Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Unable to remove isearch.claro-search.com browser hijacker


  • Please log in to reply
13 replies to this topic

#1 Antonella

Antonella

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Local time:11:34 PM

Posted 16 August 2012 - 06:46 PM

Hello

Today I've had the misfortune of downloading a file which instead infected me with this browser hijacker isearch.claro-search.com that automatically makes my homepage look like this:

Posted Image

I've been trying all day to remove it but nothing works. First I went in add/remove programs, uninstalled isearch.claro-search.com and other of its components easily. I re-opened firefox and there it was again. I ran a (quick) Norton scan but it caught nothing. I searched on google for tutorials on how to remove it but so many suggest to play around with regedit and although I have some basic computer knowledge, I don't feel confident enough to toy with anything from regedit. So instead I downloaded and ran Kaspersky tdsskiller but it found nothing useful. I then downloaded Spyware Doctor and ran a quick scan on safe mode with networking and it easily found isearch.claro-search.com along with other infections (which I suspect are all linked to this hijacker because I didn't have any computer problems before today). So I purchased Spyware Doctor in order to fully fix the infections and it successfully quarantined them. I thought I was done but to my disappointment, I re-open firefox and there it is again. I don't know what to do anymore. Quite frankly I'm desperate and out of ideas to fix this.

I sincerely hope something can be done to remove this nasty hijacker. A big thank you in advance to anyone willing to help.

p.s. I use Windows Vista.

BC AdBot (Login to Remove)

 


#2 InadequateInfirmity

InadequateInfirmity

  • Members
  • 2,595 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:34 PM

Posted 16 August 2012 - 07:24 PM

Download Adware Cleaner run it as admin Click the delete button allow it to run and post the log it creates.
http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner
What happens when you press Alt + F4 at the same time?

#3 Antonella

Antonella
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Local time:11:34 PM

Posted 16 August 2012 - 08:05 PM

Thank you for answering so quickly.

Just a warning, my Vista is in French so Adware Cleaner automatically ran/installed in French. I hope that's not a problem? Here is the log:


# AdwCleaner v1.801 - Rapport créé le 16/08/2012 à 20:57:12
# Mis à jour le 14/08/2012 par Xplode
# Système d'exploitation : Windows ™ Vista Home Premium Service Pack 2 (64 bits)
# Nom d'utilisateur : Anto - PC-DE-ANTO
# Mode de démarrage : Normal
# Exécuté depuis : C:\Users\Anto\Downloads\adwcleaner.exe
# Option [Suppression]


***** [Services] *****


***** [Fichiers / Dossiers] *****

Supprimé au redémarrage : C:\Users\Anto\AppData\LocalLow\boost_interprocess
Supprimé au redémarrage : C:\Users\Anto\AppData\Roaming\Babylon
Supprimé au redémarrage : C:\Users\Anto\AppData\Roaming\Complitly
Supprimé au redémarrage : C:\Users\Anto\AppData\Roaming\Desktopicon
Supprimé au redémarrage : C:\Users\Anto\AppData\Roaming\OpenCandy
Supprimé au redémarrage : C:\Users\Anto\AppData\Roaming\Mozilla\Firefox\Profiles\tp5vt1b1.default\extensions\{33E0DAA6-3AF3-D8B5-6752-10E949C61516}
Supprimé au redémarrage : C:\ProgramData\Babylon
Supprimé au redémarrage : C:\ProgramData\Tarma Installer
Supprimé au redémarrage : C:\Program Files (x86)\Complitly
Supprimé au redémarrage : C:\Program Files (x86)\Mozilla Firefox\Extensions\[email protected]
Fichier Supprimé : C:\Users\Anto\AppData\Roaming\Microsoft\Windows\Start Menu\eBay.lnk
Fichier Supprimé : C:\Users\Anto\AppData\Roaming\Mozilla\Firefox\Profiles\tp5vt1b1.default\searchplugins\Askcom.xml
Fichier Supprimé : C:\Users\Anto\AppData\Roaming\Mozilla\Firefox\Profiles\tp5vt1b1.default\searchplugins\Conduit.xml
Fichier Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
Fichier Supprimé : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
Fichier Supprimé : C:\user.js

***** [Registre] *****

[*] Clé Supprimée : HKLM\SOFTWARE\Classes\Toolbar.CT1060933
Clé Supprimée : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Clé Supprimée : HKCU\Software\Ask&Record
Clé Supprimée : HKCU\Software\Complitly
Clé Supprimée : HKCU\Software\Softonic
Clé Supprimée : HKCU\Software\Zugo
Clé Supprimée : HKLM\SOFTWARE\Babylon
Clé Supprimée : HKLM\SOFTWARE\BabylonToolbar
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Clé Supprimée : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Clé Supprimée : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO
Clé Supprimée : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO.1
Clé Supprimée : HKLM\SOFTWARE\Classes\YontooIEClient.Api
Clé Supprimée : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
Clé Supprimée : HKLM\SOFTWARE\Classes\YontooIEClient.Layers
Clé Supprimée : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1
Clé Supprimée : HKLM\SOFTWARE\Google\Chrome\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel
Clé Supprimée : HKLM\SOFTWARE\Google\Chrome\Extensions\dlfienamagdnkekbbbocojppncdambda
Clé Supprimée : HKLM\SOFTWARE\Google\Chrome\Extensions\lpmkgpnbiojfaoklbkpfneikocaobfai
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4FFBB818-B13C-11E0-931D-B2664824019B}_is1
[x64] Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
[x64] Clé Supprimée : HKLM\SOFTWARE\Tarma Installer

***** [Registre - GUID] *****

Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{442F13BC-2031-42D5-9520-437F65271153}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{01BCB858-2F62-4F06-A8F4-48F927C15333}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C99FDC39-A1AE-4B24-8D71-E5274F8D7C54}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Valeur Supprimée : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
[x64] Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
[x64] Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
[x64] Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
[x64] Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}

***** [Navigateurs] *****

-\\ Internet Explorer v8.0.6001.19298

[OK] Le registre ne contient aucune entrée illégitime.

