot\system32\DRIVERS\msisadrv.sys
    0x00FB5000 \SystemRoot\system32\DRIVERS\pci.sys
    0x00FE8000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
    0x00E00000 \SystemRoot\System32\drivers\partmgr.sys
    0x00E15000 \SystemRoot\system32\DRIVERS\compbatt.sys
    0x00E1E000 \SystemRoot\system32\DRIVERS\BATTC.SYS
    0x00E2A000 \SystemRoot\system32\DRIVERS\volmgr.sys
    0x0109F000 \SystemRoot\System32\drivers\volmgrx.sys
    0x010FB000 \SystemRoot\System32\drivers\mountmgr.sys
    0x01115000 \SystemRoot\system32\DRIVERS\atapi.sys
    0x0111E000 \SystemRoot\system32\DRIVERS\ataport.SYS
    0x01148000 \SystemRoot\system32\DRIVERS\msahci.sys
    0x01153000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
    0x01163000 \SystemRoot\system32\DRIVERS\amdxata.sys
    0x0116E000 \SystemRoot\system32\drivers\fltmgr.sys
    0x011BA000 \SystemRoot\system32\drivers\fileinfo.sys
    0x011CE000 \SystemRoot\System32\Drivers\PxHlpa64.sys
    0x01231000 \SystemRoot\System32\Drivers\Ntfs.sys
    0x01000000 \SystemRoot\System32\Drivers\msrpc.sys
    0x013D4000 \SystemRoot\System32\Drivers\ksecdd.sys
    0x0148A000 \SystemRoot\System32\Drivers\cng.sys
    0x014FD000 \SystemRoot\System32\drivers\pcw.sys
    0x0150E000 \SystemRoot\System32\Drivers\Fs_Rec.sys
    0x0166B000 \SystemRoot\system32\drivers\ndis.sys
    0x0175D000 \SystemRoot\system32\drivers\NETIO.SYS
    0x017BD000 \SystemRoot\System32\Drivers\ksecpkg.sys
    0x01600000 \SystemRoot\system32\DRIVERS\volsnap.sys
    0x0164C000 \SystemRoot\system32\DRIVERS\stdflt.sys
    0x01654000 \SystemRoot\System32\Drivers\spldr.sys
    0x01518000 \SystemRoot\System32\drivers\rdyboost.sys
    0x017E8000 \SystemRoot\System32\Drivers\mup.sys
    0x0165C000 \SystemRoot\System32\drivers\hwpolicy.sys
    0x01552000 \SystemRoot\System32\DRIVERS\fvevol.sys
    0x0158C000 \SystemRoot\system32\DRIVERS\disk.sys
    0x015A2000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
    0x01413000 \SystemRoot\system32\DRIVERS\cdrom.sys
    0x0143D000 \SystemRoot\System32\Drivers\Null.SYS
    0x01446000 \SystemRoot\System32\Drivers\Beep.SYS
    0x0144D000 \SystemRoot\System32\drivers\vga.sys
    0x0145B000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
    0x013EE000 \SystemRoot\System32\drivers\watchdog.sys
    0x01480000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0x015F7000 \SystemRoot\system32\drivers\rdpencdd.sys
    0x01200000 \SystemRoot\system32\drivers\rdprefmp.sys
    0x01209000 \SystemRoot\System32\Drivers\Msfs.SYS
    0x01214000 \SystemRoot\System32\Drivers\Npfs.SYS
    0x02A01000 \SystemRoot\System32\drivers\tcpip.sys
    0x00E3F000 \SystemRoot\System32\drivers\fwpkclnt.sys
    0x0105E000 \SystemRoot\system32\DRIVERS\tdx.sys
    0x0107C000 \SystemRoot\system32\DRIVERS\TDI.SYS
    0x03C13000 \SystemRoot\system32\drivers\afd.sys
    0x03C9D000 \SystemRoot\System32\DRIVERS\netbt.sys
    0x03CE2000 \SystemRoot\system32\DRIVERS\wfplwf.sys
    0x03CEB000 \SystemRoot\system32\DRIVERS\pacer.sys
    0x03D11000 \SystemRoot\system32\DRIVERS\vwififlt.sys
    0x03D27000 \SystemRoot\system32\DRIVERS\netbios.sys
    0x03D36000 \SystemRoot\system32\DRIVERS\wanarp.sys
    0x03D51000 \SystemRoot\system32\DRIVERS\termdd.sys
    0x03D65000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0x03DB6000 \SystemRoot\system32\drivers\nsiproxy.sys
    0x03DC2000 \SystemRoot\system32\DRIVERS\mssmbios.sys
    0x03DCD000 \SystemRoot\System32\drivers\discache.sys
    0x03DDC000 \SystemRoot\System32\Drivers\dfsc.sys
    0x03C00000 \SystemRoot\system32\DRIVERS\blbdrive.sys
    0x011DA000 \SystemRoot\system32\DRIVERS\tunnel.sys
    0x0467F000 \SystemRoot\system32\DRIVERS\igdkmd64.sys
    0x03E4D000 \SystemRoot\System32\drivers\dxgkrnl.sys
    0x03F41000 \SystemRoot\System32\drivers\dxgmms1.sys
    0x03F87000 \SystemRoot\system32\DRIVERS\HECIx64.sys
    0x03F98000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0x03FA9000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0x03E00000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
    0x0437D000 \SystemRoot\system32\DRIVERS\risdpe64.sys
    0x04396000 \SystemRoot\system32\DRIVERS\rimspe64.sys
    0x04000000 \SystemRoot\system32\DRIVERS\rixdpe64.sys
    0x04056000 \SystemRoot\system32\DRIVERS\1394ohci.sys
    0x043AF000 \SystemRoot\system32\DRIVERS\Rt64win7.sys
    0x04094000 \SystemRoot\system32\DRIVERS\i8042prt.sys
    0x040B2000 \SystemRoot\system32\DRIVERS\kbdclass.sys
    0x04600000 \SystemRoot\system32\DRIVERS\SynTP.sys
    0x040C1000 \SystemRoot\system32\DRIVERS\USBD.SYS
    0x043EE000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0x03E24000 \SystemRoot\system32\DRIVERS\Acceler.sys
    0x03E30000 \SystemRoot\system32\DRIVERS\intelppm.sys
    0x0464B000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
    0x040C3000 \SystemRoot\system32\DRIVERS\CmBatt.sys
    0x04654000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
    0x04664000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
    0x00DC1000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0x04DE3000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0x00C00000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0x00C2F000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0x05082000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0x050A3000 \SystemRoot\system32\DRIVERS\rassstp.sys
    0x050BD000 \SystemRoot\system32\DRIVERS\swenum.sys
    0x050BF000 \SystemRoot\system32\DRIVERS\ks.sys
    0x05102000 \SystemRoot\system32\DRIVERS\umbus.sys
    0x05114000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0x0516E000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0x05000000 \SystemRoot\system32\DRIVERS\stwrt64.sys
    0x05183000 \SystemRoot\system32\DRIVERS\portcls.sys
    0x051C0000 \SystemRoot\system32\DRIVERS\drmk.sys
    0x051E2000 \SystemRoot\system32\drivers\ksthunk.sys
    0x05E9C000 \SystemRoot\system32\drivers\HdAudio.sys
    0x00030000 \SystemRoot\System32\win32k.sys
    0x05EF8000 \SystemRoot\System32\drivers\Dxapi.sys
    0x05F04000 \SystemRoot\system32\DRIVERS\usbccgp.sys
    0x05F21000 \SystemRoot\System32\Drivers\usbvideo.sys
    0x05F4F000 \SystemRoot\system32\DRIVERS\CtClsFlt.sys
    0x05F7A000 \SystemRoot\system32\DRIVERS\udfs.sys
    0x05FCF000 \SystemRoot\System32\Drivers\crashdmp.sys
    0x05FDD000 \SystemRoot\System32\Drivers\dump_dumpata.sys
    0x05FE9000 \SystemRoot\System32\Drivers\dump_msahci.sys
    0x05E00000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
    0x00470000 \SystemRoot\System32\TSDDD.dll
    0x00670000 \SystemRoot\System32\cdd.dll
    0x05E21000 \SystemRoot\system32\drivers\luafv.sys
    0x05E44000 \SystemRoot\system32\drivers\WudfPf.sys
    0x05E65000 \SystemRoot\system32\DRIVERS\lltdio.sys
    0x024F0000 \SystemRoot\system32\DRIVERS\nwifi.sys
    0x02543000 \SystemRoot\system32\DRIVERS\ndisuio.sys
    0x02556000 \SystemRoot\system32\DRIVERS\rspndr.sys
    0x02400000 \SystemRoot\system32\drivers\HTTP.sys
    0x024C8000 \SystemRoot\system32\DRIVERS\bowser.sys
    0x0256E000 \SystemRoot\System32\drivers\mpsdrv.sys
    0x02586000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0x03691000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
    0x036DF000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
    0x03702000 \SystemRoot\system32\drivers\peauth.sys
    0x037A8000 \SystemRoot\System32\Drivers\secdrv.SYS
    0x037B3000 \SystemRoot\System32\DRIVERS\srvnet.sys
    0x037E0000 \SystemRoot\System32\drivers\tcpipreg.sys
    0x03600000 \SystemRoot\System32\DRIVERS\srv2.sys
    0x0622B000 \SystemRoot\System32\DRIVERS\srv.sys
    0x062C1000 \SystemRoot\system32\drivers\BCM42RLY.sys
    0x062CA000 \SystemRoot\System32\Drivers\fastfat.SYS
    0x040C8000 \SystemRoot\system32\DRIVERS\bcmwl664.sys
    0x0639A000 \SystemRoot\system32\DRIVERS\vwifibus.sys
    0x063DF000 \SystemRoot\system32\DRIVERS\monitor.sys
    0x06200000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
    0x774F0000 \Windows\System32\ntdll.dll
    0x48500000 \Windows\System32\smss.exe
    0xFF810000 \Windows\System32\apisetschema.dll
    0xFF3B0000 \Windows\System32\autochk.exe
    0xFF7E0000 \Windows\System32\imagehlp.dll
    0xFF660000 \Windows\System32\urlmon.dll
    0xFF5C0000 \Windows\System32\clbcatq.dll
    0xFF490000 \Windows\System32\rpcrt4.dll
    0xFE700000 \Windows\System32\shell32.dll
    0xFE620000 \Windows\System32\advapi32.dll
    0xFE5A0000 \Windows\System32\difxapi.dll
    0xFE570000 \Windows\System32\imm32.dll
    0xFE550000 \Windows\System32\sechost.dll
    0x773D0000 \Windows\System32\kernel32.dll
    0xFE4B0000 \Windows\System32\msvcrt.dll
    0xFE250000 \Windows\System32\iertutil.dll
    0xFE170000 \Windows\System32\oleaut32.dll
    0x776C0000 \Windows\System32\normaliz.dll
    0xFE060000 \Windows\System32\msctf.dll
    0xFDF30000 \Windows\System32\wininet.dll
    0xFDD20000 \Windows\System32\ole32.dll
    0xFDCA0000 \Windows\System32\shlwapi.dll
    0xFDC30000 \Windows\System32\gdi32.dll
    0xFDB60000 \Windows\System32\usp10.dll
    0xFDB10000 \Windows\System32\Wldap32.dll
    0xFD930000 \Windows\System32\setupapi.dll
    0xFD890000 \Windows\System32\comdlg32.dll
    0x776B0000 \Windows\System32\psapi.dll
    0xFD840000 \Windows\System32\ws2_32.dll
    0xFD830000 \Windows\System32\nsi.dll
    0xFD820000 \Windows\System32\lpk.dll
    0x772D0000 \Windows\System32\user32.dll
    0xFD800000 \Windows\System32\devobj.dll
    0xFD7C0000 \Windows\System32\cfgmgr32.dll
    0xFD650000 \Windows\System32\crypt32.dll
    0xFD610000 \Windows\System32\wintrust.dll
    0xFD5A0000 \Windows\System32\KernelBase.dll
    0xFD500000 \Windows\System32\comctl32.dll
    0xFD4F0000 \Windows\System32\msasn1.dll
    0x76FA0000 \Windows\SysWOW64\normaliz.dll

