Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Application Cannot Be Executed. The File ***.exe is Infected. Please help  (Read 5349 times)

0 Members and 1 Guest are viewing this topic.

reddevils235

    Topic Starter


    Starter

    I use win7. I've read the sticky post above and some other posts with the same problem. I've already run Malwarebytes and here is the log

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4052

    Windows 6.1.7600 (Safe Mode)
    Internet Explorer 8.0.7600.16385

    8/13/2010 10:59:46 AM
    mbam-log-2010-08-13 (10-59-46).txt

    Scan type: Full scan (C:\|D:\|H:\|)
    Objects scanned: 331749
    Time elapsed: 41 minute(s), 12 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 4

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Program Files (x86)\Cheat Engine\Systemcallretriever.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Program Files (x86)\Hammerfight Rus\Uninstall.exe (Malware.Packer.Krunchy) -> Quarantined and deleted successfully.
    D:\$RECYCLE.BIN\S-1-5-21-2923943177-3455369907-4057632841-1000\$R84S35H.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
    C:\Windows\System32\h@tkeysh@@k.dll (Trojan.Agent) -> Quarantined and deleted successfully.


    Please tell me what to do next.
    Thanks for your help.
    (sorry about my poor english)

    reddevils235

      Topic Starter


      Starter

      Here are my rkill and SAS logs ( I can only run them in safe mode)


      This log file is located at C:\rkill.log.
      Please post this only if requested to by the person helping you.
      Otherwise you can close this log when you wish.
      Ran as khai on 08/13/2010 at 10:49:06.


      Processes terminated by Rkill or while it was running:


      C:\Users\khai\Downloads\rkill.com


      Rkill completed on 08/13/2010  at 10:49:08.






      SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 08/13/2010 at 04:00 PM

      Application Version : 4.41.1000

      Core Rules Database Version : 5347
      Trace Rules Database Version: 3159

      Scan type       : Complete Scan
      Total Scan Time : 00:28:29

      Memory items scanned      : 385
      Memory threats detected   : 0
      Registry items scanned    : 13370
      Registry threats detected : 0
      File items scanned        : 31672
      File threats detected     : 679