-\\ Mozilla Firefox v14.0.1 (en-US)

Nom du profil : default
Fichier : C:\Users\Anto\AppData\Roaming\Mozilla\Firefox\Profiles\tp5vt1b1.default\prefs.js

C:\Users\Anto\AppData\Roaming\Mozilla\Firefox\Profiles\tp5vt1b1.default\user.js ... Supprimé !

Supprimée : user_pref("browser.search.defaultthis.engineName", "Freecorder Customized Web Search");
Supprimée : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&Sea[...]
Supprimée : user_pref("extensions.BabylonToolbar_i.newTab", true);
Supprimée : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://isearch.claro-search.com/?affID=115131&tt[...]
Supprimée : user_pref("extensions.addonfox.addit.remoteInstallItems", "{ \"software\": {\"1\": {\"id\": \"1\",\"[...]

*************************

AdwCleaner[S3].txt - [7625 octets] - [16/08/2012 20:57:12]

########## EOF - C:\AdwCleaner[S3].txt - [7753 octets] ##########

#4 InadequateInfirmity

InadequateInfirmity

  • Members
  • 2,595 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:34 PM

Posted 16 August 2012 - 08:10 PM

Looks like Adware cleaner removed it.

Can you please post the following logs in your next reply.

Please download MINITOOLBOX and save it to your desktop Right click Run as Admin. run

Checkmark following boxes:


Report IE Proxy Settings
Report FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries
List last 10 Event Viewer log
List Installed Programs
List Users, Partitions and Memory size
List Devices (problems only)



Click Go and copy and paste the result.

Please download FarbarServiceScanner and run it on the computer with the issue.Make sure and run this program as admin.


Make sure the following options are checked:
Internet Services
Windows Firewall
System Restore
Security Center/Action Center
Windows Update

Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.
Please copy and paste the log to your reply.
What happens when you press Alt + F4 at the same time?

#5 Antonella

Antonella
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Local time:11:34 PM

Posted 16 August 2012 - 08:17 PM

Here is the MINITOOLBOX result:

MiniToolBox by Farbar Version: 23-07-2012
Ran by Anto (administrator) on 16-08-2012 at 21:13:11
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2 (X64)
Boot Mode: Normal
***************************************************************************

========================= IE Proxy Settings: ==============================

Proxy is enabled.
No Proxy Server is set.

========================= FF Proxy Settings: ==============================

========================= Hosts content: =================================

::1 localhost

127.0.0.1 localhost

========================= IP Configuration: ================================

Realtek RTL8168C(P)/8111C(P) Family PCI-E GBE NIC = Connexion au réseau local (Connected)


# ----------------------------------
# Configuration du protocole IPv4
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled


popd
# Fin de la configuration du protocole IPv4



Configuration IP de Windows

Nom de l'h“te . . . . . . . . . . : PC-de-Anto
Suffixe DNS principal . . . . . . :
Type de noeud. . . . . . . . . . : Hybride
Routage IP activ‚ . . . . . . . . : Non
Proxy WINS activ‚ . . . . . . . . : Non

Carte Ethernet Connexion au r‚seau local :

Suffixe DNS propre … la connexion. . . :
Description. . . . . . . . . . . . . . : Realtek RTL8168C(P)/8111C(P) Family PCI-E GBE NIC
Adresse physique . . . . . . . . . . . : 00-26-18-71-04-60
DHCP activ‚. . . . . . . . . . . . . . : Oui
Configuration automatique activ‚e. . . : Oui
Adresse IPv6 de liaison locale. . : fe80::d4b5:1c29:80ed:6fe5%10(pr‚f‚r‚)
Adresse IPv4. . . . . . . . . . . : 192.168.0.107(pr‚f‚r‚)
Masque de sous-r‚seau. . . .ÿ. . . . . : 255.255.255.0
Bail obtenu. . . . . . . . .ÿ. . . . . : 16 ao–t 2012 20:59:48
Bail expirant. . . . . . . . .ÿ. . . . : 23 ao–t 2012 20:59:48
Passerelle par d‚faut. . . .ÿ. . . . . : 192.168.0.1
Serveur DHCP . . . . . . . . . . . . . : 192.168.0.1
IAID DHCPv6 . . . . . . . . . . . : 251667596
DUID de client DHCPv6. . . . . . . . : 00-01-00-01-12-03-90-2C-00-26-18-71-04-60
Serveurs DNS. . . . . . . . . . . . . : 192.168.0.1
NetBIOS sur Tcpip. . . . . . . . . . . : Activ‚

Carte Tunnel Connexion au r‚seau local* 6 :

Statut du m‚dia. . . . . . . . . . . . : M‚dia d‚connect‚
Suffixe DNS propre … la connexion. . . :
Description. . . . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Adresse physique . . . . . . . . . . . : 02-00-54-55-4E-01
DHCP activ‚. . . . . . . . . . . . . . : Non
Configuration automatique activ‚e. . . : Oui

Carte Tunnel Connexion au r‚seau local* 7 :

Statut du m‚dia. . . . . . . . . . . . : M‚dia d‚connect‚
Suffixe DNS propre … la connexion. . . :
Description. . . . . . . . . . . . . . : isatap.{73562B51-0415-4C2A-89F2-0856B6F5101D}
Adresse physique . . . . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP activ‚. . . . . . . . . . . . . . : Non
Configuration automatique activ‚e. . . : Oui
Serveur : UnKnown
Address: 192.168.0.1

Nom : google.com
Addresses: 2607:f8b0:4004:802::1002
74.125.228.99
74.125.228.102
74.125.228.96
74.125.228.104
74.125.228.103
74.125.228.101
74.125.228.105
74.125.228.100
74.125.228.110
74.125.228.98
74.125.228.97

Envoi d'une requˆte 'ping' sur google.com [74.125.228.6] avec 32 octets de donn‚esÿ:R‚ponse de 74.125.228.6ÿ: octets=32 temps=41 ms TTL=55R‚ponse de 74.125.228.6ÿ: octets=32 temps=40 ms TTL=55Statistiques Ping pour 74.125.228.6: Paquetsÿ: envoy‚s = 2, re‡us = 2, perdus = 0 (perte 0%),Dur‚e approximative des boucles en millisecondes : Minimum = 40ms, Maximum = 41ms, Moyenne = 40msServeur : UnKnown
Address: 192.168.0.1