    Processes (total 76):
    0 System Idle Process
    4 System
    280 C:\Windows\System32\smss.exe
    412 csrss.exe
    476 C:\Windows\System32\wininit.exe
    496 csrss.exe
    532 C:\Windows\System32\services.exe
    556 C:\Windows\System32\lsass.exe
    564 C:\Windows\System32\lsm.exe
    664 C:\Windows\System32\svchost.exe
    744 C:\Windows\System32\svchost.exe
    812 C:\Windows\System32\svchost.exe
    844 C:\Windows\System32\svchost.exe
    884 C:\Windows\System32\svchost.exe
    920 C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_42d83e1760b1e973\stacsv64.exe
    344 C:\Windows\System32\svchost.exe
    332 C:\Program Files\Dell\DellDock\DockLogin.exe
    328 C:\Windows\System32\svchost.exe
    1084 C:\Windows\System32\winlogon.exe
    1284 C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
    1328 C:\Program Files\Dell\Dell Wireless WLAN Card\BCMWLTRY.EXE
    1428 C:\Windows\System32\spoolsv.exe
    1468 C:\Windows\System32\svchost.exe
    1560 C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_42d83e1760b1e973\AESTSr64.exe
    1616 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    1672 C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    1708 C:\Windows\System32\svchost.exe
    1792 C:\Program Files (x86)\STMicroelectronics\Accelerometer\InstallFilterService.exe
    1840 C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    1916 C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
    2012 C:\Windows\System32\svchost.exe
    2044 C:\Windows\System32\svchost.exe
    2608 WmiPrvSE.exe
    2800 C:\Windows\System32\dwm.exe
    2916 C:\Windows\System32\taskhost.exe
    2200 C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
    2376 C:\Windows\System32\conhost.exe
    2744 C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe
    3100 C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
    3216 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    3236 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    3408 C:\Program Files\IDT\WDM\sttray64.exe
    3420 C:\Windows\System32\igfxtray.exe
    3456 C:\Windows\System32\hkcmd.exe
    3464 C:\Windows\System32\igfxpers.exe
    3476 C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
    3488 C:\Program Files\Dell\QuickSet\quickset.exe
    3500 C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe
    3508 C:\Program Files (x86)\Skype\Phone\Skype.exe
    3516 C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    3528 C:\Program Files\Windows Sidebar\sidebar.exe
    3592 C:\Windows\System32\igfxsrvc.exe
    3604 C:\Program Files (x86)\AIM\aim.exe
    3632 C:\Program Files (x86)\uTorrent\uTorrent.exe
    3672 C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
    3808 C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
    3824 C:\Program Files\Dell\DellDock\DellDock.exe
    3872 C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
    3904 C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
    4008 C:\Program Files (x86)\iTunes\iTunesHelper.exe
    2748 C:\Windows\System32\SearchIndexer.exe
    3956 C:\Program Files (x86)\iPod\bin\iPodService.exe
    4544 C:\Program Files (x86)\Roxio\Roxio Burn\Roxio Burn.exe
    5076 C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
    4536 C:\Windows\explorer.exe
    4052 C:\Program Files\Windows Media Player\wmpnetwk.exe
    3200 C:\Windows\System32\svchost.exe
    3132 C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
    2512 C:\Windows\System32\wlanext.exe
    3168 C:\Windows\System32\conhost.exe
    5708 C:\Windows\System32\audiodg.exe
    5656 C:\Program Files (x86)\Dell DataSafe Local Backup\SftVss64.exe
    3064 WmiPrvSE.exe
    1164 C:\Windows\System32\dllhost.exe
    1104 E:\MBRCheck.exe
    860 C:\Windows\System32\conhost.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000003`abf38a00 (NTFS)
    \\.\E: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (FAT32)
    \\.\Y: --> \\.\PhysicalDrive0 at offset 0x00000000`02738a00 (NTFS)

    PhysicalDrive0 Model Number: WDCWD2500BEKT-75F3T0, Rev: 11.01A11
    PhysicalDrive1 Model Number: WD5000BEV External, Rev: 1.75

    Size Device Name MBR Status
    --------------------------------------------
    232 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected
    SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979
    465 GB \\.\PhysicalDrive1 RE: Unknown MBR code
    SHA1: 2BE9ACE700A45722604874D4A10E3B6A212931F3


    Found non-standard or infected MBR.
    Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    Done!
     