      Adware.Tracking Cookie
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@apmebf[2].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@bluestreak[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][3].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@mediaplex[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@trafficmp[2].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@eyewonder[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@pointroll[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@serving-sys[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@specificclick[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@imrworldwide[2].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@myroitracking[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@atdmt[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@fastclick[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@yieldmanager[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@casalemedia[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@adinterax[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@tribalfusion[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@interclick[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@clicksor[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@invitemedia[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@insightexpressai[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@doubleclick[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@247realmedia[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@zedo[1].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@specificmedia[2].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@mediafire[2].txt
         C:\Users\khai\AppData\Roaming\Microsoft\Windows\Cookies\khai@questionmarket[1].txt
         .doubleclick.net [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .mediaplex.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .atdmt.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .revsci.net [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .atdmt.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .collective-media.net [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .invitemedia.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .invitemedia.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .invitemedia.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .trafficmp.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .mediafire.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .realmedia.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .interclick.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .insightexpressai.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .insightexpressai.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .insightexpressai.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .insightexpressai.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .insightexpressai.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .adserver.adtechus.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .zedo.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         stat.onestat.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         stat.onestat.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .specificmedia.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .revsci.net [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .revsci.net [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .revsci.net [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .legolas-media.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .apmebf.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .specificclick.net [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .specificclick.net [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .specificclick.net [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .specificclick.net [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .specificclick.net [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .specificclick.net [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .specificclick.net [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .specificclick.net [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .247realmedia.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .247realmedia.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .interclick.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .ads.pointroll.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .pointroll.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .ads.pointroll.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .pointroll.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .ads.pointroll.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .ads.pointroll.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .ads.pointroll.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .ads.pointroll.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .ads.pointroll.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .ads.pointroll.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .mediafire.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         adserver.duetads.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .bs.serving-sys.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .serving-sys.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .serving-sys.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .serving-sys.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .serving-sys.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .serving-sys.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .serving-sys.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .serving-sys.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .serving-sys.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .mediafire.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .advertising.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .advertising.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .advertising.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .advertising.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .advertising.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         click2go.org [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .trafficmp.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .trafficmp.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         cdn1.trafficmp.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         cdn1.trafficmp.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .trafficmp.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .trafficmp.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .trafficmp.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .trafficmp.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .trafficmp.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .trafficmp.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .trafficmp.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .trafficmp.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .media6degrees.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .media6degrees.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .mediafire.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .mediaplex.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .casalemedia.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .casalemedia.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .casalemedia.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .casalemedia.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .casalemedia.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .content.yieldmanager.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         dc.tremormedia.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .revsci.net [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .realmedia.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .network.realmedia.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .imrworldwide.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .imrworldwide.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .zedo.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .content.yieldmanager.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .fastclick.net [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .fastclick.net [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .fastclick.net [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .adcentriconline.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         ad.yieldmanager.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         ad.yieldmanager.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .tribalfusion.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .zedo.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .zedo.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .zedo.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .zedo.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .a1.interclick.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .a1.interclick.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .a1.interclick.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .a1.interclick.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .a1.interclick.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .a1.interclick.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .a1.interclick.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .interclick.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .questionmarket.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .questionmarket.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         ad.yieldmanager.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         ad.yieldmanager.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         ad.yieldmanager.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .mediafire.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .mediafire.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         .mediafire.com [ C:\Users\khai\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
         bc.youporn.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         cdn.insights.gravity.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         cdn4.specificclick.net [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         cdn5.specificclick.net [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         convoad.technoratimedia.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         crackle.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         freeporn.youngleafs.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         ia.media-imdb.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         imgs.adverticum.net [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         lovelyteenmovs.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         media.easy2.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         media.mtvnservices.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         media.scanscout.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         media.socialvibe.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         media1.break.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         mediaforgews.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         naiadsystems.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         nakedfunny.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         objects.tremormedia.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         secure-us.imrworldwide.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         static.hosting.vcmedia.vn [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         udn.specificclick.net [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         video.redorbit.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         widget1.adnet.vn [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         www.naiadsystems.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         www.porn3.eu [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         www.pornhub.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         wwwstatic.megaporn.com [ C:\Users\khai\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KLMHLE29 ]
         .mediafire.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .mediafire.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .mediafire.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .mediafire.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .trafficmp.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .trafficmp.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .trafficmp.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .trafficmp.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .trafficmp.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         ad.yieldmanager.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         ad.yieldmanager.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         ad.yieldmanager.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         ad.yieldmanager.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .tribalfusion.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .content.yieldmanager.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .interclick.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .a1.interclick.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .a1.interclick.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .a1.interclick.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .interclick.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .questionmarket.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .specificclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .specificclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .specificclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .specificclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         ad.yieldmanager.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .specificmedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .doubleclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         cdn4.specificclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         cdn4.specificclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         cdn4.specificclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         cdn4.specificclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .specificclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .specificclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         cdn4.specificclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         cdn4.specificclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .interclick.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .bs.serving-sys.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .serving-sys.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .serving-sys.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .serving-sys.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .serving-sys.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .serving-sys.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .serving-sys.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .serving-sys.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .atdmt.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .atdmt.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         ad.yieldmanager.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .invitemedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .invitemedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .invitemedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .invitemedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .invitemedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .invitemedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .overture.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .overture.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .myroitracking.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .clicksor.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .clicksor.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .clicksor.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .clicksor.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .clicksor.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .adbrite.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .adbrite.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .adbrite.