Nom : yahoo.com
Addresses: 98.139.183.24
72.30.38.140
98.138.253.109

Envoi d'une requˆte 'ping' sur yahoo.com [98.139.183.24] avec 32 octets de donn‚esÿ:R‚ponse de 98.139.183.24ÿ: octets=32 temps=155 ms TTL=53R‚ponse de 98.139.183.24ÿ: octets=32 temps=53 ms TTL=53Statistiques Ping pour 98.139.183.24: Paquetsÿ: envoy‚s = 2, re‡us = 2, perdus = 0 (perte 0%),Dur‚e approximative des boucles en millisecondes : Minimum = 53ms, Maximum = 155ms, Moyenne = 104msServeur : UnKnown
Address: 192.168.0.1

Nom : bleepingcomputer.com
Address: 208.43.87.2

Envoi d'une requˆte 'ping' sur bleepingcomputer.com [208.43.87.2] avec 32 octets de donn‚esÿ:R‚ponse de 208.43.87.2ÿ: Impossible de joindre l'h“te de destination.R‚ponse de 208.43.87.2ÿ: Impossible de joindre l'h“te de destination.Statistiques Ping pour 208.43.87.2: Paquetsÿ: envoy‚s = 2, re‡us = 2, perdus = 0 (perte 0%),Envoi d'une requˆte 'Ping' 127.0.0.1 avec 32 octets de donn‚esÿ:R‚ponse de 127.0.0.1ÿ: octets=32 temps<1ms TTL=128R‚ponse de 127.0.0.1ÿ: octets=32 temps<1ms TTL=128Statistiques Ping pour 127.0.0.1: Paquetsÿ: envoy‚s = 2, re‡us = 2, perdus = 0 (perte 0%),Dur‚e approximative des boucles en millisecondes : Minimum = 0ms, Maximum = 0ms, Moyenne = 0ms===========================================================================
Liste d'Interfaces
10 ...00 26 18 71 04 60 ...... Realtek RTL8168C(P)/8111C(P) Family PCI-E GBE NIC
1 ........................... Software Loopback Interface 1
11 ...02 00 54 55 4e 01 ...... Teredo Tunneling Pseudo-Interface
12 ...00 00 00 00 00 00 00 e0 isatap.{73562B51-0415-4C2A-89F2-0856B6F5101D}
===========================================================================

IPv4 Table de routage
===========================================================================
Itin‚raires actifsÿ:
Destination r‚seau Masque r‚seau Adr. passerelle Adr. interface M‚trique
0.0.0.0 0.0.0.0 192.168.0.1 192.168.0.107 20
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
192.168.0.0 255.255.255.0 On-link 192.168.0.107 276
192.168.0.107 255.255.255.255 On-link 192.168.0.107 276
192.168.0.255 255.255.255.255 On-link 192.168.0.107 276
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.0.107 276
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.0.107 276
===========================================================================
Itin‚raires persistantsÿ:
Aucun

IPv6 Table de routage
===========================================================================
Itin‚raires actifsÿ:
If Metric Network Destination Gateway
1 306 ::1/128 On-link
10 276 fe80::/64 On-link
10 276 fe80::d4b5:1c29:80ed:6fe5/128
On-link
1 306 ff00::/8 On-link
10 276 ff00::/8 On-link
===========================================================================
Itin‚raires persistantsÿ:
Aucun
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [48128] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [50176] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [62464] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [62464] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [19968] (Microsoft Corporation)
Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog9 01 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll [329688] (PC Tools Research Pty Ltd.)
Catalog9 02 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll [329688] (PC Tools Research Pty Ltd.)
Catalog9 03 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll [329688] (PC Tools Research Pty Ltd.)
Catalog9 04 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll [329688] (PC Tools Research Pty Ltd.)
Catalog9 05 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll [329688] (PC Tools Research Pty Ltd.)
Catalog9 06 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll [329688] (PC Tools Research Pty Ltd.)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 11 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 12 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 13 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 14 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 15 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 16 C:\Windows\SysWOW64\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 17 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll [329688] (PC Tools Research Pty Ltd.)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [61440] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [62976] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [78848] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [78848] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [27648] (Microsoft Corporation)
x64-Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)
x64-Catalog9 01 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll [448472] (PC Tools Research Pty Ltd.)
x64-Catalog9 02 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll [448472] (PC Tools Research Pty Ltd.)
x64-Catalog9 03 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll [448472] (PC Tools Research Pty Ltd.)
x64-Catalog9 04 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll [448472] (PC Tools Research Pty Ltd.)
x64-Catalog9 05 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll [448472] (PC Tools Research Pty Ltd.)
x64-Catalog9 06 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll [448472] (PC Tools Research Pty Ltd.)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 11 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 12 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 13 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 14 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 15 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 16 C:\Windows\System32\mswsock.dll [304128] (Microsoft Corporation)
x64-Catalog9 17 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll [448472] (PC Tools Research Pty Ltd.)

========================= Event log errors: ===============================

Application errors:
==================
Error: (08/16/2012 09:01:17 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/16/2012 08:59:58 PM) (Source: WDSmartWareBackgroundService) (User: )
Description: Problem starting Memeo Background Service :Échec de la configuration d'accès distant avec l'exception 'System.Reflection.TargetInvocationException: Une exception a été levée par la cible d'un appel. ---> System.Security.Principal.IdentityNotMappedException: Impossible de traduire certaines ou toutes les références d'identité.
à System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
à System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
à System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
--- Fin de la trace de la pile d'exception interne ---
à System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
à System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
à System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
à System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
à System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
à System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)'. à System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
à System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
à RemoteServerService.WDSmartWareBackgroundService.OnStart(String[] args)

Error: (08/16/2012 08:56:59 PM) (Source: Application Error) (User: )
Description: Application défaillante pctsSvc.exe, version 9.0.0.2308, horodatage 0x4fe3e7e2, module défaillant unknown, version 0.0.0.0, horodatage 0x00000000, code d’exception 0xc0000005, décalage d’erreur 0x084f5a53,
ID du processus 0xa3c, heure de début de l’application 0xpctsSvc.exe0.