  15. 2010/09/04
    Jubis

    Jubis Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    58
    Likes Received:
    0
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 09/03/2010 at 08:14 PM

    Application Version : 4.42.1000

    Core Rules Database Version : 5410
    Trace Rules Database Version: 3222

    Scan type : Complete Scan
    Total Scan Time : 00:46:44

    Memory items scanned : 318
    Memory threats detected : 0
    Registry items scanned : 14094
    Registry threats detected : 0
    File items scanned : 124510
    File threats detected : 386

    Adware.Tracking Cookie
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@atdmt[4].txt
    boypornclips.com [ C:\Users\Nick\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\5SP75AHH ]
    cdn4.specificclick.net [ C:\Users\Nick\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\5SP75AHH ]
    collegeboyporn.com [ C:\Users\Nick\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\5SP75AHH ]
    homemadegaysex.com [ C:\Users\Nick\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\5SP75AHH ]
    ia.media-imdb.com [ C:\Users\Nick\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\5SP75AHH ]
    media.fleshlight.com [ C:\Users\Nick\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\5SP75AHH ]
    media.mtvnservices.com [ C:\Users\Nick\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\5SP75AHH ]
    movies.privategayporn.com [ C:\Users\Nick\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\5SP75AHH ]
    secure-us.imrworldwide.com [ C:\Users\Nick\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\5SP75AHH ]
    udn.specificclick.net [ C:\Users\Nick\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\5SP75AHH ]
    vidii.hardsextube.com [ C:\Users\Nick\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\5SP75AHH ]
    www.gotgayporn.com [ C:\Users\Nick\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\5SP75AHH ]
    www.naiadsystems.com [ C:\Users\Nick\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\5SP75AHH ]
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\Low\nick@a1.interclick[1].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\Low\nick@ad.wsod[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\Low\nick@ad.yieldmanager[1].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\Low\nick@advertising[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\Low\nick@apmebf[1].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\Low\nick@atdmt[1].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\Low\nick@bs.serving-sys[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\Low\nick@doubleclick[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\Low\nick@imrworldwide[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\Low\nick@insightexpressai[1].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\Low\nick@interclick[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\Low\nick@mediaplex[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\Low\nick@msnportal.112.2o7[1].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\Low\nick@questionmarket[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\Low\nick@revsci[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\Low\nick@serving-sys[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@ad.yieldmanager[1].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@ads.bridgetrack[1].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@ads.pointroll[1].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@advertising[1].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@advertising[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@apmebf[1].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@apmebf[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@ar.atwola[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@at.atwola[1].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@atdmt[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@atdmt[3].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@atwola[1].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@cdn.at.atwola[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@content.yieldmanager[1].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@doubleclick[1].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@doubleclick[3].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@insightexpressai[1].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@mediaplex[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@mediaplex[3].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@msnportal.112.2o7[1].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@pointroll[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@statse.webtrendslive[1].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@tacoda[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@yieldmanager[2].txt
    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies\nick@zedo[1].txt
    .apmebf.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .fastclick.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .fastclick.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    googleads.g.doubleclick.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .doubleclick.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .doubleclick.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .imrworldwide.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .imrworldwide.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .atdmt.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .atdmt.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    statse.webtrendslive.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .paypal.112.2o7.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .mediaplex.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adultfriendfinder.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adultfriendfinder.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adultfriendfinder.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adultfriendfinder.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adultfriendfinder.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adultfriendfinder.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .2o7.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .2o7.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ads.pointroll.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .pointroll.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ads.pointroll.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .pointroll.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ads.pointroll.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ads.pointroll.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ads.pointroll.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ads.pointroll.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ads.pointroll.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ads.pointroll.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .casalemedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .casalemedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .casalemedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .bs.serving-sys.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .serving-sys.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .serving-sys.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .serving-sys.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .serving-sys.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .serving-sys.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .serving-sys.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .serving-sys.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .kontera.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .kontera.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .kontera.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .media6degrees.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .media6degrees.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .advertising.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .statcounter.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .at.atwola.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .advertising.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .specificclick.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .specificclick.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .interclick.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .interclick.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .interclick.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .media6degrees.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .media6degrees.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adbrite.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adbrite.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adcentriconline.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .specificclick.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .specificclick.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .specificmedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    in.getclicky.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .advertising.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .advertising.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .advertising.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .invitemedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .invitemedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .invitemedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    ad.yieldmanager.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .revsci.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .media6degrees.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .a1.interclick.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .a1.interclick.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adecn.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    cdn4.specificclick.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    cdn4.specificclick.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    cdn4.specificclick.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    cdn4.specificclick.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .tribalfusion.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .media6degrees.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    2.v.y.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    ad.yieldmanager.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .zedo.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .zedo.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    ad.yieldmanager.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    rotator.adjuggler.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    rotator.adjuggler.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    ad.yieldmanager.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .redorbit.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .redorbit.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .lucidmedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .lucidmedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .lucidmedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .statcounter.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .redorbit.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .redorbit.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    ad.yieldmanager.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .mediaplex.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .myroitracking.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adserving.contextualmarketplace.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adserving.contextualmarketplace.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .questionmarket.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    ad.zanox.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .videoegg.adbureau.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    www.gayxxxclips.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .eyewonder.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .invitemedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .invitemedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .invitemedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .2o7.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .viacom.adbureau.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .viacom.adbureau.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .2o7.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .viacom.adbureau.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .collective-media.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .viacom.adbureau.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .fastclick.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .realmedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .burstnet.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .advertising.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .yieldmanager.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .247realmedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .realmedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .a1.interclick.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adbrite.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ru4.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ru4.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ru4.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adxpose.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .trafficmp.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .trafficmp.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .trafficmp.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .trafficmp.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .trafficmp.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    emoboyporn.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    www.emoboyporn.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .walmart.112.2o7.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ge.112.2o7.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    x.u.y.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    x.x.y.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ru4.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ru4.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ru4.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ru4.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .emogayporn.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .emogayporn.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    www.emogayporn.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .pro-market.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .pro-market.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .pro-market.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adbrite.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .specificclick.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .realmedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .247realmedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .invitemedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    e.x.i.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .clicksor.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .clicksor.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .clicksor.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .clicksor.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .clicksor.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .atdmt.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .atdmt.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .burstnet.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .fastclick.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .fastclick.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .247realmedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .247realmedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .media6degrees.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .pro-market.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .zedo.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    optimize.indieclick.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .legolas-media.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .legolas-media.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .legolas-media.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .questionmarket.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    g.e.i.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .yadro.ru [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .liveperson.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .liveperson.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    www.emogaysex.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .atdmt.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .edge.ru4.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .edge.ru4.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .edge.ru4.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .edge.ru4.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .edge.ru4.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .edge.ru4.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .edge.ru4.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .edge.ru4.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    cardfinder.capitalone.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .casalemedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .liveperson.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .lucidmedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .lucidmedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    ads.bridgetrack.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    ads.bridgetrack.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    ads.bridgetrack.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    www.burstbeacon.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .burstbeacon.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .gay-sex-teens.manticket.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .gay-sex-teens.manticket.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .tacoda.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .tacoda.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .tacoda.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adlegend.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adlegend.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    5.x.i.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .atwola.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    ar.atwola.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .atwola.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .specificmedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .linksynergy.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .linksynergy.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .linksynergy.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .chitika.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .movieticketscom.122.2o7.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    3.v.j.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    3.t.j.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    www.adfluxmedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    www.adfluxmedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    www.adfluxmedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    clixrevenue.ultrasat.blueseek.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .advertise.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    f.k.i.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .collective-media.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    dc.tremormedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adserver.adtechus.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    3.t.j.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    3.t.j.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    3.t.j.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    ad.yieldmanager.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    ad.yieldmanager.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    ad.yieldmanager.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .invitemedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .zedo.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ru4.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    ad.yieldmanager.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .collective-media.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .a1.interclick.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    c.u.j.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .content.yieldmanager.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    g.w.j.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .2o7.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .2o7.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    www.googleadservices.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    www.googleadservices.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    www.googleadservices.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .www.burstnet.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .zedo.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .zedo.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .zedo.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ontarget.122.2o7.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .casalemedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .journalregistercompany.122.2o7.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .casalemedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .interclick.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .realmedia.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .revsci.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .revsci.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .revsci.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .revsci.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .pornhub.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .pornhub.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .pornhub.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .pornhub.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .pornhub.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .pornhub.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .pornhub.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .pornhublive.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    4.u.j.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    ad.yieldmanager.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .revenue.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    teenboysvids.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .cunttt.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .cunttt.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adultfriendfinder.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .mediabrandsww.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .overture.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .insightexpressai.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .liveperson.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .trafficmp.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .hitbox.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ehg-verizon.hitbox.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .ehg-verizon.hitbox.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .hitbox.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .adbrite.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .fastclick.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    o.w.h.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .zedo.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    o.u.h.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .restoredchurchofgod.112.2o7.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    o.g.h.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    .revsci.net [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    o.p.h.cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    ad.yieldmanager.com [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    cltomedia.info [ C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\cookies.sqlite ]
    C:\Windows\Temp\Cookies\nick@statse.webtrendslive[2].txt

