Jump to content
IObit Forum
Top Free Driver Updater Tools Best 25 PC Optimization Software Best 22 Antimalware Best 22 Uninstaller Software IObit Coupons & Discount Offers PC Optimizer Mac Boost Advice IObit Coupons A Good Utility Program From IObit IObit Promo Codes IObit Coupon Codes IObit Coupons and Deals FAQs Driver Booster Pro Review

Google jump virus


dcoombs

Recommended Posts

I have been attempting to remove the jump virus from my system. Having run every malware & antivirus software I know of I am now trying the IS360 & hijackthis. Can anyone in this forum help?

Logfile of IObit HijackScan v1.0.2.0

Scan saved at 10:30:6, on 2010-11-12

 

Running processes:

C:\Windows\System32\smss.exe

C:\Windows\system32\csrss.exe

C:\Windows\system32\wininit.exe

C:\Windows\system32\csrss.exe

C:\Windows\system32\services.exe

C:\Windows\system32\lsass.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\winlogon.exe

C:\Windows\system32\svchost.exe

C:\Windows\system32\ibmpmsvc.exe

C:\Windows\system32\svchost.exe

C:\Windows\system32\atiesrxx.exe

C:\Windows\System32\svchost.exe

C:\Windows\System32\svchost.exe

C:\Windows\system32\svchost.exe

C:\Windows\system32\svchost.exe

C:\Windows\system32\atieclxx.exe

C:\Windows\system32\svchost.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\taskeng.exe

C:\Windows\system32\svchost.exe

C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Windows\system32\svchost.exe

C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe

C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe

C:\Program Files\Common Files\Motive\McciCMService.exe

C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\Windows\system32\svchost.exe

C:\Windows\System32\svchost.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files\Lenovo\Access Connections\AcSvc.exe

C:\Windows\system32\taskhost.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\System32\TpShocks.exe

C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe

C:\Program Files\Lenovo\Client Security Solution\cssauth.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe

C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe

C:\Program Files\HP\HP Software Update\hpwuschd2.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Genie-Soft\GBMHome8\GBMAgent.exe

C:\Windows\system32\taskeng.exe

C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe

C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

C:\Windows\system32\rundll32.exe

C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe

C:\Program Files\Lenovo\Access Connections\SvcGuiHlpr.exe

C:\Windows\system32\SearchIndexer.exe

C:\Windows\system32\svchost.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\System32\svchost.exe

C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE

C:\Windows\system32\DllHost.exe

C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe

C:\Windows\system32\svchost.exe

c:\Program Files\Lenovo\System Update\SUService.exe

C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe

C:\Program Files\AOL 9.5\waol.exe

C:\Program Files\AOL 9.5\shellmon.exe

C:\Windows\System32\svchost.exe

C:\Program Files\IObit\IObit Security 360\is360.exe

C:\Program Files\IObit\IObit Security 360\is360tray.exe

C:\Program Files\IObit\IObit Security 360\IS360srv.exe

C:\Program Files\IObit\IObit Security 360\a_hijackscan.exe

 

O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\MICROS~4\Office14\URLREDIR.DLL

O2 - BHO: IePasswordManagerHelper Class - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll

O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: @C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll

O4 - HKCU|\Software\Microsoft\Windows\CurrentVersion\Run\: [GenieSearchforArchive] "C:\Program Files\Genie-Soft\Genie Archive for Outlook 2\GenieSearchforArchive.exe" -startup

O4 - HKCU|\Software\Microsoft\Windows\CurrentVersion\Run\: [GBMHome8Agent] C:\Program Files\Genie-Soft\GBMHome8\GBMAgent.exe

O4 - HKCU|\Software\Microsoft\Windows\CurrentVersion\Run\: [AOL Fast Start] "C:\Program Files\AOL 9.5\AOL.EXE" -b

O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [TpShocks] TpShocks.exe

O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe

O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [smartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t

O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [PWMTRV] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor

O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [Message Center Plus] C:\Program Files\LENOVO\Message Center Plus\MCPLaunch.exe /start

O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [AcWin7Hlpr] C:\Program Files\Lenovo\Access Connections\AcTBenabler.exe

O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent

O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [HostManager] C:\Program Files\Common Files\AOL\1272201713\ee\AOLSoftware.exe

O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [LENOVO.TPKNRRES] C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe

O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [GBMHome8Agent] C:\Program Files\Genie-Soft\GBMHome8\GBMAgent.exe

O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [iObit Security 360] "C:\Program Files\IObit\IObit Security 360\IS360tray.exe" /autostart

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office14\EXCEL.EXE/3000

O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~4\Office14\ONBttnIE.dll/105

O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} -

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} -

O9 - Extra button: OneNote Linked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} -

O9 - Extra button: @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm

O9 - Extra button: Lenovo Password Manager... - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}Java Plug-in 1.6.0_22 - http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab

O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}Java Plug-in 1.6.0_22 - http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}Java Plug-in 1.6.0_22 - http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab

O23 - Service: AcPrfMgrSvc (AcPrfMgrSvc) - Lenovo - C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe

O23 - Service: AcSvc (AcSvc) - Lenovo - C:\Program Files\Lenovo\Access Connections\AcSvc.exe

O23 - Service: AMD External Events Utility (AMD External Events Utility) - AMD - C:\Windows\system32\atiesrxx.exe

O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe

O23 - Service: Apple Mobile Device (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: Bonjour Service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe

O23 - Service: DCOM Server Process Launcher (DcomLaunch) - Unknown -

O23 - Service: Diagnostic Policy Service (DPS) - Unknown -

O23 - Service: Group Policy Client (gpsvc) - Unknown -

O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo. - C:\Windows\system32\ibmpmsvc.exe

O23 - Service: Windows CardSpace (idsvc) - Unknown - %systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe

O23 - Service: iPod Service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe

O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe

O23 - Service: McciCMService (McciCMService) - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe

O23 - Service: Net.Tcp Port Sharing Service (NetTcpPortSharing) - Unknown - %systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe

O23 - Service: Power Manager DBC Service (Power Manager DBC Service) - Lenovo - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE

O23 - Service: Quality Windows Audio Video Experience (QWAVE) - Unknown - %windir%\system32\svchost.exe

O23 - Service: Remote Procedure Call (RPC) (RpcSs) - Unknown -

O23 - Service: Security Accounts Manager (SamSs) - Unknown -

O23 - Service: Secondary Logon (seclogon) - Unknown - %windir%\system32\svchost.exe

O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\Program Files\Lenovo\System Update\SUService.exe

O23 - Service: ThinkVantage Registry Monitor Service (ThinkVantage Registry Monitor Service) - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe

O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\Windows\system32\TPHDEXLG.exe

O23 - Service: Distributed Link Tracking Client (TrkWks) - Unknown -

O23 - Service: Windows Modules Installer (TrustedInstaller) - Unknown -

O23 - Service: TVT Backup Service (TVT Backup Service) - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe

O23 - Service: Block Level Backup Engine Service (wbengine) - Unknown - %systemroot%\system32\wbengine.exe

O23 - Service: Diagnostic Service Host (WdiServiceHost) - Unknown -

O23 - Service: Diagnostic System Host (WdiSystemHost) - Unknown -

O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown - %PROGRAMFILES%\Windows Media Player\wmpnetwk.exe

O23 - Service: IS360service (IS360service) - IObit - C:\Program Files\IObit\IObit Security 360\IS360srv.exe

Link to comment
Share on other sites

Hello and welcome to IOBit Forums. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

 

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.

2. The fixes are specific to your problem and should only be used for this issue on this machine.

3. If you don't know or understand something, please don't hesitate to ask.

4. Please DO NOT run any other tools or scans while I am helping you.

5. It is important that you reply to this thread. Do not start a new topic.

6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.

7. Absence of symptoms does not mean that everything is clear.

 

SUPERAntiSpyware

 

If you already have SUPERAntiSpyware be sure to check for updates before scanning!

 

Download SuperAntispyware Free Edition (SAS)

* Double-click the icon on your desktop to run the installer.

* When asked to Update the program definitions, click Yes

* If you encounter any problems while downloading the updates, manually download and unzip them from here

* Next click the Preferences button.

 

•Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts

* Click the Scanning Control tab.

* Under Scanner Options make sure only the following are checked:

 

•Close browsers before scanning

•Scan for tracking cookies

•Terminate memory threats before quarantining

Please leave the others unchecked

 

•Click the Close button to leave the control center screen.

 

* On the main screen click Scan your computer

* On the left check the box for the drive you are scanning.

* On the right choose Perform Complete Scan

* Click Next to start the scan. Please be patient while it scans your computer.

* After the scan is complete a summary box will appear. Click OK

* Make sure everything in the white box has a check next to it, then click Next

* It will quarantine what it found and if it asks if you want to reboot, click Yes

 

•To retrieve the removal information please do the following:

•After reboot, double-click the SUPERAntiSpyware icon on your desktop.

•Click Preferences. Click the Statistics/Logs tab.

 

•Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

 

•It will open in your default text editor (preferably Notepad).

•Save the notepad file to your desktop by clicking (in notepad) File > Save As...

 

* Save the log somewhere you can easily find it. (normally the desktop)

* Click close and close again to exit the program.

*Copy and Paste the log in your post.

****************************************

Please download Malwarebytes Anti-Malware from here.

 

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.

Extra Note:

 

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

************************************

Download Security Check by screen317 from one of the following links and save it to your desktop.

 

Link 1

Link 2

 

* Unzip SecurityCheck.zip and a folder named Security Check should appear.

* Open the Security Check folder and double-click Security Check.bat

* Follow the on-screen instructions inside of the black box.

* A Notepad document should open automatically called checkup.txt

* Post the contents of that document in your next reply.

 

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.

Link to comment
Share on other sites

Mbam

 

Malwarebytes' Anti-Malware 1.46

http://www.malwarebytes.org

 

Database version: 5128

 

Windows 6.1.7600

Internet Explorer 8.0.7600.16385

 

11/16/2010 3:16:40 PM

mbam-log-2010-11-16 (15-16-40).txt

 

Scan type: Full scan (C:\|)

Objects scanned: 247203

Time elapsed: 56 minute(s), 54 second(s)

 

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

 

Memory Processes Infected:

(No malicious items detected)

 

Memory Modules Infected:

(No malicious items detected)

 

Registry Keys Infected:

(No malicious items detected)

 

Registry Values Infected:

(No malicious items detected)

 

Registry Data Items Infected:

(No malicious items detected)

 

Folders Infected:

(No malicious items detected)

 

Files Infected:

(No malicious items detected)

Link to comment
Share on other sites

Security Check by screen317

 

Results of screen317's Security Check version 0.99.6

Windows 7 (UAC is enabled)

Internet Explorer 8

``````````````````````````````

Antivirus/Firewall Check:

Windows Security Center service is not running! This report may not be accurate!

Windows Firewall Enabled!

EAV Antivirus Suite 6.60

WMI entry may not exist for antivirus; attempting automatic update.