Error: (08/16/2012 07:43:35 PM) (Source: Application Error) (User: )
Description: Application défaillante LVPrcSrv.exe, version 11.70.1196.0, horodatage 0x47a91581, module défaillant USER32.dll, version 6.0.6002.18541, horodatage 0x4ec3e855, code d’exception 0xc0000142, décalage d’erreur 0x00000000000b6fc8,
ID du processus 0x1490, heure de début de l’application 0xLVPrcSrv.exe0.

Error: (08/16/2012 07:12:57 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/16/2012 07:12:28 PM) (Source: WDSmartWareBackgroundService) (User: )
Description: Problem starting Memeo Background Service :Échec de la configuration d'accès distant avec l'exception 'System.Reflection.TargetInvocationException: Une exception a été levée par la cible d'un appel. ---> System.Security.Principal.IdentityNotMappedException: Impossible de traduire certaines ou toutes les références d'identité.
à System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
à System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
à System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
--- Fin de la trace de la pile d'exception interne ---
à System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
à System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
à System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
à System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
à System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
à System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)'. à System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
à System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
à RemoteServerService.WDSmartWareBackgroundService.OnStart(String[] args)

Error: (08/16/2012 07:07:18 PM) (Source: System Restore) (User: )
Description: Échec de la création d’un point de restauration sur le volume (Processus = C:\Program Files (x86)\PC Tools\PC Tools Security\pctsSvc.exe Files (x86)\PC Tools\PC Tools Security\pctsSvc.exe" ; Description = PC Tools Spyware Doctor: Cleaning Threats ; Hr = 0x8007043c).

Error: (08/16/2012 06:40:04 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/16/2012 06:39:57 PM) (Source: EventSystem) (User: )
Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c

Error: (08/16/2012 06:26:09 PM) (Source: Application Error) (User: )
Description: Application défaillante pctsGui.exe, version 9.0.0.2308, horodatage 0x4fe3e7e8, module défaillant rtl100.bpl, version 11.0.2902.10471, horodatage 0x475fc385, code d’exception 0xc0000005, décalage d’erreur 0x00002618,
ID du processus 0x200, heure de début de l’application 0xpctsGui.exe0.


System errors:
=============
Error: (08/16/2012 09:03:29 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: AUTORITE NT)
Description: 0x80070032

Error: (08/16/2012 09:01:18 PM) (Source: Service Control Manager) (User: )
Description: FileDisk
i8042prt

Error: (08/16/2012 09:01:18 PM) (Source: Service Control Manager) (User: )
Description: Agent de stratégie IPsecBFE

Error: (08/16/2012 09:01:18 PM) (Source: Service Control Manager) (User: )
Description: Modules de génération de clés IKE et AuthIPBFE

Error: (08/16/2012 09:01:18 PM) (Source: Service Control Manager) (User: )
Description: Explorateur d'ordinateurs%%1060

Error: (08/16/2012 08:59:33 PM) (Source: Application Popup) (User: )
Description: Le chargement de \SystemRoot\SysWow64\Drivers\FileDisk.SYS a été bloqué en raison d’une incompatibilité avec ce système. Contactez l’éditeur de votre logiciel pour obtenir une version compatible du pilote.

Error: (08/16/2012 07:23:24 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: AUTORITE NT)
Description: 0x80070032

Error: (08/16/2012 07:20:22 PM) (Source: Service Control Manager) (User: )
Description: Windows Update

Error: (08/16/2012 07:15:32 PM) (Source: Service Control Manager) (User: )
Description: Service de cache de police Windows%%1053

Error: (08/16/2012 07:15:32 PM) (Source: Service Control Manager) (User: )
Description: 30000Service de cache de police Windows


Microsoft Office Sessions:
=========================
Error: (08/16/2012 09:01:17 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/16/2012 08:59:58 PM) (Source: WDSmartWareBackgroundService)(User: )
Description: Problem starting Memeo Background Service :Échec de la configuration d'accès distant avec l'exception 'System.Reflection.TargetInvocationException: Une exception a été levée par la cible d'un appel. ---> System.Security.Principal.IdentityNotMappedException: Impossible de traduire certaines ou toutes les références d'identité.
à System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
à System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
à System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
--- Fin de la trace de la pile d'exception interne ---
à System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
à System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
à System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
à System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
à System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
à System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)'. à System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
à System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
à RemoteServerService.WDSmartWareBackgroundService.OnStart(String[] args)

Error: (08/16/2012 08:56:59 PM) (Source: Application Error)(User: )
Description: pctsSvc.exe9.0.0.23084fe3e7e2unknown0.0.0.000000000c0000005084f5a53a3c01cd7c0498b15cdb

Error: (08/16/2012 07:43:35 PM) (Source: Application Error)(User: )
Description: LVPrcSrv.exe11.70.1196.047a91581USER32.dll6.0.6002.185414ec3e855c000014200000000000b6fc8149001cd7c08f2b1fe7b

Error: (08/16/2012 07:12:57 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/16/2012 07:12:28 PM) (Source: WDSmartWareBackgroundService)(User: )
Description: Problem starting Memeo Background Service :Échec de la configuration d'accès distant avec l'exception 'System.Reflection.TargetInvocationException: Une exception a été levée par la cible d'un appel. ---> System.Security.Principal.IdentityNotMappedException: Impossible de traduire certaines ou toutes les références d'identité.
à System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
à System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
à System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
--- Fin de la trace de la pile d'exception interne ---
à System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
à System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
à System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
à System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
à System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
à System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)'. à System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
à System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
à RemoteServerService.WDSmartWareBackgroundService.OnStart(String[] args)

Error: (08/16/2012 07:07:18 PM) (Source: System Restore)(User: )
Description: C:\Program Files (x86)\PC Tools\PC Tools Security\pctsSvc.exe Files (x86)\PC Tools\PC Tools Security\pctsSvc.exe"PC Tools Spyware Doctor: Cleaning Threats0x8007043c