    Rogue.AntiMalwareDoctor
    C:\Users\Nick\AppData\Roaming\AA1FF08C41A91E7357D162DD95CFD307
     
  16. 2010/09/04
    Jubis

    Jubis Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    58
    Likes Received:
    0
    OTL logfile created on: 9/4/2010 5:55:34 PM - Run 1
    OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Nick\Downloads
    64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.7600.16385)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 62.00% Memory free
    8.00 Gb Paging File | 6.00 Gb Available in Paging File | 78.00% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 218.20 Gb Total Space | 47.90 Gb Free Space | 21.95% Space Free | Partition Type: NTFS
    Drive D: | 6.89 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
    E: Drive not present or media not loaded
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: NICK-LAPTOP
    Current User Name: Nick
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Include 64bit Scans
    Company Name Whitelist: On
    Skip Microsoft Files: On
    File Age = 90 Days
    Output = Standard
    Quick Scan

    ========== Processes (SafeList) ==========

    PRC - [2010/09/04 17:55:03 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Nick\Downloads\OTL.exe
    PRC - [2010/07/24 20:14:00 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    PRC - [2010/07/24 20:14:00 | 000,014,808 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
    PRC - [2010/07/17 01:40:31 | 000,322,352 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe
    PRC - [2010/06/10 21:03:08 | 000,144,176 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    PRC - [2010/04/03 17:39:31 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    PRC - [2010/03/31 12:42:56 | 000,786,432 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe
    PRC - [2010/03/25 18:08:06 | 001,573,376 | ---- | M] (SoftThinks - Dell) -- C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
    PRC - [2010/03/08 17:04:49 | 003,972,440 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\AIM\aim.exe
    PRC - [2010/03/04 13:28:08 | 000,658,656 | ---- | M] (SoftThinks) -- C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
    PRC - [2009/12/29 17:35:38 | 000,140,520 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
    PRC - [2009/10/15 04:10:44 | 001,169,904 | ---- | M] () -- C:\Program Files (x86)\Roxio\Roxio Burn\Roxio Burn.exe
    PRC - [2009/10/15 04:10:28 | 000,498,160 | ---- | M] () -- C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
    PRC - [2009/07/22 09:52:12 | 002,384,896 | ---- | M] () -- C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe
    PRC - [2009/06/09 10:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) -- C:\Program Files\Dell\DellDock\DockLogin.exe
    PRC - [2009/05/21 09:59:08 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
    PRC - [2009/05/21 09:59:08 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
    PRC - [2009/01/14 18:53:02 | 000,226,656 | ---- | M] (Microsoft Corp.) -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe


    ========== Modules (SafeList) ==========

    MOD - [2010/09/04 17:55:03 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Nick\Downloads\OTL.exe
    MOD - [2009/07/13 21:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx
    MOD - [2009/07/13 21:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


    ========== Win32 Services (SafeList) ==========

    SRV:64bit: - [2010/06/29 13:49:27 | 000,128,752 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE)
    SRV:64bit: - [2009/12/14 01:28:54 | 000,244,736 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_42d83e1760b1e973\stacsv64.exe -- (STacSV)
    SRV:64bit: - [2009/07/16 21:06:22 | 000,033,280 | ---- | M] () [Auto | Running] -- C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE -- (wltrysvc)
    SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV:64bit: - [2009/06/09 10:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService)
    SRV:64bit: - [2009/03/02 14:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_42d83e1760b1e973\AESTSr64.exe -- (AESTFilters)
    SRV - [2010/06/10 21:03:08 | 000,144,176 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
    SRV - [2010/03/27 12:30:15 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
    SRV - [2010/03/04 13:28:08 | 000,658,656 | ---- | M] (SoftThinks) [Auto | Running] -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE -- (SftService)
    SRV - [2009/06/23 17:02:42 | 000,060,928 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\STMicroelectronics\Accelerometer\InstallFilterService.exe -- (InstallFilterService)
    SRV - [2009/06/05 20:07:28 | 000,250,616 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe -- (GameConsoleService)
    SRV - [2009/05/21 09:59:08 | 000,206,064 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter)
    SRV - [2009/01/14 18:53:02 | 000,226,656 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
    SRV - [2006/10/27 00:47:54 | 000,065,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - [2010/04/19 20:47:42 | 000,050,688 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2010/02/17 14:23:05 | 000,014,920 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
    DRV:64bit: - [2010/02/17 14:23:05 | 000,012,360 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
    DRV:64bit: - [2009/12/14 01:28:54 | 000,505,856 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
    DRV:64bit: - [2009/10/07 20:37:48 | 007,749,408 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
    DRV:64bit: - [2009/09/17 00:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel(R)
    DRV:64bit: - [2009/08/23 23:20:22 | 000,285,744 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
    DRV:64bit: - [2009/08/20 12:05:06 | 000,239,616 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
    DRV:64bit: - [2009/07/24 02:13:02 | 000,023,912 | ---- | M] (ST Microelectronics) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Acceler.sys -- (Acceler)
    DRV:64bit: - [2009/07/23 13:57:48 | 000,018,792 | ---- | M] (ST Microelectronics) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\stdflt.sys -- (stdflt)
    DRV:64bit: - [2009/07/16 21:06:20 | 000,022,520 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bcm42rly.sys -- (BCM42RLY)
    DRV:64bit: - [2009/07/16 21:06:16 | 002,769,400 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
    DRV:64bit: - [2009/07/13 21:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2009/07/13 21:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2009/07/09 04:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
    DRV:64bit: - [2009/07/04 07:27:02 | 000,055,808 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rixdpe64.sys -- (rixdpcie)
    DRV:64bit: - [2009/07/01 20:54:52 | 000,060,416 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rimspe64.sys -- (rimspci)
    DRV:64bit: - [2009/07/01 06:31:58 | 000,080,896 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\risdpe64.sys -- (risdpcie)
    DRV:64bit: - [2009/06/25 05:04:20 | 000,067,584 | ---- | M] (REDC) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rimmpx64.sys -- (rimmptsk)
    DRV:64bit: - [2009/06/25 04:38:52 | 000,057,856 | ---- | M] (REDC) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rixdpx64.sys -- (rismxdp)
    DRV:64bit: - [2009/06/25 04:13:44 | 000,055,296 | ---- | M] (REDC) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rimspx64.sys -- (rimsptsk)
    DRV:64bit: - [2009/06/15 14:06:42 | 000,172,704 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CtClsFlt.sys -- (CtClsFlt)
    DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
    DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
    DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
    DRV:64bit: - [2006/11/01 12:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)