```````````````````````````````

Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware

Java 6 Update 22

Adobe Flash Player 10.1.53.64

Adobe Reader 9.4.0

````````````````````````````````

Process Check:

objlist.exe by Laurent

````````````````````````````````

DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

 

``````````End of Log````````````

Link to comment
Share on other sites

I don't see your SAS log.

 

Please download ComboFix http://img7.imageshack.us/img7/4930/combofix.gif from BleepingComputer.com

 

Alternate link: GeeksToGo.com

 

Rename ComboFix.exe to commy.exe before you save it to your Desktop

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here

Click Start then copy paste the following command into the search box & hit enter: "%userprofile%\desktop\commy.exe" /stepdel

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. This will not install in Vista. Just continue scanning, and skip the console install.

When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply.

 

If you have problems with ComboFix usage, see How to use ComboFix

Link to comment
Share on other sites

ComboFix

 

ComboFix 10-11-16.06 - David Coombs 11/17/2010 11:06:00.1.1 - x86

Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.1790.994 [GMT -5:00]

Running from: c:\users\David Coombs\Desktop\commy.exe

Command switches used :: /stepdel

SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

* Created a new restore point

.

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\ipconfig.txt

c:\windows\system32\arp.exe

c:\windows\system32\Thumbs.db

 

.

((((((((((((((((((((((((( Files Created from 2010-10-17 to 2010-11-17 )))))))))))))))))))))))))))))))

.

 

2010-11-17 16:21 . 2010-11-17 16:21 -------- d-----w- C:\Device

2010-11-17 16:13 . 2010-11-17 16:13 -------- d-----w- c:\users\Default\AppData\Local\temp

2010-11-16 17:20 . 2010-11-16 17:20 -------- d-----w- c:\users\David Coombs\AppData\Roaming\SUPERAntiSpyware.com

2010-11-16 17:20 . 2010-11-16 17:20 -------- d-----w- c:\programdata\SUPERAntiSpyware.com

2010-11-16 17:20 . 2010-11-16 17:21 -------- d-----w- c:\program files\SUPERAntiSpyware

2010-11-12 15:47 . 2010-11-12 15:47 388096 ----a-r- c:\users\David Coombs\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2010-11-12 15:47 . 2010-11-12 15:47 -------- d-----w- c:\program files\Trend Micro

2010-11-12 15:19 . 2010-11-12 15:19 -------- d-----w- c:\programdata\IObit

2010-11-11 14:39 . 2006-11-02 06:50 128104 ----a-w- c:\windows\system32\drivers\WimFltr.sys

2010-11-08 18:42 . 2010-11-08 18:42 -------- d-----w- c:\users\David Coombs\AppData\Roaming\Malwarebytes

2010-11-08 18:42 . 2010-04-29 20:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-11-08 18:42 . 2010-11-08 18:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-11-08 18:42 . 2010-11-08 18:42 -------- d-----w- c:\programdata\Malwarebytes

2010-11-08 18:42 . 2010-04-29 20:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-10-28 11:27 . 2010-08-04 06:18 641536 ----a-w- c:\windows\system32\CPFilters.dll

2010-10-28 11:27 . 2010-08-04 06:17 417792 ----a-w- c:\windows\system32\msdri.dll

2010-10-28 11:27 . 2010-08-04 06:15 204288 ----a-w- c:\windows\system32\MSNP.ax

2010-10-28 11:27 . 2010-08-04 06:15 199680 ----a-w- c:\windows\system32\mpg2splt.ax

2010-10-28 11:27 . 2010-07-13 05:22 26504 ----a-w- c:\windows\system32\drivers\Diskdump.sys

2010-10-26 12:40 . 2010-10-07 23:21 6146896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2D31E022-59FC-45FE-90DE-8871B114D51E}\mpengine.dll

2010-10-24 11:07 . 2010-10-24 11:07 -------- d-----w- c:\users\David Coombs\AppData\Local\Windows Live Writer

2010-10-24 11:07 . 2010-10-24 11:07 -------- d-----w- c:\users\David Coombs\AppData\Roaming\Windows Live Writer

2010-10-23 15:03 . 2010-10-23 15:03 -------- d-----w- c:\program files\iTunes

2010-10-23 15:03 . 2010-10-23 15:03 -------- d-----w- c:\program files\iPod

2010-10-23 14:59 . 2010-10-23 14:59 -------- d-----w- c:\program files\Bonjour

2010-10-21 19:38 . 2010-10-21 19:38 -------- d-----w- c:\windows\en

2010-10-21 19:35 . 2010-10-21 19:35 -------- d-----w- c:\program files\MSN Toolbar

2010-10-21 19:35 . 2010-10-21 19:35 -------- d-----w- c:\program files\Bing Bar Installer

2010-10-21 19:34 . 2009-09-04 21:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll

2010-10-21 19:34 . 2009-09-04 21:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll

2010-10-21 19:34 . 2009-09-04 21:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll

2010-10-21 19:32 . 2010-10-21 19:32 469256 ----a-w- c:\program files\Common Files\Windows Live\.cache\b37c0e871cb71562c\InstallManager_WLE_WLE.exe

2010-10-21 19:31 . 2010-10-21 19:31 15712 ----a-w- c:\program files\Common Files\Windows Live\.cache\8d40f7a91cb715620\MeshBetaRemover.exe

2010-10-21 19:30 . 2010-10-21 19:30 94040 ----a-w- c:\program files\Common Files\Windows Live\.cache\73772e0f1cb715618\DSETUP.dll

2010-10-21 19:30 . 2010-10-21 19:30 525656 ----a-w- c:\program files\Common Files\Windows Live\.cache\73772e0f1cb715618\DXSETUP.exe

2010-10-21 19:30 . 2010-10-21 19:30 1691480 ----a-w- c:\program files\Common Files\Windows Live\.cache\73772e0f1cb715618\dsetup32.dll

2010-10-21 19:30 . 2010-10-21 19:30 525656 ----a-w- c:\program files\Common Files\Windows Live\.cache\71a770541cb715617\DXSETUP.exe

2010-10-21 19:30 . 2010-10-21 19:30 1691480 ----a-w- c:\program files\Common Files\Windows Live\.cache\71a770541cb715617\dsetup32.dll

2010-10-21 19:30 . 2010-10-21 19:30 94040 ----a-w- c:\program files\Common Files\Windows Live\.cache\71a770541cb715617\DSETUP.dll

2010-10-21 19:27 . 2010-10-21 19:27 -------- d-----w- c:\users\David Coombs\AppData\Local\Windows Live

2010-10-21 19:25 . 2010-05-23 10:11 196608 ----a-w- c:\windows\system32\mfreadwrite.dll

2010-10-21 19:25 . 2010-05-23 10:11 3181568 ----a-w- c:\windows\system32\mf.dll

2010-10-21 19:25 . 2010-05-23 10:15 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-10-19 15:41 . 2010-04-25 12:24 222080 ------w- c:\windows\system32\MpSigStub.exe

2010-09-23 04:47 . 2010-09-23 04:47 49016 ----a-w- c:\windows\system32\sirenacm.dll

2010-09-23 04:32 . 2010-09-23 04:32 301936 ----a-w- c:\windows\WLXPGSS.SCR

2010-09-21 18:03 . 2010-09-21 18:03 208768 ----a-w- c:\windows\system32\LIVESSP.DLL

2010-09-15 08:50 . 2010-04-25 22:55 472808 ----a-w- c:\windows\system32\deployJava1.dll

2010-09-08 15:17 . 2010-09-08 15:17 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx

2010-09-08 15:17 . 2010-09-08 15:17 69632 ----a-w- c:\windows\system32\QuickTime.qts

2010-09-08 04:30 . 2010-10-14 18:23 978432 ----a-w- c:\windows\system32\wininet.dll

2010-09-08 04:28 . 2010-10-14 18:23 44544 ----a-w- c:\windows\system32\licmgr10.dll

2010-09-08 03:22 . 2010-10-14 18:23 386048 ----a-w- c:\windows\system32\html.iec

2010-09-08 02:48 . 2010-10-14 18:23 1638912 ----a-w- c:\windows\system32\mshtml.tlb

2010-09-01 04:23 . 2010-10-14 18:23 12625408 ----a-w- c:\windows\system32\wmploc.DLL

2010-09-01 02:34 . 2010-10-14 18:23 2327552 ----a-w- c:\windows\system32\win32k.sys

2010-08-31 04:32 . 2010-10-14 18:23 954752 ----a-w- c:\windows\system32\mfc40.dll

2010-08-31 04:32 . 2010-10-14 18:23 954288 ----a-w- c:\windows\system32\mfc40u.dll

2010-08-28 16:03 . 2010-08-28 16:03 737072 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll

2010-08-28 16:03 . 2010-05-22 21:45 4277016 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll

2010-08-28 16:02 . 2010-05-22 21:44 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll

2010-08-27 05:46 . 2010-10-14 18:23 168448 ----a-w- c:\windows\system32\srvsvc.dll

2010-08-27 03:31 . 2010-10-14 18:23 310784 ----a-w- c:\windows\system32\drivers\srv.sys

2010-08-27 03:30 . 2010-10-14 18:23 308736 ----a-w- c:\windows\system32\drivers\srv2.sys

2010-08-27 03:30 . 2010-10-14 18:23 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys

2010-08-26 04:39 . 2010-10-14 18:23 109056 ----a-w- c:\windows\system32\t2embed.dll

2010-08-21 05:36 . 2010-10-14 18:23 738816 ----a-w- c:\windows\system32\wmpmde.dll

2010-08-21 05:36 . 2010-10-14 18:23 224256 ----a-w- c:\windows\system32\schannel.dll

2010-08-21 05:33 . 2010-10-14 18:23 530432 ----a-w- c:\windows\system32\comctl32.dll

2010-08-21 05:32 . 2010-09-15 11:27 316928 ----a-w- c:\windows\system32\spoolsv.exe

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"GenieSearchforArchive"="c:\program files\Genie-Soft\Genie Archive for Outlook 2\GenieSearchforArchive.exe" [2009-02-12 336512]

"AOL Fast Start"="c:\program files\AOL 9.5\AOL.EXE" [2010-03-23 29520]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"TpShocks"="TpShocks.exe" [2009-12-11 337256]

"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe" [2009-11-16 487992]

"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768]

"PWMTRV"="c:\progra~1\ThinkPad\UTILIT~1\PWMTR32V.DLL" [2009-12-10 865640]

"Message Center Plus"="c:\program files\LENOVO\Message Center Plus\MCPLaunch.exe" [2009-05-28 49976]

"AcWin7Hlpr"="c:\program files\Lenovo\Access Connections\AcTBenabler.exe" [2009-10-14 36864]

"cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2009-08-26 3089720]

"HostManager"="c:\program files\Common Files\AOL\1272201713\ee\AOLSoftware.exe" [2010-02-10 41800]

"LENOVO.TPKNRRES"="c:\program files\Lenovo\Communications Utility\TPKNRRES.exe" [2010-03-10 62312]

"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]

"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]

"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2010-06-11 1280344]

 

c:\users\David Coombs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2010-8-19 503808]

 

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2009-10-2 795936]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NoSMMyDocs"= 1 (0x1)

"NoRecentDocsNetHood"= 1 (0x1)

 

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

"NoSMMyDocs"= 1 (0x1)

"NoRecentDocsNetHood"= 1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

 

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 LENOVO.CAMMUTE;Lenovo Camera Mute;c:\program files\Lenovo\Communications Utility\CAMMUTE.exe [2010-03-10 50536]

R3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]

R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4640000]

R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.EXE [2009-12-10 75112]

R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]

R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]

R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-01 1343400]

S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM86.sys [2009-10-09 20520]

S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiif32.sys [2008-05-12 13480]

S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]

S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-10-19 172032]

S2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\IS360srv.exe [2010-06-11 312152]

S2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction;c:\program files\Lenovo\Communications Utility\TPKNRSVC.exe [2010-03-10 74088]

S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-01-07 182304]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-03-04 277536]

S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [2010-03-09 1006624]

S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-06-05 27320]

S3 usbsmi;Integrated Camera;c:\windows\system32\DRIVERS\SMIksdrv.sys [2009-11-23 181120]

S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]

 

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPService REG_MULTI_SZ HPSLPSVC

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

.

Contents of the 'Scheduled Tasks' folder

 

2010-11-17 c:\windows\Tasks\AWC AutoSweep.job

- c:\program files\IObit\Advanced SystemCare 3\AutoSweep.exe [2010-05-28 18:11]

 

2010-11-17 c:\windows\Tasks\AWC Startup.job

- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-05-28 01:33]

 

2010-11-16 c:\windows\Tasks\AWC Update.job

- c:\program files\IObit\Advanced SystemCare 3\IObitUpdate.exe [2010-05-28 19:24]

 

