| Live Chat & Podcast at 1:00PM Eastern on Sunday! |
| | |
| Thread Tools |
|
12-Apr-2009, 10:21 AM
#1 |
| So basically when i open up and then open any multiple of tabs IE decides to crash for some reason. Happened 3 times in a row, so i reverted to running firefox for the time being. SAS found a scary amount of tracking cookies, 57 the first time and 90 from the second log. Scared it might be a keylogger.. I'm posting up my previous 2 SAS logs and my HJT log, some help would be muchly appreciated. HJT log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:07:06, on 12/04/2009 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\RtHDVCpl.exe C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe C:\Program Files\COMODO\SafeSurf\cssurf.exe C:\Program Files\PowerISO\PWRISOVM.EXE C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Windows\System32\rundll32.exe C:\Windows\vVX1000.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\ESET\ESET Smart Security\egui.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Internet Download Manager\IDMan.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\Xfire\Xfire.exe C:\Program Files\Internet Download Manager\IEMonitor.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Program Files\PACKARDBELL\Packard Bell Recovery Management\NotificationCenter\Framework.NotificationCenter.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Windows\explorer.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Sean\Desktop\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.packardbell.com/rdr....m=imedia_x2416 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.packardbell.com/rdr....m=imedia_x2416 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = : R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file) O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - (no file) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file) O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [Skytel] Skytel.exe O4 - HKLM\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetupMyPC\SmpSys.exe O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe" O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Startup: SDK Tray Menu.lnk = ? O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe O4 - Global Startup: Nokia Nseries PC Suite.lnk = C:\Program Files\Nokia\NNPCS\RunLauncher.exe O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O13 - Gopher Prefix: O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/Driver...sysreqlab3.cab O16 - DPF: {4E218431-2F07-40BD-A9D3-035324C1F13F} (DyynoX Class) - http://webserver.dyyno.com/tng/dyyno...t/DyynoCAB.CAB O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/Driver...aSmartScan.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{27FA60FB-5855-47ED-90FC-73C7DFD953D2}: NameServer = 192.168.1.1,192.168.1.2 O17 - HKLM\System\CS1\Services\Tcpip\..\{27FA60FB-5855-47ED-90FC-73C7DFD953D2}: NameServer = 192.168.1.1,192.168.1.2 O17 - HKLM\System\CS2\Services\Tcpip\..\{27FA60FB-5855-47ED-90FC-73C7DFD953D2}: NameServer = 192.168.1.1,192.168.1.2 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: C:\Windows\system32\cssdll32.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\PACKARDBELL\Packard Bell Recovery Management\Service\ETService.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe -- End of file - 9179 bytes SAS log 1: SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 04/11/2009 at 12:17 PM Application Version : 4.1.1046 Core Rules Database Version : 3839 Trace Rules Database Version: 1795 Scan type : Complete Scan Total Scan Time : 00:23:47 Memory items scanned : 561 Memory threats detected : 0 Registry items scanned : 7321 Registry threats detected : 0 File items scanned : 23534 File threats detected : 57 Adware.Tracking Cookie C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@serving-sys[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@adviva[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@doubleclick[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@bs.serving-sys[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@questionmarket[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@ad.yieldmanage r[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@revsci[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@bluestreak[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@atdmt[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@doubleclick[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@specificcl ick[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@atwola[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ads.aol.co[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@adtech[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ad.yieldma nager[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@www.warez-bb[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@adviva[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@www.warez-bb[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@aoluk.122. 2o7[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@warez-bb[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@www.3dstat s[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@mediaplex[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@www.zanox-affiliate[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@advertisin g[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@dynamic.me dia.adrevolver[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ad.zanox[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@doubleclic k[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ad.yieldma nager[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@statse.web trendslive[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@fastclick[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@adbrite[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@adecn[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@adrevolver[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ads.clicks or[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@apmebf[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@at.atwola[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@atdmt[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@bs.serving-sys[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@clicktorre nt[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@doubleclic k[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@eas.apm.em ediate[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@hesperia.1 12.2o7[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@imrworldwi de[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@kontera[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@media.adre volver[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@rotator.ad juggler[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@myroitrack ing[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@partypoker[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@questionma rket[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@rotator.ad juggler[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@uk.at.atwo la[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@serving-sys[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@sixtgmbh.1 12.2o7[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@tacoda[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@warez-bb[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@bs.serving-sys[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@serving-sys[2].txt SAS log 2: SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 04/12/2009 at 02:18 PM Application Version : 4.1.1046 Core Rules Database Version : 3839 Trace Rules Database Version: 1795 Scan type : Complete Scan Total Scan Time : 00:22:03 Memory items scanned : 570 Memory threats detected : 0 Registry items scanned : 7397 Registry threats detected : 0 File items scanned : 23651 File threats detected : 53 Adware.Tracking Cookie C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@serving-sys[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@doubleclick[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@bs.serving-sys[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@atdmt[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@doubleclick[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@adserving. cpxinteractive[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@atdmt[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@specificcl ick[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@atwola[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ads.aol.co[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ad.yieldma nager[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ad.yieldma nager[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@www.warez-bb[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@adviva[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@www.warez-bb[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ehg-nokiafin.hitbox[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@warez-bb[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@warez-bb[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@adbrite[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@advertisin g[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@advertisin g[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ads.clicks or[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@mediaplex[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@media.adre volver[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@aoluk.122. 2o7[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@serw.click sor[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@adrevolver[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ads.admaxa sia[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@apmebf[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@at.atwola[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@atdmt[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@clickaider[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@collective-media[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@doubleclic k[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@dynamic.me dia.adrevolver[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ehg-nokiafin.hitbox[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@fastclick[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@mediaplex[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@hitbox[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@hitbox[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@kontera[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@media6degr ees[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@msnportal. 112.2o7[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@myroitrack ing[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@statcounte r[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@tacoda[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@tacoda[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@tribalfusi on[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@uk.at.atwo la[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@yieldmanag er[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@atdmt[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@bs.serving-sys[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@serving-sys[1].txt .tribalfusion.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .tribalfusion.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .tribalfusion.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .tribalfusion.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .tribalfusion.