    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6092

    ========== FireFox ==========

    FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig?tab=mw&hl=en&source=iglk "
    FF - prefs.js..extensions.enabledItems: {6A97713B-73B8-450C-968C-6637DA62D2AC}:1.9.1
    FF - prefs.js..network.proxy.type: 0


    FF - HKLM\software\mozilla\Firefox\Extensions\\{6A97713B-73B8-450C-968C-6637DA62D2AC}: C:\Users\Nick\AppData\Local\{6A97713B-73B8-450C-968C-6637DA62D2AC}\ [2010/09/02 16:51:35 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/08/04 00:38:30 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/08/04 00:38:30 | 000,000,000 | ---D | M]

    [2010/04/05 09:14:08 | 000,000,000 | ---D | M] -- C:\Users\Nick\AppData\Roaming\Mozilla\Extensions
    [2010/04/15 21:40:10 | 000,000,000 | ---D | M] -- C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\nletdhqw.default\extensions
    [2010/04/05 09:13:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions

    O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg64.dll (Google Inc.)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
    O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
    O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
    O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
    O4:64bit: - HKLM..\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe ()
    O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
    O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
    O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
    O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
    O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
    O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
    O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
    O4 - HKLM..\Run: [Desktop Disc Tool] c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
    O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
    O4 - HKCU..\Run: [Aim] C:\Program Files (x86)\AIM\aim.exe (AOL Inc.)
    O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
    O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
    O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
    O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
    O4:64bit: - HKLM..\RunOnce: [DSUpdateLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe (Dell)
    O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe (Softthinks)
    O4 - HKLM..\RunOnce: [STToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\ToasterLauncher.exe ()
    O4 - Startup: C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files (x86)\Dell\DellDock\DellDock.exe File not found
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
    O8:64bit: - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
    O8 - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
    O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
    O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O13 - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
    O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
    O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
    O18:64bit: - Protocol\Handler\cozi {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
    O18 - Protocol\Handler\cozi {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll (Cozi Group, Inc.)
    O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20:64bit: - Winlogon\Notify\GoToAssist: DllName - Reg Error: Key error. - C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll File not found
    O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2003/06/16 04:43:29 | 000,000,073 | R--- | M] () - D:\AUTORUN.INF -- [ UDF ]
    O33 - MountPoints2\{6b3ea773-39cc-11df-8829-806e6f6e6963}\Shell - " " = AutoRun
    O33 - MountPoints2\{6b3ea773-39cc-11df-8829-806e6f6e6963}\Shell\AutoRun\command - " " = D:\install.EXE id= ver=1.0.0.0 -- File not found
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*


    Drivers32:64bit: aux - wdmaud.drv (Microsoft Corporation)
    Drivers32:64bit: midi - wdmaud.drv (Microsoft Corporation)
    Drivers32:64bit: midi1 - wdmaud.drv (Microsoft Corporation)
    Drivers32:64bit: midimapper - midimap.dll (Microsoft Corporation)
    Drivers32:64bit: mixer - wdmaud.drv (Microsoft Corporation)
    Drivers32:64bit: mixer1 - wdmaud.drv (Microsoft Corporation)
    Drivers32:64bit: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
    Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32:64bit: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
    Drivers32:64bit: msacm.msg711 - msg711.acm (Microsoft Corporation)
    Drivers32:64bit: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
    Drivers32:64bit: MSVideo8 - VfWWDM32.dll (Microsoft Corporation)
    Drivers32:64bit: vidc.i420 - iyuv_32.dll (Microsoft Corporation)
    Drivers32:64bit: VIDC.IYUV - iyuv_32.dll (Microsoft Corporation)
    Drivers32:64bit: vidc.mrle - msrle32.dll (Microsoft Corporation)
    Drivers32:64bit: vidc.msvc - msvidc32.dll (Microsoft Corporation)
    Drivers32:64bit: VIDC.UYVY - msyuv.dll (Microsoft Corporation)
    Drivers32:64bit: VIDC.YUY2 - msyuv.dll (Microsoft Corporation)
    Drivers32:64bit: VIDC.YVU9 - tsbyuv.dll (Microsoft Corporation)
    Drivers32:64bit: VIDC.YVYU - msyuv.dll (Microsoft Corporation)
    Drivers32:64bit: wave - wdmaud.drv (Microsoft Corporation)
    Drivers32:64bit: wave1 - wdmaud.drv (Microsoft Corporation)
    Drivers32:64bit: wavemapper - msacm32.drv (Microsoft Corporation)
    Drivers32: aux - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
    Drivers32: midi - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
    Drivers32: midi1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
    Drivers32: midimapper - C:\Windows\SysWow64\midimap.dll (Microsoft Corporation)
    Drivers32: mixer - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
    Drivers32: mixer1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
    Drivers32: msacm.imaadpcm - C:\Windows\SysWow64\imaadp32.acm (Microsoft Corporation)
    Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.msadpcm - C:\Windows\SysWow64\msadp32.acm (Microsoft Corporation)
    Drivers32: msacm.msg711 - C:\Windows\SysWow64\msg711.acm (Microsoft Corporation)
    Drivers32: msacm.msgsm610 - C:\Windows\SysWow64\msgsm32.acm (Microsoft Corporation)
    Drivers32: msacm.siren - C:\Windows\SysWow64\sirenacm.dll (Microsoft Corporation)
    Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
    Drivers32: vidc.i420 - C:\Windows\SysWow64\iyuv_32.dll (Microsoft Corporation)
    Drivers32: vidc.iyuv - C:\Windows\SysWow64\iyuv_32.dll (Microsoft Corporation)
    Drivers32: vidc.mrle - C:\Windows\SysWow64\msrle32.dll (Microsoft Corporation)
    Drivers32: vidc.msvc - C:\Windows\SysWow64\msvidc32.dll (Microsoft Corporation)
    Drivers32: vidc.uyvy - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
    Drivers32: vidc.yuy2 - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
    Drivers32: vidc.yvu9 - C:\Windows\SysWow64\tsbyuv.dll (Microsoft Corporation)
    Drivers32: vidc.yvyu - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
    Drivers32: wave - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
    Drivers32: wave1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
    Drivers32: wavemapper - C:\Windows\SysWow64\msacm32.drv (Microsoft Corporation)

    CREATERESTOREPOINT
    Error creating restore point.