2010-10-28 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job

- c:\program files\PC-Doctor\pcdlauncher.exe [2009-11-20 10:12]

 

2010-11-15 c:\windows\Tasks\SmartDefrag.job

- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-05-14 20:48]

 

2010-11-15 c:\windows\Tasks\SystemToolsDailyTest.job

- c:\program files\PC-Doctor\pcdr5cuiw32.exe [2010-01-28 17:51]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

uInternet Settings,ProxyOverride = *.local

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~1\MICROS~4\Office14\ONBttnIE.dll/105

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL

FF - ProfilePath - c:\users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\

FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-aolTB50CL-chromesbox-en-us

FF - prefs.js: browser.startup.homepage - hxxp://www.northforsythumc.org/

FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=843&invocationType=tb50-ff-aolTB50CL-ab-en-us&query=

FF - prefs.js: network.proxy.type - 0

FF - plugin: c:\progra~1\MICROS~4\Office14\NPAUTHZ.DLL

FF - plugin: c:\progra~1\MICROS~4\Office14\NPSPWRAP.DLL

FF - plugin: c:\program files\Common Files\Motive\npMotive.dll

FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll

FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

 

---- FIREFOX POLICIES ----

FF - user.js: network.protocol-handler.warn-external.dnupdate - false

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

.

- - - - ORPHANS REMOVED - - - -

 

Toolbar-Locked - (no file)

HKLM-Run-SynTPEnh - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe

 

 

.

--------------------- LOCKED REGISTRY KEYS ---------------------

 

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

--------------------- DLLs Loaded Under Running Processes ---------------------

 

- - - - - - - > 'Explorer.exe'(2744)

c:\program files\Lenovo\Access Connections\ACDeskBand.dll

c:\program files\Lenovo\Access Connections\AcLocSettings.dll

c:\program files\Lenovo\Access Connections\AcSvcStub.dll

c:\program files\Lenovo\Access Connections\ACHelper.dll

c:\program files\ThinkPad\Bluetooth Software\btncopy.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\system32\ibmpmsvc.exe

c:\windows\system32\atieclxx.exe

c:\program files\Lenovo\Access Connections\AcPrfMgrSvc.exe

c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe

c:\program files\Common Files\Motive\McciCMService.exe

c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

c:\windows\system32\taskhost.exe

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

c:\program files\Lenovo\Access Connections\AcSvc.exe

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

c:\windows\system32\WUDFHost.exe

c:\windows\system32\rundll32.exe

c:\windows\system32\conhost.exe

c:\windows\system32\DllHost.exe

c:\program files\Windows Media Player\wmpnetwk.exe

c:\program files\ThinkPad\Bluetooth Software\btwdins.exe

c:\windows\system32\sppsvc.exe

c:\program files\Lenovo\System Update\SUService.exe

c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe

c:\\?\c:\windows\system32\wbem\WMIADAP.EXE

.

**************************************************************************

.

Completion time: 2010-11-17 11:27:19 - machine was rebooted

ComboFix-quarantined-files.txt 2010-11-17 16:27

 

Pre-Run: 170,541,592,576 bytes free

Post-Run: 170,295,562,240 bytes free

 

- - End Of File - - 66D27048078D67CC6821591BA5D3BE7C

Link to comment
Share on other sites

Sas

 

Hi Superdave,

 

First I want to thank you for taking on helping me with this problem - I was at my wits end! Not sure why my SAS logs are causing so much trouble. First time it was too big but I didn't realize it had failed to post at all. Once I became aware of that I split it in two and it seem to post fine but now I see that both posts are empty - not sure what happened. Now I can't seem to find the original text file :-( I'm going to re-run it and send the results but if you think you need the original run let me know. I'm pretty sure I can find/recover it if I really need to. I have some utilities around somewhere that I haven't used in a long time that do that.

 

Dave

Link to comment
Share on other sites

How's your computer running now?

 

P2P - I see you have P2P software installed on your machine LimeWire. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation.

 

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

 

I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

*********************************************

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

 

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

 

Double-click gmer.exe. The program will begin to run.

 

**Caution**

These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised!

 

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.

  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
  • Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Link to comment
Share on other sites

LimeWire

 

Thanks for heads up on LimeWire. I don't use any P2P software. I allowed someone else to use my computer and they installed and used that software. I have uninstalled it. If you see any other questionable software please let me know.

Link to comment
Share on other sites

GMER Part 1

 

GMER 1.0.15.15530 - http://www.gmer.net

Rootkit scan 2010-11-17 16:03:06

Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 HITACHI_HTS545025B9A300 rev.PB2ZC61H

Running: gmer.exe; Driver: C:\Users\DAVIDC~1\AppData\Local\Temp\pwdyipob.sys

 

 

---- Kernel code sections - GMER 1.0.15 ----

 

.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82C87599 1 Byte [06]

.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82CABF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}

.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8DE3E000, 0x2CC244, 0xE8000020]

 

---- User code sections - GMER 1.0.15 ----

 

.text C:\Windows\Explorer.EXE[2092] kernel32.dll!CreateProcessW 7600202D 6 Bytes JMP 5F0D0F5A

.text C:\Windows\Explorer.EXE[2092] kernel32.dll!CreateProcessA 76002062 6 Bytes JMP 5F0A0F5A

.text C:\Windows\Explorer.EXE[2092] kernel32.dll!LoadLibraryExW 7604B6BF 6 Bytes JMP 5F070F5A

.text C:\Windows\Explorer.EXE[2092] ADVAPI32.dll!CreateProcessAsUserW 7623BBDB 6 Bytes JMP 5F100F5A

.text C:\Windows\Explorer.EXE[2092] ADVAPI32.dll!CreateProcessWithLogonW 762742A1 6 Bytes JMP 5F040F5A

.text C:\Windows\System32\notepad.exe[17180] ntdll.dll!NtCreateKey 77104A70 3 Bytes [FF, 25, 1E]

.text C:\Windows\System32\notepad.exe[17180] ntdll.dll!NtCreateKey + 4 77104A74 2 Bytes [17, 5F] {POP SS; POP EDI}

.text C:\Windows\System32\notepad.exe[17180] ntdll.dll!NtSetValueKey 77105C70 3 Bytes [FF, 25, 1E]

.text C:\Windows\System32\notepad.exe[17180] ntdll.dll!NtSetValueKey + 4 77105C74 2 Bytes [14, 5F] {ADC AL, 0x5f}

.text C:\Windows\System32\notepad.exe[17180] kernel32.dll!CreateProcessW 7600202D 6 Bytes JMP 5F0D0F5A

.text C:\Windows\System32\notepad.exe[17180] kernel32.dll!CreateProcessA 76002062 6 Bytes JMP 5F0A0F5A

.text C:\Windows\System32\notepad.exe[17180] kernel32.dll!LoadLibraryExW 7604B6BF 6 Bytes JMP 5F070F5A

.text C:\Windows\System32\notepad.exe[17180] ADVAPI32.dll!CreateProcessAsUserW 7623BBDB 6 Bytes JMP 5F100F5A

.text C:\Windows\System32\notepad.exe[17180] ADVAPI32.dll!CreateServiceW 7625DBC1 6 Bytes JMP 5F1C0F5A

.text C:\Windows\System32\notepad.exe[17180] ADVAPI32.dll!CreateServiceA 76272120 6 Bytes JMP 5F190F5A

.text C:\Windows\System32\notepad.exe[17180] ADVAPI32.dll!CreateProcessWithLogonW 762742A1 6 Bytes JMP 5F040F5A

 

---- User IAT/EAT - GMER 1.0.15 ----

 

IAT C:\Windows\Explorer.EXE[2092] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73F62494] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

IAT C:\Windows\Explorer.EXE[2092] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73F45624] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

IAT C:\Windows\Explorer.EXE[2092] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73F456E2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

IAT C:\Windows\Explorer.EXE[2092] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [73F6250F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

IAT C:\Windows\Explorer.EXE[2092] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73F58573] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

IAT C:\Windows\Explorer.EXE[2092] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73F54D27] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

IAT C:\Windows\Explorer.EXE[2092] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [73F550CE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

IAT C:\Windows\Explorer.EXE[2092] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [73F551A3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

IAT C:\Windows\Explorer.EXE[2092] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [73F566D0] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

IAT C:\Windows\Explorer.EXE[2092] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [73F582CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

IAT C:\Windows\Explorer.EXE[2092] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73F58819] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

IAT C:\Windows\Explorer.EXE[2092] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [73F5907A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

IAT C:\Windows\Explorer.EXE[2092] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [73F5E21D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

IAT C:\Windows\Explorer.EXE[2092] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73F54C59] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\user32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9E78] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\user32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9DEB] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\user32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9F05] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\user32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9F05] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9E78] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9CDD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9E78] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9CDD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9DEB] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9F05] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9CDD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9CDD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9E78] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9DEB] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9F05] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9CDD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9F05] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9E78] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [6BFA9CDD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9F05] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9E78] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9DEB] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\AOL 9.5\waol.exe[2164] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9CDD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Windows\System32\rundll32.exe[2432] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

IAT C:\Windows\System32\rundll32.exe[2432] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

IAT C:\Windows\System32\rundll32.exe[2432] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

IAT C:\Windows\System32\rundll32.exe[2432] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

IAT C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe[2440] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

IAT C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe[2440] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

IAT C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe[2440] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