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .doubleclick.net [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .mediaplex.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .mediaplex.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] ad.yieldmanager.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] ad.yieldmanager.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] ad.yieldmanager.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] ad.yieldmanager.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] ad.yieldmanager.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] ad.yieldmanager.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] ad.yieldmanager.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] ad.yieldmanager.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] ad.yieldmanager.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .partypoker.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] ad3.clickhype.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .partypoker.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .adecn.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .adecn.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .warez-bb.org [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .warez-bb.org [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .warez-bb.org [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] www.warez-bb.org [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] eas.apm.emediate.eu [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] eas.apm.emediate.eu [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .apmebf.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .atdmt.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] ad.zanox.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] ad.zanox.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] ad.zanox.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .adrevolver.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .adrevolver.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] .advertising.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] media.adrevolver.com [ C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\emmn62ev.default\coo kies.txt ] Last edited by sean1604; 12-Apr-2009 at 10:22 AM.. Reason: Thread title mis-spelled |
| |
|
15-Apr-2009, 01:46 PM
#4 |
| and another bump :/ Just an update incase anyone does help, i have a Quad-core processor and some menial tasks have been taking up quite a bit of the cpu usage. Like today i was moving a small file, bout 175mb, from one folder to another, the cpu usage jumped to like 50%+ and the operation took like 2 or 3 mins to complete. This hasn't happened a lot, but still wierd in combination with the above. Would apprecaite any help ![]() |
|
27-May-2009, 02:48 PM
#6 |
| And another bump over a month and no help now... My internet speed is suffering now because of these things i think. Please help! I have another SAS log here over 100 tracking cookies this time: SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 05/27/2009 at 06:45 PM Application Version : 4.1.1046 Core Rules Database Version : 3911 Trace Rules Database Version: 1855 Scan type : Complete Scan Total Scan Time : 00:25:12 Memory items scanned : 557 Memory threats detected : 0 Registry items scanned : 7566 Registry threats detected : 0 File items scanned : 24968 File threats detected : 119 Adware.Tracking Cookie C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@serving-sys[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@media.adrevolv er[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@media.xfire[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@adviva[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@mediaplex[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@advertising[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@ads.aol.co[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@doubleclick[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@bs.serving-sys[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@tacoda[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@at.atwola[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@apmebf[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@media.adrevolv er[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@ads.pointroll[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@atwola[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@adrevolver[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@uk.at.atwola[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@specificclick[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@aoluk.122.2o7[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@ad.yieldmanage r[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@revsci[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@atdmt[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@msnportal.112. 2o7[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@www.pornda d[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@apmebf[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@insightexp ressai[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@specificcl ick[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@revenue[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@server.cpm star[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@toplist[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@tribalfusi on[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ads.aol.co[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@atwola[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@tribalfusi on[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@adtech[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@nhl.112.2o 7[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@adviva[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ad.yieldma nager[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ad.yieldma nager[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ads.doodle[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@www.burstn et[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@adviva[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@www.warez-bb[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@accounts.p kr[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@serving-sys[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ads.widget bucks[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@warez-bb[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@burstnet[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@adbrite[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@tradedoubl er[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@cross****r y[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ads.viddle r[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@web4.realt racker[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@mediaplex[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@advertisin g[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@adserv.leg itreviews[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ar.atwola[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@imrworldwi de[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@eas.apm.em ediate[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@media.adre volver[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ad.zanox[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@doubleclic k[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@sexer[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@aoluk.122. 2o7[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@statcounte r[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@realmedia[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@collective-media[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ads.us.e-planning[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@msnaccount services.112.2o7[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ads.predic tad[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@revsci[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@fastclick[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@statcounte r[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@tacoda[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@tacoda[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@247realmed ia[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@2o7[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@adrevolver[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ads.associ atedcontent[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ads.guru3d[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@adserver.a dtechus[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@adultadwor ld[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@atdmt[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@at.atwola[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@atdmt[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@clicktorre nt[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@bs.serving-sys[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@cgm.adbure au[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@data.corem etrics[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@dynamic.me dia.adrevolver[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@eb.adburea u[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@euroclick[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@ice.112.2o 7[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@kontera[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@kontera[3].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@media.phot obucket[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@microsoftg amestudio.112.2o7[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@msnportal. 112.2o7[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@myticketma rket.112.2o7[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@openxxx.vi ragemedia[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@overture[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@revsci[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@questionma rket[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@questionma rket[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@rotator.ad juggler[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@serv12.blu ffmedia[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@tradedoubl er[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@uk.at.atwo la[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@warez-bb[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@viacom.adb ureau[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@viacom.adb ureau[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@www.cross* ***ry[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@www.cross* ***ry[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@www.warez-bb[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@your****bo ok[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\sean@zedo[2].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@atdmt[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@doubleclick[1].txt C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\sean@revsci[1].txt |
| Tags |
| hjt, log, sas, spyware |

|
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |

| Thread Tools | |
| |
| You Are Using: |
Advertisements do not imply our endorsement of that product or service. All times are GMT -4. The time now is 02:18 AM. Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved. | |