    ========== Files/Folders - Created Within 90 Days ==========

    [2010/09/03 19:18:28 | 000,000,000 | ---D | C] -- C:\Users\Nick\AppData\Roaming\SUPERAntiSpyware.com
    [2010/09/03 19:18:28 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
    [2010/09/03 19:18:23 | 000,000,000 | ---D | C] -- C:\ProgramData\!SASCORE
    [2010/09/03 19:18:22 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
    [2010/09/03 05:42:24 | 000,000,000 | ---D | C] -- C:\Users\Nick\AppData\Local\ElevatedDiagnostics
    [2010/09/02 22:23:56 | 000,000,000 | ---D | C] -- C:\Users\Nick\AppData\Roaming\Malwarebytes
    [2010/09/02 22:23:40 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
    [2010/09/02 22:23:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2010/09/02 22:23:38 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2010/09/02 22:23:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    [2010/09/02 21:38:42 | 000,000,000 | R--D | C] -- C:\32788R22FWJFW
    [2010/09/02 16:51:35 | 000,000,000 | ---D | C] -- C:\Users\Nick\AppData\Local\{6A97713B-73B8-450C-968C-6637DA62D2AC}
    [2010/09/02 16:50:55 | 000,000,000 | -HSD | C] -- C:\Users\Nick\.COMMgr
    [2010/09/02 16:50:20 | 000,000,000 | ---D | C] -- C:\Users\Nick\AppData\Local\vpcyrschs
    [2010/09/02 16:49:46 | 000,000,000 | ---D | C] -- C:\Users\Nick\AppData\Local\Windows Server
    [2010/08/25 00:37:27 | 000,000,000 | ---D | C] -- C:\Windows\Sun
    [2010/08/10 11:02:41 | 000,000,000 | ---D | C] -- C:\Users\Nick\AppData\Roaming\WinRAR
    [2010/08/10 11:02:03 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
    [2010/08/06 23:02:48 | 000,000,000 | ---D | C] -- C:\Users\Nick\AppData\Local\PowerDVD DX
    [2010/08/06 23:02:47 | 000,000,000 | ---D | C] -- C:\ProgramData\CyberLink
    [2010/08/06 23:01:22 | 000,000,000 | ---D | C] -- C:\Users\Nick\AppData\Roaming\dvdcss
    [2010/08/04 14:30:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
    [2010/08/04 12:01:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
    [2010/08/04 12:01:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iPod
    [2010/08/04 11:56:10 | 000,000,000 | -HSD | C] -- C:\Config.Msi
    [2010/08/04 00:40:04 | 000,000,000 | ---D | C] -- C:\Users\Nick\AppData\Roaming\Apple Computer
    [2010/08/04 00:40:04 | 000,000,000 | ---D | C] -- C:\Users\Nick\AppData\Local\Apple Computer
    [2010/08/04 00:39:56 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
    [2010/08/04 00:39:21 | 000,000,000 | ---D | C] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
    [2010/08/04 00:38:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
    [2010/08/04 00:38:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
    [2010/08/04 00:37:54 | 000,000,000 | ---D | C] -- C:\Users\Nick\AppData\Local\Apple
    [2010/08/04 00:37:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
    [2010/08/04 00:37:13 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
    [2010/08/04 00:37:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
    [2010/08/04 00:36:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
    [2010/08/04 00:36:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
    [2010/07/15 10:41:49 | 000,000,000 | ---D | C] -- C:\Users\Nick\AppData\Local\Diagnostics

    ========== Files - Modified Within 90 Days ==========

    [2010/09/04 17:56:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2010/09/04 17:51:10 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2010/09/04 17:50:58 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
    [2010/09/04 17:50:57 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2010/09/04 17:50:49 | 3061,202,944 | -HS- | M] () -- C:\hiberfil.sys
    [2010/09/04 09:21:08 | 001,572,864 | -HS- | M] () -- C:\Users\Nick\ntuser.dat
    [2010/09/04 09:21:04 | 001,525,462 | -H-- | M] () -- C:\Users\Nick\AppData\Local\IconCache.db
    [2010/09/03 20:23:06 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2010/09/03 20:23:06 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2010/09/03 19:18:23 | 000,001,810 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2010/09/02 22:23:42 | 000,001,015 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/09/02 16:51:36 | 000,000,120 | ---- | M] () -- C:\Users\Nick\AppData\Local\Vgaletiyogovitog.dat
    [2010/09/02 16:51:36 | 000,000,000 | ---- | M] () -- C:\Users\Nick\AppData\Local\Bhilogewusuyanam.bin
    [2010/09/02 00:41:42 | 000,524,288 | -HS- | M] () -- C:\Users\Nick\ntuser.dat{f83cab63-b64b-11df-96b7-b8ac6f5a8a10}.TMContainer00000000000000000002.regtrans-ms
    [2010/09/02 00:41:42 | 000,524,288 | -HS- | M] () -- C:\Users\Nick\ntuser.dat{f83cab63-b64b-11df-96b7-b8ac6f5a8a10}.TMContainer00000000000000000001.regtrans-ms
    [2010/09/02 00:41:42 | 000,065,536 | -HS- | M] () -- C:\Users\Nick\ntuser.dat{f83cab63-b64b-11df-96b7-b8ac6f5a8a10}.TM.blf
    [2010/08/27 12:16:20 | 000,713,888 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2010/08/27 12:16:20 | 000,615,360 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2010/08/27 12:16:20 | 000,103,702 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2010/08/25 00:50:37 | 000,524,288 | -HS- | M] () -- C:\Users\Nick\ntuser.dat{820e656f-b003-11df-b2dc-b8ac6f5a8a10}.TMContainer00000000000000000002.regtrans-ms
    [2010/08/25 00:50:36 | 000,524,288 | -HS- | M] () -- C:\Users\Nick\ntuser.dat{820e656f-b003-11df-b2dc-b8ac6f5a8a10}.TMContainer00000000000000000001.regtrans-ms
    [2010/08/25 00:50:36 | 000,065,536 | -HS- | M] () -- C:\Users\Nick\ntuser.dat{820e656f-b003-11df-b2dc-b8ac6f5a8a10}.TM.blf
    [2010/08/20 14:11:17 | 000,010,127 | ---- | M] () -- C:\Users\Nick\Documents\important.docx
    [2010/08/18 17:53:02 | 000,000,056 | -H-- | M] () -- C:\Windows\SysWow64\ezsidmv.dat
    [2010/08/16 03:19:37 | 000,426,840 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
    [2010/08/13 00:53:43 | 019,461,015 | ---- | M] () -- C:\Users\Nick\Documents\vlc-1.1.2-win32.exe
    [2010/08/04 12:01:04 | 000,002,429 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
    [2010/08/04 00:38:25 | 000,001,847 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
    [2010/07/25 20:28:45 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
    [2010/06/22 14:10:01 | 002,514,964 | ---- | M] () -- C:\Users\Nick\Desktop\ringtone.mp3

    ========== Files Created - No Company Name ==========

    [2010/09/03 19:18:23 | 000,001,810 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2010/09/02 22:23:42 | 000,001,015 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/09/02 16:51:36 | 000,000,120 | ---- | C] () -- C:\Users\Nick\AppData\Local\Vgaletiyogovitog.dat
    [2010/09/02 16:51:36 | 000,000,000 | ---- | C] () -- C:\Users\Nick\AppData\Local\Bhilogewusuyanam.bin
    [2010/09/02 00:41:42 | 000,524,288 | -HS- | C] () -- C:\Users\Nick\ntuser.dat{f83cab63-b64b-11df-96b7-b8ac6f5a8a10}.TMContainer00000000000000000002.regtrans-ms
    [2010/09/02 00:41:42 | 000,524,288 | -HS- | C] () -- C:\Users\Nick\ntuser.dat{f83cab63-b64b-11df-96b7-b8ac6f5a8a10}.TMContainer00000000000000000001.regtrans-ms
    [2010/09/02 00:41:42 | 000,065,536 | -HS- | C] () -- C:\Users\Nick\ntuser.dat{f83cab63-b64b-11df-96b7-b8ac6f5a8a10}.TM.blf
    [2010/08/25 00:50:37 | 000,524,288 | -HS- | C] () -- C:\Users\Nick\ntuser.dat{820e656f-b003-11df-b2dc-b8ac6f5a8a10}.TMContainer00000000000000000002.regtrans-ms
    [2010/08/25 00:50:36 | 000,524,288 | -HS- | C] () -- C:\Users\Nick\ntuser.dat{820e656f-b003-11df-b2dc-b8ac6f5a8a10}.TMContainer00000000000000000001.regtrans-ms
    [2010/08/25 00:50:36 | 000,065,536 | -HS- | C] () -- C:\Users\Nick\ntuser.dat{820e656f-b003-11df-b2dc-b8ac6f5a8a10}.TM.blf
    [2010/08/20 14:11:16 | 000,010,127 | ---- | C] () -- C:\Users\Nick\Documents\important.docx
    [2010/08/18 17:53:02 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
    [2010/08/13 00:49:34 | 019,461,015 | ---- | C] () -- C:\Users\Nick\Documents\vlc-1.1.2-win32.exe
    [2010/08/04 12:01:04 | 000,002,429 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
    [2010/08/04 00:38:25 | 000,001,847 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
    [2010/07/25 20:28:45 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
    [2010/06/22 14:09:57 | 002,514,964 | ---- | C] () -- C:\Users\Nick\Desktop\ringtone.mp3
    [2010/02/26 07:54:21 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
    [2010/02/26 07:54:21 | 000,147,456 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
    [2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
    [2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll

    ========== LOP Check ==========

    [2010/04/07 13:10:32 | 000,000,000 | ---D | M] -- C:\Users\Nick\AppData\Roaming\acccore
    [2010/09/04 17:57:34 | 000,000,000 | ---D | M] -- C:\Users\Nick\AppData\Roaming\uTorrent
    [2010/04/14 13:22:14 | 000,000,000 | ---D | M] -- C:\Users\Nick\AppData\Roaming\WildTangent
    [2009/07/14 01:08:49 | 000,010,158 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.* >
    [2010/03/27 15:05:45 | 000,003,658 | RH-- | M] () -- C:\dell.sdr
    [2010/09/04 17:50:49 | 3061,202,944 | -HS- | M] () -- C:\hiberfil.sys
    [2010/04/07 13:10:19 | 000,000,346 | -H-- | M] () -- C:\IPH.PH
    [2006/12/02 00:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll
    [2010/09/04 17:50:56 | 4081,606,656 | -HS- | M] () -- C:\pagefile.sys
    [2010/09/02 21:32:40 | 000,000,317 | ---- | M] () -- C:\rkill.log

    < %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >

    < %systemroot%\system32\*.wt >

    < %systemroot%\system32\*.ruy >

    < %systemroot%\Fonts\*.com >
    [2009/07/14 01:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
    [2009/07/14 01:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
    [2009/07/14 01:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
    [2009/07/14 01:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

    < %systemroot%\*. /mp /s >


    < %systemroot%\system32\*.dll /lockedfiles >

    < %systemroot%\Tasks\*.job /lockedfiles >

    < %systemroot%\System32\config\*.sav >

    < %systemroot%\system32\user32.dll /md5 >
    [2009/07/13 21:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll

    < %systemroot%\system32\ws2_32.dll /md5 >
    [2009/07/13 21:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\SysWOW64\ws2_32.dll

    < %systemroot%\system32\ws2help.dll /md5 >
    [2009/07/13 21:11:26 | 000,004,608 | ---- | M] (Microsoft Corporation) MD5=808AABDF9337312195CAFF76D1804786 -- C:\Windows\SysWOW64\ws2help.dll

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
    < End of report >
     
  17. 2010/09/04
    Jubis

    Jubis Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    58
    Likes Received:
    0
    OTL Extras logfile created on: 9/4/2010 5:55:35 PM - Run 1
    OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Nick\Downloads
    64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.7600.16385)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 62.00% Memory free
    8.00 Gb Paging File | 6.00 Gb Available in Paging File | 78.00% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 218.20 Gb Total Space | 47.90 Gb Free Space | 21.95% Space Free | Partition Type: NTFS
    Drive D: | 6.89 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
    E: Drive not present or media not loaded
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: NICK-LAPTOP
    Current User Name: Nick
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Include 64bit Scans
    Company Name Whitelist: On
    Skip Microsoft Files: On
    File Age = 90 Days
    Output = Standard
    Quick Scan

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

    [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %* File not found
    cmdfile [open] -- "%1" %* File not found
    comfile [open] -- "%1" %* File not found
    exefile [open] -- "%1" %* File not found
    helpfile [open] -- Reg Error: Key error.
    htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
    htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll ",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %* File not found
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1" File not found
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
    scrfile [open] -- "%1" /S File not found
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
    Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
    Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1 ",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
    htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll ",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1 "
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
    Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    ========== Authorized Applications List ==========


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{26A24AE4-039D-4CA4-87B4-2F86416017FF}" = Java(TM) 6 Update 17 (64-bit)
    "{328CC232-CFDC-468B-A214-2E21300E4CB5}" = Apple Mobile Device Support
    "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
    "{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64
    "{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
    "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
    "{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
    "{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
    "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{B91110FB-33B4-468B-90C2-4D5E8AE3FAE1}" = Bonjour
    "{C73A3942-84C8-4597-9F9B-EE227DCBA758}" = Dell Dock
    "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
    "Dell Wireless WLAN Card Utility" = Dell Wireless WLAN Card Utility
    "SynTPDeinstKey" = Dell Touchpad
    "WinRAR archiver" = WinRAR archiver

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}" = Microsoft Visual C++ 2005 Redistributable
    "{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
    "{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
    "{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
    "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
    "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
    "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
    "{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 17
    "{2DA5F129-11AC-4F11-8188-B2F07EAAC20A}" = Cozi
    "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
    "{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
    "{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime
    "{41B9E2CF-0B3F-442A-B5B3-592A4A355634}" = iTunes
    "{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}" = Banctec Service Agreement
    "{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
    "{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
    "{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
    "{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
    "{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
    "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
    "{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
    "{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
    "{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
    "{87434D51-51DB-4109-B68F-A829ECDCF380}" = Accelerometer
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
    "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
    "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
    "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
    "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
    "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
    "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{926CC8AE-8414-43DF-8EB4-CF26D9C3C663}" =
    "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
    "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
    "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
    "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
    "{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
    "{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
    "{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
    "{A33E7B0C-B99C-4EC9-B702-8A328B161AF9}" = Roxio Burn
    "{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
    "{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.2
    "{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
    "{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}" = Roxio Burn
    "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
    "{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
    "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
    "{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
    "{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
    "{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
    "{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
    "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
    "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
    "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Graphics Media Accelerator Driver
    "{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
    "Advanced Audio FX Engine" = Advanced Audio FX Engine
    "AIM_7" = AIM 7
    "Dell Dock" = Dell Dock
    "Dell Webcam Central" = Dell Webcam Central
    "ENTERPRISE" = Microsoft Office Enterprise 2007
    "GoToAssist" = GoToAssist 8.0.0.514
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
    "Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
    "SoftwareUpdUtility" = Download Updater (AOL LLC)
    "uTorrent" = µTorrent
    "VLC media player" = VLC media player 1.0.5
    "WildTangent dell Master Uninstall" = WildTangent Games
    "WinLiveSuite_Wave3" = Windows Live Essentials

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 8/21/2010 11:08:17 AM | Computer Name = Nick-Laptop | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledSPRetry 2106

    Error - 8/22/2010 2:02:18 AM | Computer Name = Nick-Laptop | Source = SideBySide | ID = 16842832
    Description = Activation context generation failed for "c:\Program Files (x86)\Cozi
    Express\CoziExpress.exe ".Error in manifest or policy file " " on line . A component
    version required by the application conflicts with another component version already
    active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.
    Component
    2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.

    Error - 8/22/2010 2:03:06 AM | Computer Name = Nick-Laptop | Source = SideBySide | ID = 16842787
    Description = Activation context generation failed for "c:\program files (x86)\windows
    live\photo gallery\MovieMaker.Exe ".Error in manifest or policy file "c:\program
    files (x86)\windows live\photo gallery\WLMFDS.DLL" on line 8. Component identity
    found in manifest does not match the identity of the component requested. Reference
    is WLMFDS,processorArchitecture= "AMD64 ",type= "win32 ",version= "1.0.0.1 ". Definition
    is WLMFDS,processorArchitecture= "x86 ",type= "win32 ",version= "1.0.0.1 ". Please use
    sxstrace.exe for detailed diagnosis.