IAT C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe[2440] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9E78] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9CDD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9DEB] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9F05] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9E78] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9DEB] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9F05] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9F05] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9E78] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9CDD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9CDD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9CDD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9E78] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9DEB] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9F05] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe[2464] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9CDD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

Link to comment
Share on other sites

GMER Part 2

 

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9E78] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9DEB] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9F05] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9F05] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9E78] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9CDD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9CDD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9CDD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9E78] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9DEB] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9F05] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9CDD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9E78] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9CDD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9DEB] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9F05] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [6BFA9D64] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9F05] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9E78] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [6BFA9CDD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[3204] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

IAT c:\Program Files\Lenovo\System Update\SUService.exe[4696] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

IAT c:\Program Files\Lenovo\System Update\SUService.exe[4696] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

IAT c:\Program Files\Lenovo\System Update\SUService.exe[4696] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

IAT c:\Program Files\Lenovo\System Update\SUService.exe[4696] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

IAT c:\Program Files\Lenovo\System Update\SUService.exe[4696] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75165E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

 

---- Devices - GMER 1.0.15 ----

 

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)

 

Device \Driver\ACPI_HAL \Device\00000054 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

 

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

AttachedDevice \Driver\volmgr \Device\HarddiskVolume8 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

 

---- Registry - GMER 1.0.15 ----

 

Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001f3ad3f68b

Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001f3ad3f68b (not active ControlSet)

 

---- Disk sectors - GMER 1.0.15 ----

 

Disk \Device\Harddisk0\DR0 sector 08: copy of MBR

 

---- EOF - GMER 1.0.15 ----

Link to comment
Share on other sites

SAS Part 1

 

SUPERAntiSpyware Scan Log

http://www.superantispyware.com

 

Generated 11/17/2010 at 01:39 PM

 

Application Version : 4.45.1000

 

Core Rules Database Version : 5874

Trace Rules Database Version: 3686

 

Scan type : Complete Scan

Total Scan Time : 01:12:10

 

Memory items scanned : 449

Memory threats detected : 0

Registry items scanned : 9365

Registry threats detected : 0

File items scanned : 105121

File threats detected : 358

 

Adware.Tracking Cookie

C:\Users\David Coombs\AppData\Roaming\Microsoft\Windows\Cookies\david_coombs@ar.atwola[3].txt

C:\Users\David Coombs\AppData\Roaming\Microsoft\Windows\Cookies\david_coombs@ar.atwola[2].txt

C:\Users\David Coombs\AppData\Roaming\Microsoft\Windows\Cookies\david_coombs@invitemedia[2].txt

C:\Users\David Coombs\AppData\Roaming\Microsoft\Windows\Cookies\david_coombs@sojo.advertserve[2].txt

C:\Users\David Coombs\AppData\Roaming\Microsoft\Windows\Cookies\david_coombs@track.abilityemail[2].txt

C:\Users\David Coombs\AppData\Roaming\Microsoft\Windows\Cookies\david_coombs@atwola[2].txt

C:\Users\David Coombs\AppData\Roaming\Microsoft\Windows\Cookies\david_coombs@at.atwola[2].txt

C:\Users\David Coombs\AppData\Roaming\Microsoft\Windows\Cookies\david_coombs@cdn.at.atwola[1].txt

.doubleclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

cdn4.specificclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

cdn4.specificclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

cdn4.specificclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.specificclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.specificclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

cdn4.specificclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.specificclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

cdn4.specificclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

cdn4.specificclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.statcounter.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.interclick.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.fastclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.fastclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.trafficmp.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.trafficmp.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.interclick.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.interclick.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.collective-media.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.specificclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.specificclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.specificmedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.invitemedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.invitemedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.adbrite.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.adbrite.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

ad.yieldmanager.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

sojo.advertserve.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.advertising.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.advertising.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.advertising.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.advertising.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.advertising.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.atdmt.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.atdmt.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.doubleclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

ad.yieldmanager.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.advertising.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.yieldmanager.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.apmebf.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.fastclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.revsci.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.imrworldwide.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.imrworldwide.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.e-2dj6wjkoulcpcdo.stats.esomniture.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.media6degrees.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.media6degrees.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.247realmedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.media6degrees.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.http://www.internetworldstats.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.internetworldstats.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.internetworldstats.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.internetworldstats.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.invitemedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.invitemedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.invitemedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.invitemedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.invitemedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.bs.serving-sys.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.serving-sys.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.serving-sys.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.serving-sys.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.serving-sys.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.serving-sys.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.serving-sys.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.serving-sys.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.questionmarket.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.mediaplex.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

metroleap.rotator.hadj7.adjuggler.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

metroleap.rotator.hadj7.adjuggler.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.tribalfusion.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.adecn.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.kontera.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.kontera.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.kontera.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.kontera.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.casalemedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.casalemedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.casalemedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.mediaplex.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.revenue.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.zedo.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.zedo.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.stateofgeorgia.122.2o7.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.richmedia.yahoo.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.generalelectric.112.2o7.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.media6degrees.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.media6degrees.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

statse.webtrendslive.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.pentonmedia.122.2o7.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.adbrite.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

parentmediagroup.go2jump.org [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.tacoda.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.tacoda.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.tacoda.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.at.atwola.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.at.atwola.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

http://www.ez-tracks.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

http://www.ez-tracks.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

http://www.ez-tracks.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ez-tracks.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