Error: (08/16/2012 06:40:04 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/16/2012 06:39:57 PM) (Source: EventSystem)(User: )
Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c

Error: (08/16/2012 06:26:09 PM) (Source: Application Error)(User: )
Description: pctsGui.exe9.0.0.23084fe3e7e8rtl100.bpl11.0.2902.10471475fc385c00000050000261820001cd7bfe217632a5


=========================== Installed Programs ============================

64 Bit HP CIO Components Installer (Version: 3.2.1)
Adobe Flash Player 11 Plugin 64-bit (Version: 11.1.102.55)
Apple Mobile Device Support (Version: 5.1.1.4)
ATI AVIVO64 Codecs (Version: 9.15.0.20713)
ATI Catalyst Install Manager (Version: 3.0.673.0)
Better File Rename 5.2
Bonjour (Version: 3.0.0.10)
Coffret de pilotes Logitech QuickCam
Hardware Diagnostic Tools (Version: 5.1.5144.16)
HP Customer Participation Program 12.0 (Version: 12.0)
HP Imaging Device Functions 12.0 (Version: 12.0)
HP MediaSmart SmartMenu (Version: 2.1.12)
HP Photosmart C309a All-In-One Driver Software 12.0 Rel .5 (Version: 12.0)
HP Photosmart Essential 3.5 (Version: 3.5)
HP Remote Software (Version: 1.0.5.0)
HP Smart Web Printing (Version: 4.05)
HP Solution Center 12.0 (Version: 12.0)
Intel® Graphics Media Accelerator Driver
Intel® Matrix Storage Manager
iTunes (Version: 10.6.1.7)
Logitech QuickCam (Version: 11.70.1200)
Microsoft .NET Framework 3.5 Language Pack SP1 - fra (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile FRA Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (Version: 8.0.51011)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053)
Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053)
Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053)
Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053)
Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000)
Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000)
Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000)
Module linguistique Microsoft .NET Framework 3.5 SP1- fra
Module linguistique Microsoft .NET Framework 4 Client Profile FRA (Version: 4.0.30319)
MSVCRT Redists (Version: 1.0)
Network64 (Version: 120.0.194.000)
OCR Software by I.R.I.S. 12.0 (Version: 12.0)
Shop for HP Supplies (Version: 12)
Topaz Clean 3 (64-bit) (Version: 3.0.2)
Version de démonstration de Microsoft Office Home and Student 2007
WD SmartWare (Version: 1.1.1.6)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Language Selector (Version: 15.4.3555.0308)
Wondershare Streaming Video Recorder(Build 2.0.2.2)

========================= Devices: ================================

Name: Photosmart C309a series
Description: Photosmart C309a series
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


========================= Memory info: ===================================

Percentage of memory in use: 31%
Total physical RAM: 8181.33 MB
Available physical RAM: 5599.55 MB
Total Pagefile: 16413.69 MB
Available Pagefile: 13781.13 MB
Total Virtual: 4095.88 MB
Available Virtual: 3995.18 MB

========================= Partitions: =====================================

1 Drive c: (HP) (Fixed) (Total:582.19 GB) (Free:76.42 GB) NTFS
2 Drive d: (FACTORY_IMAGE) (Fixed) (Total:13.98 GB) (Free:1.95 GB) NTFS
3 Drive e: (DVDVolume) (CDROM) (Total:4.22 GB) (Free:0 GB) UDF
4 Drive f: (THE_UNINVITED) (CDROM) (Total:5.7 GB) (Free:0 GB) UDF

========================= Users: ========================================

comptes d'utilisateurs de \\PC-DE-ANTO

Administrateur Anto Invit‚
La commande s'est termin‚e correctement.


**** End of log ****






Here is the FarbarServiceScanner log:

Farbar Service Scanner Version: 06-08-2012
Ran by Anto (administrator) on 16-08-2012 at 21:15:43
Running from "C:\Users\Anto\Downloads"
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
IE proxy is enabled.



Windows Firewall:
=============
mpsdrv Service is not running. Checking service configuration:
The start type of mpsdrv service is OK.
The ImagePath of mpsdrv service is OK.

MpsSvc Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.

bfe Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.


Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============
wscsvc Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcsvc.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0268288 ____A (Microsoft Corporation) 3ED0321127CE70ACDAABBF77E157C2A7

C:\Windows\System32\drivers\afd.sys
[2012-02-15 09:39] - [2012-01-03 10:25] - 0404992 ____A (Microsoft Corporation) C4F6CE6087760AD70960C9EB130E7943

C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2012-05-11 23:12] - [2012-03-30 08:45] - 1423744 ____A (Microsoft Corporation) 46D448E9117464E4D3BBF36D7E3FA48E

C:\Windows\System32\dnsrslvr.dll
[2011-04-14 00:42] - [2011-03-02 12:12] - 0117760 ____A (Microsoft Corporation) 06230F1B721494A6DF8D47FD395BB1B0

C:\Windows\System32\mpssvc.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0603136 ____A (Microsoft Corporation) 897E3BAF68BA406A61682AE39C83900C

C:\Windows\System32\bfe.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0458240 ____A (Microsoft Corporation) FFB96C2589FFA60473EAD78B39FBDE29

C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe
[2009-12-03 16:50] - [2009-04-11 03:11] - 1433600 ____A (Microsoft Corporation) B75232DAD33BFD95BF6F0A3E6BFF51E1

C:\Windows\System32\wscsvc.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0074752 ____A (Microsoft Corporation) 9EA3E6D0EF7A5C2B9181961052A4B01A

C:\Windows\System32\wbem\WMIsvc.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0221696 ____A (Microsoft Corporation) D2E7296ED1BD26D8DB2799770C077A02

C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 1081856 ____A (Microsoft Corporation) 6D316F4859634071CC25C4FD4589AD2C

C:\Windows\System32\es.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0361984 ____A (Microsoft Corporation) E12F22B73F153DECE721CD45EC05B4AF

C:\Windows\System32\cryptsvc.dll
[2012-06-12 23:39] - [2012-04-23 12:25] - 0174592 ____A (Microsoft Corporation) 62740B9D2A137E8CED41A9E4239A7A31

C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0719872 ____A (Microsoft Corporation) CF8B9A3A5E7DC57724A89D0C3E8CF9EF



**** End of log ****

#6 InadequateInfirmity

InadequateInfirmity

  • Members
  • 2,595 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:34 PM

Posted 16 August 2012 - 08:44 PM

Create a restore point.
http://www.howtogeek.com/howto/windows-vista/create-a-restore-point-for-windows-vistas-system-restore/

Download the vista file in the link below.
http://www.smartestcomputing.us.com/files/download/9-registry-network-keys/

Create a new folder on your desktop then unzip the folder you just downloaded above to it.