    Error - 8/22/2010 2:03:27 AM | Computer Name = Nick-Laptop | Source = SideBySide | ID = 16842811
    Description = Activation context generation failed for "c:\program files (x86)\microsoft\search
    enhancement pack\search helper\searchhelper.dll ".Error in manifest or policy file
    "c:\program files (x86)\microsoft\search enhancement pack\search helper\searchhelper.dll "
    on line 2. Invalid Xml syntax.

    Error - 8/23/2010 6:28:02 PM | Computer Name = Nick-Laptop | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: Continuously busy for more than a second

    Error - 8/23/2010 6:28:02 PM | Computer Name = Nick-Laptop | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledEvent 5070

    Error - 8/23/2010 6:28:02 PM | Computer Name = Nick-Laptop | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledSPRetry 5070

    Error - 8/25/2010 12:37:46 AM | Computer Name = Nick-Laptop | Source = Application Error | ID = 1000
    Description = Faulting application name: firefox.exe, version: 1.9.2.3855, time
    stamp: 0x4c48d5ce Faulting module name: icucnv36.dll, version: 3.6.0.0, time stamp:
    0x470eff71 Exception code: 0xc0000005 Fault offset: 0x000013df Faulting process id:
    0x1078 Faulting application start time: 0x01cb440ed02a3950 Faulting application path:
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe Faulting module path: C:\Program
    Files (x86)\Adobe\Reader 9.0\Reader\icucnv36.dll Report Id: 819d2a51-b002-11df-9ac8-b8ac6f5a8a10

    Error - 8/25/2010 12:42:13 AM | Computer Name = Nick-Laptop | Source = SideBySide | ID = 16842832
    Description = Activation context generation failed for "C:\Program Files (x86)\Cozi
    Express\CoziExpress.exe ".Error in manifest or policy file " " on line . A component
    version required by the application conflicts with another component version already
    active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.
    Component
    2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.

    Error - 8/25/2010 12:42:13 AM | Computer Name = Nick-Laptop | Source = SideBySide | ID = 16842832
    Description = Activation context generation failed for "C:\Program Files (x86)\Cozi
    Express\CoziExpress.exe ".Error in manifest or policy file " " on line . A component
    version required by the application conflicts with another component version already
    active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.
    Component
    2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.

    [ Broadcom Wireless LAN Events ]
    Error - 4/1/2010 6:31:43 PM | Computer Name = Nick-Laptop | Source = WLAN-Tray | ID = 0
    Description = 18:31:43, Thu, Apr 01, 10 Error - Unable to get current user admin
    status

    Error - 4/1/2010 6:32:52 PM | Computer Name = Nick-Laptop | Source = WLAN-Tray | ID = 0
    Description = 18:32:52, Thu, Apr 01, 10 Error - Unable to get current user admin
    status

    Error - 4/1/2010 6:39:03 PM | Computer Name = Nick-Laptop | Source = WLAN-Tray | ID = 0
    Description = 17:39:03, Thu, Apr 01, 10 Error - Unable to switch user context, authentication
    information not set correctly

    Error - 5/19/2010 8:49:16 PM | Computer Name = Nick-Laptop | Source = WLAN-Tray | ID = 0
    Description = 20:49:16, Wed, May 19, 10 Error - Unable to gain access to user store


    [ Media Center Events ]
    Error - 8/13/2010 2:24:20 PM | Computer Name = Nick-Laptop | Source = MCUpdate | ID = 0
    Description = 2:24:20 PM - Failed to retrieve Directory (Error: The underlying connection
    was closed: An unexpected error occurred on a receive.)

    [ System Events ]
    Error - 9/2/2010 5:45:16 PM | Computer Name = Nick-Laptop | Source = Service Control Manager | ID = 7001
    Description = The Computer Browser service depends on the Server service which failed
    to start because of the following error: %%1068

    Error - 9/2/2010 5:45:16 PM | Computer Name = Nick-Laptop | Source = Service Control Manager | ID = 7001
    Description = The Computer Browser service depends on the Server service which failed
    to start because of the following error: %%1068

    Error - 9/2/2010 5:45:16 PM | Computer Name = Nick-Laptop | Source = Service Control Manager | ID = 7001
    Description = The Computer Browser service depends on the Server service which failed
    to start because of the following error: %%1068

    Error - 9/2/2010 5:45:16 PM | Computer Name = Nick-Laptop | Source = Service Control Manager | ID = 7001
    Description = The Computer Browser service depends on the Server service which failed
    to start because of the following error: %%1068

    Error - 9/2/2010 5:45:26 PM | Computer Name = Nick-Laptop | Source = Service Control Manager | ID = 7001
    Description = The Computer Browser service depends on the Server service which failed
    to start because of the following error: %%1068

    Error - 9/2/2010 5:45:26 PM | Computer Name = Nick-Laptop | Source = Service Control Manager | ID = 7001
    Description = The Computer Browser service depends on the Server service which failed
    to start because of the following error: %%1068

    Error - 9/2/2010 5:45:26 PM | Computer Name = Nick-Laptop | Source = Service Control Manager | ID = 7001
    Description = The Computer Browser service depends on the Server service which failed
    to start because of the following error: %%1068

    Error - 9/2/2010 5:47:34 PM | Computer Name = Nick-Laptop | Source = Service Control Manager | ID = 7001
    Description = The Computer Browser service depends on the Server service which failed
    to start because of the following error: %%1068

    Error - 9/2/2010 5:47:34 PM | Computer Name = Nick-Laptop | Source = Service Control Manager | ID = 7001
    Description = The Computer Browser service depends on the Server service which failed
    to start because of the following error: %%1068

    Error - 9/2/2010 5:47:34 PM | Computer Name = Nick-Laptop | Source = Service Control Manager | ID = 7001
    Description = The Computer Browser service depends on the Server service which failed
    to start because of the following error: %%1068


    < End of report >
     
  18. 2010/09/04
    Jubis

    Jubis Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    58
    Likes Received:
    0
    I think that's all you needed
     
    Last edited: 2010/09/04
  19. 2010/09/04
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I don't see any antivirus program running.
    Please, download and install ONE of these:
    - Avast! free antivirus: http://www.avast.com/eng/download-avast-home.html
    - Avira free antivirus: http://www.free-av.com/en/download/1/avira_antivir_personal__free_antivirus.html
    After installation, run full scan.

    ================================================================

    Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it to its own folder
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.

    ==============================================================

    Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following

      Code:
      :OTL
      IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings:  "ProxyOverride" = <local>
      IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings:  "ProxyServer" = http=127.0.0.1:6092
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
      O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
      O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
      O4 - Startup: C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files (x86)\Dell\DellDock\DellDock.exe File not found
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
      O18:64bit: - Protocol\Handler\cozi {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
      O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
      O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
      O20:64bit: - Winlogon\Notify\GoToAssist: DllName - Reg Error: Key error. - C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll File not found
      O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
      O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
      O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
      [2010/09/02 16:51:36 | 000,000,120 | ---- | C] () -- C:\Users\Nick\AppData\Local\Vgaletiyogovitog.dat
      [2010/09/02 16:51:36 | 000,000,000 | ---- | C] () -- C:\Users\Nick\AppData\Local\Bhilogewusuyanam.bin
      
      
      :Services
      
      :Reg
      
      :Files
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
      
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    ===============================================================

    Last scans....

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


    2. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    3. Go to Kaspersky website and perform an online antivirus scan.

    • Disable your active antivirus program.
    • Read through the requirements and privacy statement and click on Accept button.
    • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    • When the downloads have finished, click on Settings.
    • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      • Spyware, Adware, Dialers, and other potentially dangerous programs
      • Archives
      • Mail databases
    • Click on My Computer under Scan.
    • Once the scan is complete, it will display the results. Click on View Scan Report.
    • You will see a list of infected items there. Click on Save Report As....
    • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
     
  20. 2010/09/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Are you still out there?
     
  21. 2010/09/11
    Jubis

    Jubis Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    58
    Likes Received:
    0
    Yes, I'm sorry. I have a lot going on with school and work right now. I don't have a lot of free time. I should have these scans posted by Wednesday.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.