cdn4.specificclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.adxpose.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ads.pointroll.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.pointroll.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.pointroll.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ads.pointroll.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ads.pointroll.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ads.pointroll.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ads.pointroll.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ads.pointroll.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ads.pointroll.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.tripod.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ads.pointroll.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

cdn4.specificclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.nextag.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.nextag.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.nextag.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.nextag.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

stat.dealtime.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.a1.interclick.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.a1.interclick.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.a1.interclick.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.a1.interclick.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.interclick.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.realmedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

pluckit.demandmedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.dmtracker.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.2o7.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.paypal.112.2o7.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.bizrate.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.bizrate.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.invitemedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.overture.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.overture.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.gotquestions.org [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.gotquestions.org [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

http://www.gotquestions.org [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.2o7.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.burstnet.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.liveperson.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.liveperson.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.realmedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ru4.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ru4.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ru4.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ru4.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ru4.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.media6degrees.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ice.112.2o7.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.clickshift.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.adserver.adtechus.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.chitika.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.trvlnet.adbureau.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.trvlnet.adbureau.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.trvlnet.adbureau.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.trvlnet.adbureau.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.traveladvertising.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.traveladvertising.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.traveladvertising.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.trvlnet.adbureau.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.trvlnet.adbureau.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.traveladvertising.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.traveladvertising.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.stpetersburgtimes.122.2o7.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ehg-verizon.hitbox.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ehg-verizon.hitbox.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.hitbox.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.liveperson.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

myaccount.verizonwireless.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ehg-verizon.hitbox.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.http://www.investorsinsight.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.investorsinsight.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.investorsinsight.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.investorsinsight.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

eas.apm.emediate.eu [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.investorsinsight.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

http://www.investorsinsight.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.elephantgroup.122.2o7.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ru4.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

dc.tremormedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

http://www.burstbeacon.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.burstbeacon.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.media6degrees.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

rx9vh3hy4r.cs.serialssolutions.com.ezproxy.liberty.edu [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

rx9vh3hy4r.search.serialssolutions.com.ezproxy.liberty.edu [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.googleads.g.doubleclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

Link to comment
Share on other sites

SAS Part 2

 

findarticles.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.findarticles.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.findarticles.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.findarticles.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.findarticles.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.findarticles.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.onetoone.112.2o7.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.find.galegroup.com.ezproxy.liberty.edu [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.find.galegroup.com.ezproxy.liberty.edu [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

in.getclicky.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.lucidmedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.lucidmedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.lucidmedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.2o7.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.2o7.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.dealtime.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.dealtime.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.superstats.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

track.abilityemail.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

track.abilityemail.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.liveperson.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

solutions.liveperson.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

solutions.liveperson.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.liveperson.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.liveperson.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.liveperson.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.mediasuite.multicastmedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.mediasuite.multicastmedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.statcounter.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.yadro.ru [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.eyewonder.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.advertise.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

clicks.bestsearchfind.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

click.myiqnow.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.adknowledge.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.adknowledge.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.adknowledge.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

clicks.freesearchquick.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

c.searchfeedengine-us.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

web4.realtracker.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

counter.surfcounters.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.findgreatlistings.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

http://www.findstuff.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.atdmt.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.atdmt.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.msnportal.112.2o7.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.collective-media.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.zedo.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.zedo.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.2o7.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.invitemedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.http://www.burstnet.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.kontera.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.legolas-media.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.legolas-media.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.legolas-media.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

http://www.googleadservices.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.liveperson.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.collective-media.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

ad.yieldmanager.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

ad.yieldmanager.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

bridge2.admarketplace.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.admarketplace.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.theclickcheck.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.theclickcheck.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.pro-market.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.pro-market.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.gsicace.112.2o7.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.kantarmedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.revsci.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

ad.yieldmanager.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.advertising.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.a1.interclick.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.fultoncountyga.gov [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.fultoncountyga.gov [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.at.atwola.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.tacoda.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

http://www.googleadservices.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

http://www.googleadservices.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.web-stat.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.web-stat.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.web-stat.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.collective-media.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.revsci.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.enhance.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.enhance.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.pro-market.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.kaspersky.122.2o7.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.lucidmedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.collective-media.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.lucidmedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.lucidmedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.bestsearchfind.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