Then right click and select merge for each of the files,listed below reboot and post a fresh Farbar service scanner log please.

wscsvc
bfe
MpsSvc

Edited by InadequateInfirmity, 16 August 2012 - 08:45 PM.

What happens when you press Alt + F4 at the same time?

#7 Antonella

Antonella
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Local time:11:34 PM

Posted 16 August 2012 - 09:04 PM

I created a restore point and merged those 3 files you listed. Here is the new FarbarServiceScanner log (I checked the same options you asked for last time):



Farbar Service Scanner Version: 06-08-2012
Ran by Anto (administrator) on 16-08-2012 at 22:01:30
Running from "C:\Users\Anto\Downloads"
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
IE proxy is enabled.



Windows Firewall:
=============
MpsSvc Service is not running. Checking service configuration:
The start type of MpsSvc service is OK.
The ImagePath of MpsSvc service is OK.
The ServiceDll of MpsSvc service is OK.

bfe Service is not running. Checking service configuration:
The start type of bfe service is OK.
The ImagePath of bfe service is OK.
The ServiceDll of bfe service is OK.


Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcsvc.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0268288 ____A (Microsoft Corporation) 3ED0321127CE70ACDAABBF77E157C2A7

C:\Windows\System32\drivers\afd.sys
[2012-02-15 09:39] - [2012-01-03 10:25] - 0404992 ____A (Microsoft Corporation) C4F6CE6087760AD70960C9EB130E7943

C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2012-05-11 23:12] - [2012-03-30 08:45] - 1423744 ____A (Microsoft Corporation) 46D448E9117464E4D3BBF36D7E3FA48E

C:\Windows\System32\dnsrslvr.dll
[2011-04-14 00:42] - [2011-03-02 12:12] - 0117760 ____A (Microsoft Corporation) 06230F1B721494A6DF8D47FD395BB1B0

C:\Windows\System32\mpssvc.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0603136 ____A (Microsoft Corporation) 897E3BAF68BA406A61682AE39C83900C

C:\Windows\System32\bfe.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0458240 ____A (Microsoft Corporation) FFB96C2589FFA60473EAD78B39FBDE29

C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe
[2009-12-03 16:50] - [2009-04-11 03:11] - 1433600 ____A (Microsoft Corporation) B75232DAD33BFD95BF6F0A3E6BFF51E1

C:\Windows\System32\wscsvc.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0074752 ____A (Microsoft Corporation) 9EA3E6D0EF7A5C2B9181961052A4B01A

C:\Windows\System32\wbem\WMIsvc.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0221696 ____A (Microsoft Corporation) D2E7296ED1BD26D8DB2799770C077A02

C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 1081856 ____A (Microsoft Corporation) 6D316F4859634071CC25C4FD4589AD2C

C:\Windows\System32\es.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0361984 ____A (Microsoft Corporation) E12F22B73F153DECE721CD45EC05B4AF

C:\Windows\System32\cryptsvc.dll
[2012-06-12 23:39] - [2012-04-23 12:25] - 0174592 ____A (Microsoft Corporation) 62740B9D2A137E8CED41A9E4239A7A31

C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0719872 ____A (Microsoft Corporation) CF8B9A3A5E7DC57724A89D0C3E8CF9EF



**** End of log ****

#8 InadequateInfirmity

InadequateInfirmity

  • Members
  • 2,595 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:34 PM

Posted 16 August 2012 - 09:25 PM

Download the windows all in one repair tool and run it as admin with the following boxes checked.
http://www.tweaking.com/content/page/windows_repair_all_in_one.html


Reset registry permissions
reset file permissions
register system files
repair wmi
repair firewall
remove policies set by infections
repair winsock and dns cache
set windows services to default start



Reboot and post new FSS log please.
What happens when you press Alt + F4 at the same time?

#9 InadequateInfirmity

InadequateInfirmity

  • Members
  • 2,595 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:34 PM

Posted 16 August 2012 - 09:27 PM

Perform scans with eset online scanner and f-secure online scanner.
http://www.eset.com/us/online-scanner/
http://www.f-secure.com/en/web/home_global/protection/free-online-tools/free-online-tools

Scan with malwarebytes and super antispyware. Make sure and update the two below prior to scanning.

http://www.malwarebytes.org/mbam/program/mbam-setup.exe
http://cdn.superantispyware.com/SUPERAntiSpyware.exe


If any of the scans find anything post the results here.
What happens when you press Alt + F4 at the same time?

#10 Antonella

Antonella
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Local time:11:34 PM

Posted 16 August 2012 - 09:47 PM

I did the windows repair, reboot and here is the new FSS log:


Farbar Service Scanner Version: 06-08-2012
Ran by Anto (administrator) on 16-08-2012 at 22:43:27
Running from "C:\Users\Anto\Downloads"
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
IE proxy is enabled.



Windows Firewall:
=============
MpsSvc Service is not running. Checking service configuration:
The start type of MpsSvc service is OK.
The ImagePath of MpsSvc service is OK.
The ServiceDll of MpsSvc service is OK.

bfe Service is not running. Checking service configuration:
The start type of bfe service is OK.
The ImagePath of bfe service is OK.
The ServiceDll of bfe service is OK.


Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcsvc.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0268288 ____A (Microsoft Corporation) 3ED0321127CE70ACDAABBF77E157C2A7

C:\Windows\System32\drivers\afd.sys
[2012-02-15 09:39] - [2012-01-03 10:25] - 0404992 ____A (Microsoft Corporation) C4F6CE6087760AD70960C9EB130E7943

C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2012-05-11 23:12] - [2012-03-30 08:45] - 1423744 ____A (Microsoft Corporation) 46D448E9117464E4D3BBF36D7E3FA48E

C:\Windows\System32\dnsrslvr.dll
[2011-04-14 00:42] - [2011-03-02 12:12] - 0117760 ____A (Microsoft Corporation) 06230F1B721494A6DF8D47FD395BB1B0

C:\Windows\System32\mpssvc.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0603136 ____A (Microsoft Corporation) 897E3BAF68BA406A61682AE39C83900C

C:\Windows\System32\bfe.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0458240 ____A (Microsoft Corporation) FFB96C2589FFA60473EAD78B39FBDE29

C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe
[2009-12-03 16:50] - [2009-04-11 03:11] - 1433600 ____A (Microsoft Corporation) B75232DAD33BFD95BF6F0A3E6BFF51E1

C:\Windows\System32\wscsvc.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0074752 ____A (Microsoft Corporation) 9EA3E6D0EF7A5C2B9181961052A4B01A

C:\Windows\System32\wbem\WMIsvc.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0221696 ____A (Microsoft Corporation) D2E7296ED1BD26D8DB2799770C077A02

C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 1081856 ____A (Microsoft Corporation) 6D316F4859634071CC25C4FD4589AD2C

C:\Windows\System32\es.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0361984 ____A (Microsoft Corporation) E12F22B73F153DECE721CD45EC05B4AF

C:\Windows\System32\cryptsvc.dll
[2012-06-12 23:39] - [2012-04-23 12:25] - 0174592 ____A (Microsoft Corporation) 62740B9D2A137E8CED41A9E4239A7A31

C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll
[2009-12-03 16:50] - [2009-04-11 03:11] - 0719872 ____A (Microsoft Corporation) CF8B9A3A5E7DC57724A89D0C3E8CF9EF



**** End of log ****




I am currently on the first scan (ESET). I'll be back with the results from all the scans when they're done.

#11 Antonella

Antonella
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Local time:11:34 PM

Posted 17 August 2012 - 11:25 AM

I did a Malwarebytes scan and it detected + fixed one trojan, here is the result:


Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.08.17.01

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 8.0.6001.19298
Anto :: PC-DE-ANTO [administrator]

2012-08-16 23:02:33
mbam-log-2012-08-16 (23-02-33).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 205043
Time elapsed: 7 minute(s), 48 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Users\Anto\AppData\Local\Temp\mor.exe (Trojan.Phex.THAGen6) -> Quarantined and deleted successfully.

(end)



Here is the ESET scan result:

C:\Users\Anto\AppData\Local\{5A45C166-7912-11E1-826D-B8AC6F996F26}\chrome\content\browser.xul JS/Redirector.NIQ trojan cleaned by deleting - quarantined
C:\Users\Anto\Documents\HSS-1.57-install-anchorfree-76-conduit.exe a variant of Win32/HotSpotShield application cleaned by deleting - quarantined
C:\Windows\Temp\hss_update.exe probably a variant of Win32/HotSpotShield application cleaned by deleting - quarantined



and here is the SUPERAntiSpyware Scan Log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/17/2012 at 12:16 PM

Application Version : 5.5.1012

Core Rules Database Version : 9076
Trace Rules Database Version: 6888

Scan type : Quick Scan
Total Scan Time : 00:09:42

Operating System Information
Windows Vista Home Premium 64-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Limited User

Memory items scanned : 572
Memory threats detected : 0
Registry items scanned : 54511
Registry threats detected : 0
File items scanned : 10591
File threats detected : 268