http://www.googleadservices.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

adserving.autotrader.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.adserver.adtechus.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.smartadserver.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.smartadserver.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.smartadserver.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.smartadserver.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

http://www.icityfind.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.toseeka.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.revsci.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.questionmarket.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.cbsdigitalmedia.112.2o7.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.fastclick.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

d.jambomedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

csm.rotator.hadj7.adjuggler.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

csm.rotator.hadj7.adjuggler.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.pro-market.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.xiti.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

http://www.googleadservices.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.clickbank.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.trafficmp.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.webreports.digitalinsight.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.webreports.digitalinsight.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.webreports.digitalinsight.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.webreports.digitalinsight.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.liveperson.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.zedo.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.insightexpressai.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.adbrite.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ru4.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.ru4.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.casalemedia.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.revsci.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.adbrite.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.perf.overture.com [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.collective-media.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.collective-media.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.collective-media.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.collective-media.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.tacoda.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.tacoda.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.revsci.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.revsci.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

.revsci.net [ C:\Users\David Coombs\AppData\Roaming\Mozilla\Firefox\Profiles\xstc0zcr.default\cookies.sqlite ]

Link to comment
Share on other sites

Please download MBRCheck.exe by a_d_13 from one of the links provided below and save it to your desktop.

 

Link 1

Link 2

Link 3

 

•Double-click on MBRCheck.exe to run it.

 

•It will open a black window...please do not fix anything (if it gives you an option).

 

•When complete, you should see Done! Press ENTER to exit.... Press Enter on the keyboard.

 

•A log named MBRCheck_date_time.txt (i.e. MBRCheck_07.21.10_10.22.51.txt) will appear on the desktop.

•Please copy and paste the contents of that log in your next reply.

Link to comment
Share on other sites

Mbr

 

MBRCheck, version 1.2.3

© 2010, AD

 

Command-line:

Windows Version: Windows 7 Professional

Windows Information: (build 7600), 32-bit

Base Board Manufacturer: LENOVO

BIOS Manufacturer: LENOVO

System Manufacturer: LENOVO

System Product Name: 350829U

Logical Drives Mask: 0x00010004

 

Kernel Drivers (total 191):

0x82C49000 \SystemRoot\system32\ntkrnlpa.exe

0x82C12000 \SystemRoot\system32\halmacpi.dll

0x80BBC000 \SystemRoot\system32\kdcom.dll

0x8321F000 \SystemRoot\system32\mcupdate_AuthenticAMD.dll

0x8322A000 \SystemRoot\system32\PSHED.dll

0x8323B000 \SystemRoot\system32\BOOTVID.dll

0x83243000 \SystemRoot\system32\CLFS.SYS

0x83285000 \SystemRoot\system32\CI.dll

0x83330000 \SystemRoot\system32\drivers\Wdf01000.sys

0x833A1000 \SystemRoot\system32\drivers\WDFLDR.SYS

0x833AF000 \SystemRoot\system32\DRIVERS\ACPI.sys

0x833F7000 \SystemRoot\system32\DRIVERS\WMILIB.SYS

0x83200000 \SystemRoot\system32\DRIVERS\msisadrv.sys

0x8800C000 \SystemRoot\system32\DRIVERS\pci.sys

0x88036000 \SystemRoot\system32\DRIVERS\vdrvroot.sys

0x88041000 \SystemRoot\System32\drivers\partmgr.sys

0x88052000 \SystemRoot\system32\DRIVERS\compbatt.sys

0x8805A000 \SystemRoot\system32\DRIVERS\BATTC.SYS

0x88065000 \SystemRoot\system32\DRIVERS\volmgr.sys

0x88075000 \SystemRoot\System32\drivers\volmgrx.sys

0x880C0000 \SystemRoot\System32\drivers\mountmgr.sys

0x880D6000 \SystemRoot\system32\DRIVERS\atapi.sys

0x880DF000 \SystemRoot\system32\DRIVERS\ataport.SYS

0x88102000 \SystemRoot\system32\DRIVERS\msahci.sys

0x8810C000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS

0x8811A000 \SystemRoot\system32\DRIVERS\amdxata.sys

0x88123000 \SystemRoot\system32\drivers\fltmgr.sys

0x88157000 \SystemRoot\system32\drivers\fileinfo.sys

0x88209000 \SystemRoot\System32\Drivers\Ntfs.sys

0x88338000 \SystemRoot\System32\Drivers\msrpc.sys

0x88363000 \SystemRoot\System32\Drivers\ksecdd.sys

0x88376000 \SystemRoot\System32\Drivers\cng.sys

0x883D3000 \SystemRoot\System32\drivers\pcw.sys

0x883E1000 \SystemRoot\System32\Drivers\Fs_Rec.sys

0x88407000 \SystemRoot\system32\drivers\ndis.sys

0x884BE000 \SystemRoot\system32\drivers\NETIO.SYS

0x884FC000 \SystemRoot\System32\Drivers\ksecpkg.sys

0x88629000 \SystemRoot\System32\drivers\tcpip.sys

0x88772000 \SystemRoot\System32\drivers\fwpkclnt.sys

0x887A3000 \SystemRoot\system32\DRIVERS\vmstorfl.sys

0x887AC000 \SystemRoot\system32\DRIVERS\volsnap.sys

0x887EB000 \SystemRoot\System32\DRIVERS\ApsHM86.sys

0x887F4000 \SystemRoot\System32\Drivers\spldr.sys

0x88521000 \SystemRoot\System32\drivers\rdyboost.sys

0x88600000 \SystemRoot\System32\DRIVERS\Apsx86.sys

0x8854E000 \SystemRoot\System32\Drivers\mup.sys

0x88620000 \SystemRoot\System32\drivers\hwpolicy.sys

0x8855E000 \SystemRoot\System32\DRIVERS\fvevol.sys

0x88590000 \SystemRoot\system32\DRIVERS\disk.sys

0x885A1000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS

0x885C6000 \SystemRoot\system32\DRIVERS\AtiPcie.sys

0x88400000 \SystemRoot\System32\Drivers\Null.SYS

0x885CE000 \SystemRoot\System32\Drivers\Beep.SYS

0x885D5000 \SystemRoot\System32\drivers\vga.sys

0x88168000 \SystemRoot\System32\drivers\VIDEOPRT.SYS

0x885E1000 \SystemRoot\System32\drivers\watchdog.sys

0x885EE000 \SystemRoot\System32\DRIVERS\RDPCDD.sys

0x885F6000 \SystemRoot\system32\drivers\rdpencdd.sys

0x883EA000 \SystemRoot\system32\drivers\rdprefmp.sys

0x883F2000 \SystemRoot\System32\Drivers\Msfs.SYS

0x88189000 \SystemRoot\System32\Drivers\Npfs.SYS

0x88197000 \SystemRoot\system32\DRIVERS\tdx.sys

0x881AE000 \SystemRoot\system32\DRIVERS\TDI.SYS

0x8D421000 \SystemRoot\system32\drivers\afd.sys

0x8D47B000 \SystemRoot\System32\DRIVERS\netbt.sys

0x8D4AD000 \SystemRoot\system32\DRIVERS\wfplwf.sys

0x8D4B4000 \SystemRoot\system32\DRIVERS\pacer.sys

0x8D4D3000 \SystemRoot\system32\DRIVERS\vwififlt.sys

0x8D4E4000 \SystemRoot\system32\DRIVERS\netbios.sys

0x8D4F2000 \SystemRoot\system32\DRIVERS\wanarp.sys

0x8D505000 \SystemRoot\System32\drivers\Tppwr32v.sys

0x8D50C000 \SystemRoot\system32\DRIVERS\termdd.sys

0x8D51C000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS

0x8D53E000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS

0x8D544000 \SystemRoot\system32\DRIVERS\rdbss.sys

0x8D585000 \SystemRoot\system32\drivers\nsiproxy.sys

0x8D58F000 \SystemRoot\system32\DRIVERS\mssmbios.sys

0x8D599000 \SystemRoot\system32\DRIVERS\smiif32.sys

0x8D59B000 \SystemRoot\System32\drivers\discache.sys

0x8D210000 \SystemRoot\system32\drivers\csc.sys

0x8D274000 \SystemRoot\System32\Drivers\dfsc.sys

0x8D28C000 \SystemRoot\system32\DRIVERS\blbdrive.sys

0x8D29A000 \SystemRoot\system32\DRIVERS\tunnel.sys

0x8D2BB000 \SystemRoot\system32\DRIVERS\amdk8.sys

0x8D2CD000 \SystemRoot\system32\DRIVERS\wmiacpi.sys

0x8DA21000 \SystemRoot\system32\DRIVERS\atikmdag.sys

0x8D2D6000 \SystemRoot\System32\drivers\dxgkrnl.sys

0x8DF61000 \SystemRoot\System32\drivers\dxgmms1.sys

0x8DF9A000 \SystemRoot\system32\DRIVERS\Rt86win7.sys

0x8D804000 \SystemRoot\system32\DRIVERS\rtl8192se.sys

0x8D917000 \SystemRoot\system32\DRIVERS\vwifibus.sys

0x8D921000 \SystemRoot\system32\DRIVERS\usbohci.sys

0x8D92B000 \SystemRoot\system32\DRIVERS\USBPORT.SYS

0x8D976000 \SystemRoot\system32\DRIVERS\usbfilter.sys

0x8D97C000 \SystemRoot\system32\DRIVERS\usbehci.sys

0x8D98B000 \SystemRoot\system32\DRIVERS\HDAudBus.sys

0x8D9AA000 \SystemRoot\system32\DRIVERS\i8042prt.sys

0x8D9C2000 \SystemRoot\system32\DRIVERS\kbdclass.sys

0x8D38D000 \SystemRoot\system32\DRIVERS\SynTP.sys

0x8D9CF000 \SystemRoot\system32\DRIVERS\USBD.SYS

0x8D9D1000 \SystemRoot\system32\DRIVERS\mouclass.sys

0x8D9DE000 \SystemRoot\system32\DRIVERS\ibmpmdrv.sys

0x8D9E3000 \SystemRoot\system32\DRIVERS\CmBatt.sys

0x8D9E7000 \SystemRoot\system32\DRIVERS\CompositeBus.sys

0x8D9F4000 \SystemRoot\system32\DRIVERS\serscan.sys

0x8DFDF000 \SystemRoot\system32\DRIVERS\AgileVpn.sys

0x8DA00000 \SystemRoot\system32\DRIVERS\rasl2tp.sys

0x8DFF1000 \SystemRoot\system32\DRIVERS\ndistapi.sys

0x8D3C8000 \SystemRoot\system32\DRIVERS\ndiswan.sys

0x8D5A7000 \SystemRoot\system32\DRIVERS\raspppoe.sys

0x8D5BF000 \SystemRoot\system32\DRIVERS\raspptp.sys

0x8D5D6000 \SystemRoot\system32\DRIVERS\rassstp.sys

0x8DA18000 \SystemRoot\system32\DRIVERS\wanatw4.sys

0x8D3EA000 \SystemRoot\system32\DRIVERS\rdpbus.sys

0x8D3F4000 \SystemRoot\system32\DRIVERS\psadd.sys

0x8D9FC000 \SystemRoot\system32\DRIVERS\swenum.sys

0x881B9000 \SystemRoot\system32\DRIVERS\ks.sys

0x8D200000 \SystemRoot\system32\DRIVERS\umbus.sys

0x8E826000 \SystemRoot\system32\DRIVERS\usbhub.sys

0x8E86A000 \SystemRoot\System32\Drivers\NDProxy.SYS

0x8E87B000 \SystemRoot\system32\drivers\CHDRT32.sys

0x8E8FA000 \SystemRoot\system32\drivers\portcls.sys

0x8E929000 \SystemRoot\system32\drivers\drmk.sys

0x8E942000 \SystemRoot\System32\Drivers\RtsUStor.sys

0x8E970000 \SystemRoot\system32\DRIVERS\usbccgp.sys

0x8E987000 \SystemRoot\system32\DRIVERS\SMIksdrv.sys

0x81E14000 \SystemRoot\system32\DRIVERS\SMIEXP.SYS

0x82570000 \SystemRoot\System32\win32k.sys

0x82090000 \SystemRoot\System32\drivers\Dxapi.sys

0x8209A000 \SystemRoot\system32\DRIVERS\monitor.sys

0x827D0000 \SystemRoot\System32\TSDDD.dll

0x820A5000 \SystemRoot\system32\drivers\luafv.sys

0x820C0000 \SystemRoot\system32\drivers\WudfPf.sys

0x820DA000 \SystemRoot\system32\DRIVERS\lltdio.sys

0x820EA000 \SystemRoot\system32\DRIVERS\nwifi.sys

0x82130000 \SystemRoot\system32\DRIVERS\ndisuio.sys

0x82140000 \SystemRoot\system32\DRIVERS\rspndr.sys

0x82153000 \SystemRoot\system32\DRIVERS\vwifimp.sys

0x8215C000 \SystemRoot\system32\drivers\HTTP.sys

0x821E1000 \SystemRoot\system32\DRIVERS\bowser.sys

0x81E00000 \SystemRoot\System32\drivers\mpsdrv.sys

0x8E9B4000 \SystemRoot\system32\DRIVERS\mrxsmb.sys

0x99211000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys

0x9924C000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys

0x9927F000 \SystemRoot\system32\drivers\peauth.sys

0x99316000 \SystemRoot\System32\Drivers\secdrv.SYS

0x99320000 \SystemRoot\System32\DRIVERS\srvnet.sys

0x99341000 \SystemRoot\System32\drivers\tcpipreg.sys

0x9934E000 \SystemRoot\System32\DRIVERS\srv2.sys

0x9939D000 \SystemRoot\System32\DRIVERS\srv.sys

0x82440000 \SystemRoot\System32\cdd.dll

0x993EE000 \SystemRoot\system32\DRIVERS\asyncmac.sys

0x772D0000 \Windows\System32\ntdll.dll

0x47CA0000 \Windows\System32\smss.exe