Adware.Tracking Cookie
C:\Users\Anto\AppData\Roaming\Microsoft\Windows\Cookies\72SWX8HK.txt [ /doubleclick.net ]
C:\Users\Anto\AppData\Roaming\Microsoft\Windows\Cookies\P32MBBBE.txt [ /atdmt.com ]
C:\USERS\ANTO\AppData\Roaming\Microsoft\Windows\Cookies\Low\YMR9VGYN.txt [ Cookie:[email protected]/accounts/ ]
C:\USERS\ANTO\AppData\Roaming\Microsoft\Windows\Cookies\Low\WED13LCJ.txt [ Cookie:[email protected]/pagead/conversion/1016917504/ ]
C:\USERS\ANTO\AppData\Roaming\Microsoft\Windows\Cookies\Low\VU4Q0CH6.txt [ Cookie:[email protected]/accounts ]
C:\USERS\ANTO\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt [ Cookie:[email protected]/accounts ]
ads.networldmedia.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.networldmedia.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
C:\USERS\ANTO\AppData\Roaming\Microsoft\Windows\Cookies\Low\SXDAG7GX.txt [ Cookie:[email protected]/pagead/conversion/1022765004/ ]
.vitamine.networldmedia.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
C:\USERS\ANTO\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZVM6R41K.txt [ Cookie:[email protected]/ ]
.amazon-adsystem.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.amazon-adsystem.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
C:\USERS\ANTO\AppData\Roaming\Microsoft\Windows\Cookies\Low\425NBHV2.txt [ Cookie:[email protected]/ ]
C:\USERS\ANTO\AppData\Roaming\Microsoft\Windows\Cookies\Low\UF5MS8I8.txt [ Cookie:[email protected]/ ]
C:\USERS\ANTO\AppData\Roaming\Microsoft\Windows\Cookies\Low\KNARIPV2.txt [ Cookie:[email protected]/ ]
.invitemedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
C:\USERS\ANTO\AppData\Roaming\Microsoft\Windows\Cookies\Low\CJAMG9H4.txt [ Cookie:[email protected]/ ]
.picclick.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
C:\USERS\ANTO\AppData\Roaming\Microsoft\Windows\Cookies\Low\DCLCJ0R5.txt [ Cookie:[email protected]/accounts ]
adx.kat.ph [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.harrenmedianetwork.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
C:\USERS\ANTO\AppData\Roaming\Microsoft\Windows\Cookies\Low\TMWUUU8W.txt [ Cookie:[email protected]/ ]
C:\USERS\ANTO\AppData\Roaming\Microsoft\Windows\Cookies\Low\IX7RWC61.txt [ Cookie:[email protected]/ ]
.clickfuse.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
C:\USERS\ANTO\AppData\Roaming\Microsoft\Windows\Cookies\Low\YI5JZ9IE.txt [ Cookie:[email protected]/ ]
C:\USERS\ANTO\AppData\Roaming\Microsoft\Windows\Cookies\Low\H6MM85K4.txt [ Cookie:[email protected]/ ]
.collective-media.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.getclicky.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.static.getclicky.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
in.getclicky.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.pointroll.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
7.rotator.wigetmedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
7.rotator.wigetmedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.adnetwork.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.legolas-media.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.histats.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.histats.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
C:\USERS\ANTO\Cookies\P32MBBBE.txt [ Cookie:[email protected]/ ]
.adxpose.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
ads.saymedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
ads.saymedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.saymedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.c.gigcount.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.technoratimedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.technoratimedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.lfstmedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.lfstmedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.mediafire.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.mediafire.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.mediafire.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.teenidols4you.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.www.teenidols4you.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.teenidols4you.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.teenidols4you.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.networldmedia.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.networldmedia.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.admarketplace.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
dc.tremormedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.mediafire.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.stats.complex.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.stats.complex.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.tag.mediashakers.hiro.tv [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.tag.mediashakers.hiro.tv [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
sexy-mood-music.livejournal.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
sexy-mood-music.livejournal.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
sexy-mood-music.livejournal.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
sexy-mood-music.livejournal.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
sexy-mood-music.livejournal.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.stats.paypal.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.networldmedia.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
f.blogads.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
accounts.youtube.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.accounts.google.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.accounts.google.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.e-2dj6aekieocpkko.stats.esomniture.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
8tracks.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
8tracks.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
8tracks.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
8tracks.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.8tracks.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.8tracks.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
server.adformdsp.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.adformdsp.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.adform.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.adform.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
adserve2.adflan.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.mm.chitika.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.legolas-media.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.kanoodle.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
tradefx.advertserve.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.aim4media.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.zanox.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.horyzon-media.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.picclick.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.picclick.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.horyzon-media.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.horyzon-media.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.horyzon-media.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.horyzon-media.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.game-advertising-online.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
ads2.iweb.cortica.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
8tracks.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
8tracks.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.legolas-media.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
rotator.hadj7.adjuggler.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
rts.pgmediaserve.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
rts.pgmediaserve.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
rts.pgmediaserve.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.networldmedia.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.8tracks.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.networldmedia.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.interclick.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.interclick.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.8tracks.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
click.findsearchengineresults.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
8tracks.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.accidentalsexiness.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.accidentalsexiness.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.accidentalsexiness.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
vlc-media-player.en.softonic.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
vlc-media-player.en.softonic.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
vlc-media-player.en.softonic.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.histats.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.8tracks.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
8tracks.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
ads.networldmedia.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.vitamine.networldmedia.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
www.tunefind.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
www.tunefind.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.tunefind.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.a1.interclick.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.a1.interclick.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.a1.interclick.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.a1.interclick.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.interclick.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.interclick.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.8tracks.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.8tracks.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
8tracks.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.clickfuse.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.clickfuse.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.pointroll.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.clickfuse.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.clickfuse.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.indieclick.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
optimize.indieclick.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
optimize.indieclick.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
optimize.indieclick.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.technoratimedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.saymedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.saymedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.ad6media.fr [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.ad6media.fr [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.ad6media.fr [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
track.effiliation.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
track.effiliation.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
track.effiliation.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
track.effiliation.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
track.effiliation.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
track.effiliation.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
track.effiliation.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
track.effiliation.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
tracking.publicidees.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
tracking.publicidees.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
eas.apm.emediate.eu [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
eas.apm.emediate.eu [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
eas.apm.emediate.eu [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.lucidmedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.lucidmedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.bleepyeahmcgosling.tumblr.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.bleepyeahbells.tumblr.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.bleepyeahbells.tumblr.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
www.mediafire.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
track.prd1.netshelter.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
www.mktrack.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.networldmedia.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.legolas-media.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.legolas-media.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.mediafire.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.mediafire.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.mediafire.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.mediafire.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
www.mediafire.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
www.mediafire.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
www.mediafire.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
www.mediafire.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.www.media970.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.www.media970.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
www.belstat.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
ads.networldmedia.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
wstat.wibiya.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.steelhousemedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.px.steelhousemedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.interclick.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.bizrate.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.calmbeforetheporn.tumblr.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.calmbeforetheporn.tumblr.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.calmbeforetheporn.tumblr.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
adserver.zenoviaexchange.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
ad2.adfarm1.adition.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.adfarm1.adition.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.kontera.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.eset.122.2o7.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.flagcounter.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.legolas-media.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.flagcounter.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.clickfuse.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.vitamine.networldmedia.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
vitamine.networldmedia.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
vitamine.networldmedia.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.clickfuse.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.fastclick.net [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]
statse.webtrendslive.com [ C:\USERS\ANTO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TP5VT1B1.DEFAULT\COOKIES.SQLITE ]






For some reason F-Secure's scan does not work. The application just keeps loading after I select the language but the scan itself never launches. By the way I just thought you should know: when I open firefox for the first time, my homepage is google again but as soon as I open new tabs, the homepage is back to isearch.claro-search.com

#12 InadequateInfirmity

InadequateInfirmity

  • Members
  • 2,595 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:34 PM

Posted 17 August 2012 - 06:55 PM

There is nothing more that I can do to help you.Go ahead and post in the virus and malware removal forum they have speacialized tools to help.
What happens when you press Alt + F4 at the same time?

#13 Antonella

Antonella
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Local time:11:34 PM

Posted 17 August 2012 - 10:51 PM

Alright, thank you so much for everything. It is very appreciated.

#14 InadequateInfirmity

InadequateInfirmity

  • Members
  • 2,595 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:34 PM

Posted 18 August 2012 - 06:02 AM

:thumbup2: HAve a good day.
What happens when you press Alt + F4 at the same time?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users