0x77510000 \Windows\System32\apisetschema.dll

0x00080000 \Windows\System32\autochk.exe

0x77420000 \Windows\System32\kernel32.dll

0x77290000 \Windows\System32\ws2_32.dll

0x77130000 \Windows\System32\ole32.dll

0x77060000 \Windows\System32\msctf.dll

0x77410000 \Windows\System32\psapi.dll

0x76FB0000 \Windows\System32\rpcrt4.dll

0x76F90000 \Windows\System32\sechost.dll

0x76340000 \Windows\System32\shell32.dll

0x761A0000 \Windows\System32\setupapi.dll

0x76190000 \Windows\System32\lpk.dll

0x760C0000 \Windows\System32\user32.dll

0x76070000 \Windows\System32\gdi32.dll

0x76010000 \Windows\System32\shlwapi.dll

0x75E10000 \Windows\System32\iertutil.dll

0x75D90000 \Windows\System32\comdlg32.dll

0x75CF0000 \Windows\System32\advapi32.dll

0x75CE0000 \Windows\System32\normaliz.dll

0x75C30000 \Windows\System32\msvcrt.dll

0x75B30000 \Windows\System32\wininet.dll

0x759F0000 \Windows\System32\urlmon.dll

0x759D0000 \Windows\System32\imm32.dll

0x75930000 \Windows\System32\usp10.dll

0x75920000 \Windows\System32\nsi.dll

0x75890000 \Windows\System32\oleaut32.dll

0x75800000 \Windows\System32\clbcatq.dll

0x757B0000 \Windows\System32\Wldap32.dll

0x75750000 \Windows\System32\difxapi.dll

0x75720000 \Windows\System32\imagehlp.dll

0x756F0000 \Windows\System32\wintrust.dll

0x755D0000 \Windows\System32\crypt32.dll

0x75580000 \Windows\System32\KernelBase.dll

0x75560000 \Windows\System32\devobj.dll

0x754D0000 \Windows\System32\comctl32.dll

0x754A0000 \Windows\System32\cfgmgr32.dll

0x75490000 \Windows\System32\msasn1.dll

 

Processes (total 84):

0 System Idle Process

4 System

248 C:\Windows\System32\smss.exe

376 csrss.exe

448 C:\Windows\System32\wininit.exe

524 C:\Windows\System32\services.exe

532 C:\Windows\System32\lsass.exe

540 C:\Windows\System32\lsm.exe

676 C:\Windows\System32\svchost.exe

736 C:\Windows\System32\ibmpmsvc.exe

780 C:\Windows\System32\svchost.exe

828 C:\Windows\System32\atiesrxx.exe

896 C:\Windows\System32\svchost.exe

932 C:\Windows\System32\svchost.exe

972 C:\Windows\System32\svchost.exe

1164 C:\Windows\System32\svchost.exe

1360 C:\Windows\System32\svchost.exe

1472 C:\Windows\System32\spoolsv.exe

1508 C:\Windows\System32\svchost.exe

1580 C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe

1604 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

1636 C:\Program Files\Bonjour\mDNSResponder.exe

1708 C:\Windows\System32\svchost.exe

1740 C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe

1768 C:\Program Files\IObit\IObit Security 360\is360srv.exe

1800 C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe

1840 C:\Program Files\Common Files\Motive\McciCMService.exe

1880 C:\Windows\System32\svchost.exe

1948 C:\Windows\System32\svchost.exe

2000 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

388 C:\Windows\System32\svchost.exe

1544 C:\Windows\System32\svchost.exe

2088 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE

2120 C:\Program Files\Lenovo\Access Connections\AcSvc.exe

2248 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE

3248 WmiPrvSE.exe

3328 C:\Program Files\iPod\bin\iPodService.exe

3872 C:\Program Files\Lenovo\Access Connections\SvcGuiHlpr.exe

3616 C:\Windows\System32\svchost.exe

580 C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe

372 C:\Windows\System32\svchost.exe

3600 C:\Program Files\Lenovo\System Update\SUService.exe

2456 C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe

3544 C:\Program Files\Windows Media Player\wmpnetwk.exe

2148 csrss.exe

1004 C:\Windows\System32\winlogon.exe

3124 C:\Windows\System32\atieclxx.exe

1972 C:\Windows\System32\taskhost.exe

2152 C:\Windows\System32\dwm.exe

3644 C:\Windows\explorer.exe

160 C:\Windows\System32\taskeng.exe

3652 C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe

3532 C:\Windows\System32\TpShocks.exe

3296 C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe

2372 C:\Windows\System32\rundll32.exe

3220 C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe

3516 C:\Program Files\Lenovo\Client Security Solution\cssauth.exe

2596 C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe

2692 C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe

3668 C:\Program Files\HP\HP Software Update\hpwuschd2.exe

3288 C:\Program Files\iTunes\iTunesHelper.exe

2308 C:\Program Files\IObit\IObit Security 360\is360tray.exe

1232 C:\Program Files\Genie-Soft\Genie Archive for Outlook 2\GenieSearchforArchive.exe

1236 C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe

2304 C:\Program Files\Genie-Soft\Genie Archive for Outlook 2\GenieSearchDealer.exe

3464 C:\Windows\System32\audiodg.exe

968 C:\Program Files\Genie-Soft\Genie Archive for Outlook 2\GenieServer\apache2\bin\GenieWebServer.exe

3160 C:\Windows\System32\conhost.exe

1000 C:\Program Files\Genie-Soft\Genie Archive for Outlook 2\GenieServer\apache2\bin\GenieWebServer.exe

2260 C:\Windows\System32\svchost.exe

4448 dllhost.exe

5288 C:\Windows\System32\msiexec.exe

3964 C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE

2776 C:\Windows\System32\SearchIndexer.exe

4720 C:\Program Files\Microsoft Streets & Trips 2010\StreetsOlkShim.exe

4904 C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE

2080 C:\Program Files\AOL 9.5\waol.exe

5192 C:\Program Files\Common Files\aol\acs\AOLacsd.exe

5500 C:\Program Files\AOL 9.5\shellmon.exe

5516 C:\Program Files\Mozilla Firefox\firefox.exe

5900 C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe

1912 C:\Users\David Coombs\Downloads\MBRCheck.exe

4624 C:\Windows\System32\conhost.exe

4844 C:\Windows\System32\dllhost.exe

 

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`4b100000 (NTFS)

\\.\Q: --> \\.\PhysicalDrive0 at offset 0x00000037`c7a00000 (NTFS)

 

PhysicalDrive0 Model Number: HITACHIHTS545025B9A300, Rev: PB2ZC61H

 

Size Device Name MBR Status

--------------------------------------------

232 GB \\.\PhysicalDrive0 Unknown MBR code

SHA1: D8BAD4AC878EBC559DD84404D0802642679078D1

 

 

Found non-standard or infected MBR.

Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Options:

[1] Dump the MBR of a physical disk to file.

[2] Restore the MBR of a physical disk with a standard boot code.

[3] Exit.

 

Enter your choice:

 

Done!

Link to comment
Share on other sites

Please download NTBR by noahdfear and save it to your Desktop.

File size: 2.44 MB (2,565,432 bytes)

 

  • Place a blank CD in your CD drive.
  • Double click on NTBR_CD.exe file and a folder of the same name will appear.
  • Open the folder and double click on BurnItCD.cmd file. If your CD drive will open, simply close it.
  • Follow the prompts to burn the CD.

  • Now you will need to set the CD-Rom as first boot device if it isn't already (if you don't know how to do it, see HERE)
  • If you have any questions about this step, ask before you proceed. If you enter the BIOS and are unsure if you have carried out the step correctly, there should be an option to exit without keeping changes, so you won't do any harm.

  • Insert the newly created CD into your infected PC and reboot your computer.
  • Once you have rebooted please press Enter when prompted to continue booting from CD - you have a whole 15 seconds to do this!
  • Read the warning and then continue as prompted.
  • You first need to select your keyboard layout - press Enter for English.
  • Next you want to select the appropriate tool. Enter 1 to choose 1. MBRWORK
  • On the following screen enter 5 to select Install Standard MBR code.
  • Enter 2 to overwrite the infected MBR Code with the Windows 7 MBR code.
  • When asked to confirm please do so.
  • Afterwards, please enter E to leave MBRWORK, then 6 to leave the bootable CD.
  • Eject the disc and then press ctrl+alt+del to reboot the PC.

Once rebooted, run MBRCheck again and post its log.

Link to comment
Share on other sites

MRBCheck

 

MBRCheck, version 1.2.3

© 2010, AD

 

Command-line:

Windows Version: Windows 7 Professional

Windows Information: (build 7600), 32-bit

Base Board Manufacturer: LENOVO

BIOS Manufacturer: LENOVO

System Manufacturer: LENOVO

System Product Name: 350829U

Logical Drives Mask: 0x000101fc

 

Kernel Drivers (total 201):

0x82C0F000 \SystemRoot\system32\ntkrnlpa.exe

0x8301F000 \SystemRoot\system32\halmacpi.dll

0x80BB6000 \SystemRoot\system32\kdcom.dll

0x83209000 \SystemRoot\system32\mcupdate_AuthenticAMD.dll

0x83214000 \SystemRoot\system32\PSHED.dll

0x83225000 \SystemRoot\system32\BOOTVID.dll

0x8322D000 \SystemRoot\system32\CLFS.SYS

0x8326F000 \SystemRoot\system32\CI.dll

0x8331A000 \SystemRoot\system32\drivers\Wdf01000.sys

0x8338B000 \SystemRoot\system32\drivers\WDFLDR.SYS

0x83399000 \SystemRoot\system32\DRIVERS\ACPI.sys

0x833E1000 \SystemRoot\system32\DRIVERS\WMILIB.SYS

0x833EA000 \SystemRoot\system32\DRIVERS\msisadrv.sys

0x88021000 \SystemRoot\system32\DRIVERS\pci.sys

0x8804B000 \SystemRoot\system32\DRIVERS\vdrvroot.sys

0x88056000 \SystemRoot\System32\drivers\partmgr.sys

0x88067000 \SystemRoot\system32\DRIVERS\compbatt.sys

0x8806F000 \SystemRoot\system32\DRIVERS\BATTC.SYS

0x8807A000 \SystemRoot\system32\DRIVERS\volmgr.sys

0x8808A000 \SystemRoot\System32\drivers\volmgrx.sys

0x880D5000 \SystemRoot\System32\drivers\mountmgr.sys

0x880EB000 \SystemRoot\system32\DRIVERS\atapi.sys

0x880F4000 \SystemRoot\system32\DRIVERS\ataport.SYS

0x88117000 \SystemRoot\system32\DRIVERS\msahci.sys

0x88121000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS

0x8812F000 \SystemRoot\system32\DRIVERS\amdxata.sys

0x88138000 \SystemRoot\system32\drivers\fltmgr.sys

0x8816C000 \SystemRoot\system32\drivers\fileinfo.sys

0x88202000 \SystemRoot\System32\Drivers\Ntfs.sys

0x88331000 \SystemRoot\System32\Drivers\msrpc.sys

0x8835C000 \SystemRoot\System32\Drivers\ksecdd.sys

0x8836F000 \SystemRoot\System32\Drivers\cng.sys

0x883CC000 \SystemRoot\System32\drivers\pcw.sys

0x883DA000 \SystemRoot\System32\Drivers\Fs_Rec.sys

0x88421000 \SystemRoot\system32\drivers\ndis.sys

0x884D8000 \SystemRoot\system32\drivers\NETIO.SYS

0x88516000 \SystemRoot\System32\Drivers\ksecpkg.sys

0x8861F000 \SystemRoot\System32\drivers\tcpip.sys

0x88768000 \SystemRoot\System32\drivers\fwpkclnt.sys

0x88799000 \SystemRoot\system32\DRIVERS\vmstorfl.sys

0x887A2000 \SystemRoot\system32\DRIVERS\volsnap.sys

0x887E1000 \SystemRoot\System32\DRIVERS\ApsHM86.sys

0x887EA000 \SystemRoot\System32\Drivers\spldr.sys

0x8853B000 \SystemRoot\System32\drivers\rdyboost.sys

0x88568000 \SystemRoot\System32\DRIVERS\Apsx86.sys

0x88600000 \SystemRoot\System32\Drivers\mup.sys

0x88610000 \SystemRoot\System32\drivers\hwpolicy.sys

0x88588000 \SystemRoot\System32\DRIVERS\fvevol.sys

0x885BA000 \SystemRoot\system32\DRIVERS\disk.sys

0x885CB000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS

0x887F2000 \SystemRoot\system32\DRIVERS\AtiPcie.sys

0x88618000 \SystemRoot\System32\Drivers\Null.SYS

0x885F0000 \SystemRoot\System32\Drivers\Beep.SYS

0x88400000 \SystemRoot\System32\drivers\vga.sys

0x8817D000 \SystemRoot\System32\drivers\VIDEOPRT.SYS

0x8840C000 \SystemRoot\System32\drivers\watchdog.sys

0x88419000 \SystemRoot\System32\DRIVERS\RDPCDD.sys

0x885F7000 \SystemRoot\system32\drivers\rdpencdd.sys

0x883E3000 \SystemRoot\system32\drivers\rdprefmp.sys

0x883EB000 \SystemRoot\System32\Drivers\Msfs.SYS

0x8819E000 \SystemRoot\System32\Drivers\Npfs.SYS

0x881AC000 \SystemRoot\system32\DRIVERS\tdx.sys

0x881C3000 \SystemRoot\system32\DRIVERS\TDI.SYS

0x8CE1E000 \SystemRoot\system32\drivers\afd.sys

0x8CE78000 \SystemRoot\System32\DRIVERS\netbt.sys

0x8CEAA000 \SystemRoot\system32\DRIVERS\wfplwf.sys

0x8CEB1000 \SystemRoot\system32\DRIVERS\pacer.sys

0x8CED0000 \SystemRoot\system32\DRIVERS\vwififlt.sys

0x8CEE1000 \SystemRoot\system32\DRIVERS\netbios.sys

0x8CEEF000 \SystemRoot\system32\DRIVERS\wanarp.sys

0x8CF02000 \SystemRoot\System32\drivers\Tppwr32v.sys

0x8CF09000 \SystemRoot\system32\DRIVERS\termdd.sys

0x8CF19000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS

0x8CF3B000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS

0x8CF41000 \SystemRoot\system32\DRIVERS\rdbss.sys

0x8CF82000 \SystemRoot\system32\drivers\nsiproxy.sys

0x8CF8C000 \SystemRoot\system32\DRIVERS\mssmbios.sys

0x8CF96000 \SystemRoot\system32\DRIVERS\smiif32.sys

0x8CF98000 \SystemRoot\System32\drivers\discache.sys

0x8D027000 \SystemRoot\system32\drivers\csc.sys

0x8D08B000 \SystemRoot\System32\Drivers\dfsc.sys

0x8D0A3000 \SystemRoot\system32\DRIVERS\blbdrive.sys

0x8D0B1000 \SystemRoot\system32\DRIVERS\tunnel.sys

0x8D0D2000 \SystemRoot\system32\DRIVERS\amdk8.sys

0x8D0E4000 \SystemRoot\system32\DRIVERS\wmiacpi.sys

0x8DC25000 \SystemRoot\system32\DRIVERS\atikmdag.sys

0x8D0ED000 \SystemRoot\System32\drivers\dxgkrnl.sys

0x8E165000 \SystemRoot\System32\drivers\dxgmms1.sys

0x8E19E000 \SystemRoot\system32\DRIVERS\Rt86win7.sys

0x8D41E000 \SystemRoot\system32\DRIVERS\rtl8192se.sys

0x8D531000 \SystemRoot\system32\DRIVERS\vwifibus.sys

0x8D53B000 \SystemRoot\system32\DRIVERS\usbohci.sys

0x8D545000 \SystemRoot\system32\DRIVERS\USBPORT.SYS

0x8D590000 \SystemRoot\system32\DRIVERS\usbfilter.sys

0x8D596000 \SystemRoot\system32\DRIVERS\usbehci.sys

0x8D5A5000 \SystemRoot\system32\DRIVERS\HDAudBus.sys

0x8D5C4000 \SystemRoot\system32\DRIVERS\i8042prt.sys

0x8D5DC000 \SystemRoot\system32\DRIVERS\kbdclass.sys

0x8D1A4000 \SystemRoot\system32\DRIVERS\SynTP.sys

0x8D5E9000 \SystemRoot\system32\DRIVERS\USBD.SYS

0x8D5EB000 \SystemRoot\system32\DRIVERS\mouclass.sys

0x8D5F8000 \SystemRoot\system32\DRIVERS\ibmpmdrv.sys

0x8D400000 \SystemRoot\system32\DRIVERS\CmBatt.sys

0x8D404000 \SystemRoot\system32\DRIVERS\CompositeBus.sys

0x8D411000 \SystemRoot\system32\DRIVERS\serscan.sys

0x8E1E3000 \SystemRoot\system32\DRIVERS\AgileVpn.sys

0x8DC00000 \SystemRoot\system32\DRIVERS\rasl2tp.sys

0x8DC18000 \SystemRoot\system32\DRIVERS\ndistapi.sys

0x8D000000 \SystemRoot\system32\DRIVERS\ndiswan.sys

0x8D1DF000 \SystemRoot\system32\DRIVERS\raspppoe.sys

0x8CFA4000 \SystemRoot\system32\DRIVERS\raspptp.sys

0x8CFBB000 \SystemRoot\system32\DRIVERS\rassstp.sys

0x8E1F5000 \SystemRoot\system32\DRIVERS\wanatw4.sys

0x8CFD2000 \SystemRoot\system32\DRIVERS\rdpbus.sys

0x8D1F7000 \SystemRoot\system32\DRIVERS\psadd.sys

0x8D419000 \SystemRoot\system32\DRIVERS\swenum.sys

0x8E814000 \SystemRoot\system32\DRIVERS\ks.sys

0x8E848000 \SystemRoot\system32\DRIVERS\umbus.sys

0x8E856000 \SystemRoot\system32\DRIVERS\usbhub.sys

0x8E89A000 \SystemRoot\System32\Drivers\NDProxy.SYS

0x8E8AB000 \SystemRoot\system32\drivers\CHDRT32.sys

0x8E92A000 \SystemRoot\system32\drivers\portcls.sys

0x8E959000 \SystemRoot\system32\drivers\drmk.sys

0x8E972000 \SystemRoot\System32\Drivers\RtsUStor.sys

0x8E9A0000 \SystemRoot\system32\DRIVERS\usbccgp.sys

0x8E9B7000 \SystemRoot\system32\DRIVERS\SMIksdrv.sys

0x81E0C000 \SystemRoot\system32\DRIVERS\SMIEXP.SYS

0x8207B000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS

0x82092000 \SystemRoot\system32\DRIVERS\cdrom.sys

0x820B1000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys

0x820B7000 \SystemRoot\system32\DRIVERS\hidusb.sys

0x820C2000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS

0x820D5000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS

0x820DC000 \SystemRoot\system32\DRIVERS\kbdhid.sys

0x820E8000 \SystemRoot\System32\Drivers\fastfat.SYS

0x827A0000 \SystemRoot\System32\win32k.sys

0x82112000 \SystemRoot\System32\drivers\Dxapi.sys

0x8211C000 \SystemRoot\system32\DRIVERS\mouhid.sys

0x82127000 \SystemRoot\system32\DRIVERS\monitor.sys

0x82600000 \SystemRoot\System32\TSDDD.dll

0x82630000 \SystemRoot\System32\cdd.dll

0x8213F000 \SystemRoot\system32\drivers\luafv.sys

0x8215A000 \SystemRoot\system32\drivers\WudfPf.sys

0x82174000 \SystemRoot\system32\DRIVERS\lltdio.sys

0x82184000 \SystemRoot\system32\DRIVERS\nwifi.sys

0x821CA000 \SystemRoot\system32\DRIVERS\ndisuio.sys

0x821DA000 \SystemRoot\system32\DRIVERS\rspndr.sys

0x821ED000 \SystemRoot\system32\DRIVERS\vwifimp.sys

0x97E3F000 \SystemRoot\system32\drivers\HTTP.sys

0x97EC4000 \SystemRoot\system32\DRIVERS\bowser.sys

0x97EDD000 \SystemRoot\System32\drivers\mpsdrv.sys

0x97EEF000 \SystemRoot\system32\DRIVERS\mrxsmb.sys

0x97F12000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys

0x97F4D000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys

0x97F68000 \SystemRoot\system32\drivers\peauth.sys

0x97E00000 \SystemRoot\System32\Drivers\secdrv.SYS

0x97E0A000 \SystemRoot\System32\DRIVERS\srvnet.sys

0x97E2B000 \SystemRoot\System32\drivers\tcpipreg.sys

0x9E436000 \SystemRoot\System32\DRIVERS\srv2.sys

0x9E485000 \SystemRoot\System32\DRIVERS\srv.sys

0x9E4D6000 \SystemRoot\system32\DRIVERS\WUDFRd.sys

0x9E4F7000 \SystemRoot\system32\drivers\spsys.sys

0x772A0000 \Windows\System32\ntdll.dll

0x47BA0000 \Windows\System32\smss.exe

0x774E0000 \Windows\System32\apisetschema.dll

0x004D0000 \Windows\System32\autochk.exe

0x77140000 \Windows\System32\ole32.dll

0x77440000 \Windows\System32\oleaut32.dll

0x77060000 \Windows\System32\kernel32.dll

0x76FD0000 \Windows\System32\clbcatq.dll

0x76F20000 \Windows\System32\msvcrt.dll

0x76D80000 \Windows\System32\setupapi.dll

0x76CE0000 \Windows\System32\usp10.dll

0x76090000 \Windows\System32\shell32.dll

0x773F0000 \Windows\System32\Wldap32.dll

0x76060000 \Windows\System32\imagehlp.dll

0x773E0000 \Windows\System32\lpk.dll

0x76040000 \Windows\System32\sechost.dll

0x75FC0000 \Windows\System32\comdlg32.dll

0x75F60000 \Windows\System32\shlwapi.dll

0x75E90000 \Windows\System32\user32.dll

0x75C90000 \Windows\System32\iertutil.dll

0x75C80000 \Windows\System32\normaliz.dll

0x75BD0000 \Windows\System32\rpcrt4.dll

0x75B90000 \Windows\System32\ws2_32.dll

0x75B40000 \Windows\System32\gdi32.dll

0x75AA0000 \Windows\System32\advapi32.dll

0x75A80000 \Windows\System32\imm32.dll

0x75A20000 \Windows\System32\difxapi.dll

0x75A10000 \Windows\System32\nsi.dll

0x75910000 \Windows\System32\wininet.dll

0x75840000 \Windows\System32\msctf.dll

0x75700000 \Windows\System32\urlmon.dll

0x756F0000 \Windows\System32\psapi.dll

0x756A0000 \Windows\System32\KernelBase.dll

0x75670000 \Windows\System32\wintrust.dll

0x75550000 \Windows\System32\crypt32.dll

0x75530000 \Windows\System32\devobj.dll

0x754A0000 \Windows\System32\comctl32.dll

0x75470000 \Windows\System32\cfgmgr32.dll

0x75460000 \Windows\System32\msasn1.dll

 

Processes (total 85):

0 System Idle Process

4 System

248 C:\Windows\System32\smss.exe

368 csrss.exe

444 C:\Windows\System32\wininit.exe

456 csrss.exe

512 C:\Windows\System32\services.exe

524 C:\Windows\System32\lsass.exe

532 C:\Windows\System32\lsm.exe

556 C:\Windows\System32\winlogon.exe

676 C:\Windows\System32\svchost.exe

740 C:\Windows\System32\ibmpmsvc.exe

784 C:\Windows\System32\svchost.exe

832 C:\Windows\System32\atiesrxx.exe

964 C:\Windows\System32\svchost.exe

1000 C:\Windows\System32\svchost.exe

1040 C:\Windows\System32\svchost.exe

1096 C:\Windows\System32\audiodg.exe

1168 C:\Windows\System32\svchost.exe

1236 C:\Windows\System32\atieclxx.exe

1360 C:\Windows\System32\svchost.exe

1484 C:\Windows\System32\spoolsv.exe

1520 C:\Windows\System32\svchost.exe

1612 C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe

1636 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

1668 C:\Program Files\Bonjour\mDNSResponder.exe

1736 C:\Windows\System32\svchost.exe

1768 C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe

1796 C:\Windows\System32\svchost.exe

1820 C:\Program Files\IObit\IObit Security 360\is360srv.exe

1868 C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe

1900 C:\Program Files\Common Files\Motive\McciCMService.exe

1940 C:\Windows\System32\svchost.exe

2004 C:\Windows\System32\svchost.exe

2040 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

224 C:\Windows\System32\svchost.exe

1296 C:\Windows\System32\taskhost.exe

1984 C:\Windows\System32\dwm.exe

2192 C:\Windows\System32\TpShocks.exe

2204 C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe

2220 C:\Windows\System32\rundll32.exe

2232 C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe

2248 C:\Program Files\Lenovo\Client Security Solution\cssauth.exe

2256 C:\Program Files\Common Files\aol\1272201713\ee\aolsoftware.exe

2264 C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe

2272 C:\Program Files\HP\HP Software Update\hpwuschd2.exe

2288 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe

2312 C:\Program Files\iTunes\iTunesHelper.exe

2488 C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe

2756 C:\Windows\System32\svchost.exe

2796 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE

2820 C:\Program Files\Lenovo\Access Connections\AcSvc.exe

2972 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE

3276 WmiPrvSE.exe

3452 C:\Program Files\iPod\bin\iPodService.exe

3564 C:\Windows\System32\svchost.exe

3736 C:\Windows\System32\svchost.exe

3788 C:\Windows\System32\taskeng.exe

3912 C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe

4016 C:\Windows\System32\SearchIndexer.exe

1588 WUDFHost.exe

3620 C:\Windows\System32\SearchProtocolHost.exe

668 C:\Program Files\Lenovo\Access Connections\SvcGuiHlpr.exe

3488 C:\Windows\System32\taskeng.exe

2112 C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe

3972 C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe

1300 C:\Windows\explorer.exe

2448 C:\Windows\System32\sppsvc.exe

184 C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe

160 C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe

4380 C:\Program Files\Lenovo\System Update\SUService.exe

4432 C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe

4516 C:\Program Files\Windows Media Player\wmpnetwk.exe

4868 C:\Windows\System32\svchost.exe

5380 C:\Users\David Coombs\Desktop\MBRCheck.exe

5392 C:\Windows\System32\conhost.exe

5544 dllhost.exe

5772 WmiPrvSE.exe

5840 C:\Windows\servicing\TrustedInstaller.exe

5900 C:\Windows\System32\wbem\WMIADAP.exe

6064 C:\Windows\System32\SearchFilterHost.exe

6088 C:\Windows\System32\SearchProtocolHost.exe

3176 C:\Users\David Coombs\Desktop\MBRCheck.exe

3328 C:\Windows\System32\conhost.exe

3324 C:\Windows\System32\dllhost.exe

 

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`4b100000 (NTFS)

\\.\Q: --> \\.\PhysicalDrive0 at offset 0x00000037`c7a00000 (NTFS)

 

PhysicalDrive0 Model Number: HITACHIHTS545025B9A300, Rev: PB2ZC61H

 

Size Device Name MBR Status

--------------------------------------------

232 GB \\.\PhysicalDrive0 Windows 7 MBR code detected

SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79

 

 

Done!

Link to comment
Share on other sites

ESET Online Scan

 

Scan your computer with the ESET FREE Online Virus Scan

 

* Click the ESET Online Scanner button.

 

* For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

* Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop

* Double click on the esetsmartinstaller_enu.exe icon on your desktop.

* Place a check mark next to YES, I accept the Terms of Use.

 

* Click the Start button.

* Accept any security warnings from your browser.

* Leave the check mark next to Remove found threats and place a check next to Scan archives.

* Click the Start button.

* ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.

* When the scan completes, click List of found threats.

* Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.

* Click the Back button then click Finish.

 

In your next reply please include the ESET Online Scan Log

Link to comment
Share on other sites

Eset

 

C:\Users\David Coombs\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\3c6db6d7-53bae0fd multiple threats deleted - quarantined

C:\Users\David Coombs\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\6be38fd8-433cac33 Java/TrojanDownloader.OpenStream.NAR trojan deleted - quarantined

C:\Users\David Coombs\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\5e3e0883-1c207575 multiple threats deleted - quarantined

C:\Users\David Coombs\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\1c728dc6-191dece5 a variant of Java/TrojanDownloader.OpenStream.NAU trojan deleted - quarantined

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...