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .adbrite.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .statcounter.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .adbrite.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .*adult URL* [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .*adult URL* [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .*adult URL* [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .*adult URL* [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .zedo.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .zedo.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .zedo.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         click.kiwinets.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .eyewonder.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .apmebf.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         tracking.hostgator.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .ero-advertising.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .mediafire.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .mediaplex.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .mediaplex.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .mediaplex.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .interclick.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .247realmedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .oasn04.247realmedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .adbrite.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .fastclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .fastclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .fastclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .insightexpressai.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .insightexpressai.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .insightexpressai.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .imrworldwide.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .imrworldwide.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .casalemedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .casalemedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .casalemedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .casalemedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .casalemedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .zedo.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         counter.search.bg [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         ad.yieldmanager.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .kitaramedia.122.2o7.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .smartadserver.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .smartadserver.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .adbrite.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .advertising.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .advertising.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .advertising.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .advertising.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .advertising.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .media6degrees.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .media6degrees.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .media6degrees.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .ads.pointroll.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .pointroll.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .ads.pointroll.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .pointroll.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .ads.pointroll.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .ads.pointroll.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .ads.pointroll.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .ads.pointroll.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .ads.pointroll.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .ads.pointroll.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         eas.apm.emediate.eu [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .247realmedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .oasn04.247realmedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .tacoda.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .tacoda.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .tacoda.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .tacoda.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .collective-media.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .collective-media.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .advertising.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .at.atwola.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .at.atwola.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .invitemedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .pro-market.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         www.mediafire.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .casalemedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .*adult URL* [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .*adult URL* [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .*adult URL* [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .*adult URL* [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .*adult URL* [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .*adult URL* [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         1xxx.cqcounter.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         www.links-and-traffic.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         www.links-and-traffic.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         www.links-and-traffic.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         www.links-and-traffic.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         www.links-and-traffic.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         www.*adult URL* [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         www.*adult URL* [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         www.*adult URL* [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         www.*adult URL* [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         www.*adult URL* [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         www.*adult URL* [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .vip2.clickzs.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .vip2.clickzs.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .adserver.adtechus.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .legolas-media.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .legolas-media.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .legolas-media.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .widget2.adnet.vn [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .widget2.adnet.vn [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         googleads.g.doubleclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         s06.flagcounter.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .a1.interclick.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .a1.interclick.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .a1.interclick.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .oasn04.247realmedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .adbrite.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .ru4.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .ru4.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .ru4.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .mediafire.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .www.burstnet.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .burstnet.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         www.mediafire.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .burstnet.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         cdn4.specificclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .trafficmp.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .trafficmp.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .trafficmp.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         rotator.adjuggler.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         rotator.adjuggler.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .crackle.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .crackle.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .crackle.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .crackle.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .crackle.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .crackle.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .realmedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .realmedia.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         www.googleadservices.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .chitika.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .kontera.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         citi.bridgetrack.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         citi.bridgetrack.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         citi.bridgetrack.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         citi.bridgetrack.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .kontera.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .kontera.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .kontera.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .fastclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         ad.yieldmanager.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         ad.yieldmanager.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .adbrite.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         cdn4.specificclick.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         eas.apm.emediate.eu [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .collective-media.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .collective-media.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .questionmarket.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .adtech.de [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .kaspersky.122.2o7.net [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .adinterax.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .adinterax.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .ru4.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .content.yieldmanager.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .smartadserver.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .smartadserver.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .smartadserver.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .xiti.com [ C:\Users\khai\AppData\Roaming\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .mediafire.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .mediafire.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .mediafire.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .clicksor.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .clicksor.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .clicksor.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .clicksor.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .clicksor.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .invitemedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .invitemedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .invitemedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .invitemedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .invitemedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .specificmedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .invitemedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .wildpornpass.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .wildpornpass.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .invitemedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .fuckmyjeans.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .fuckmyjeans.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .*adult URL* [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .*adult URL* [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .media6degrees.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .media6degrees.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .media6degrees.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .interclick.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .interclick.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .a1.interclick.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .a1.interclick.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .a1.interclick.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .pointroll.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .pointroll.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .a1.interclick.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .a1.interclick.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .mediafire.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .mediafire.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .imrworldwide.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .imrworldwide.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .bannertgt.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .bannertgt.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .bannertgt.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .media6degrees.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .adxpose.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         s06.flagcounter.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .widget2.adnet.vn [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .widget2.adnet.vn [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .media6degrees.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .media6degrees.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .*adult URL* [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .*adult URL* [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         clicks.smartbizsearch.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .lucidmedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .lucidmedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .mediafire.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .lucidmedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         www.googleadservices.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         www.googleadservices.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .collective-media.net [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .collective-media.net [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .collective-media.net [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         ext-us.bestofmedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .mediaforge.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         s03.flagcounter.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .media.vndezine.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .media.vndezine.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         adserver.duetads.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         adserver.duetads.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .webpower.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .webpower.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         xml.happytofind.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         click.fastpartner.net [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .advertise.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         www.finditquick.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .media6degrees.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .server.cpmstar.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .server.cpmstar.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .*adult URL* [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .legolas-media.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .eyewonder.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         ad.xtendmedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         ad.xtendmedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         ad.xtendmedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .media6degrees.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         menmedia.co.uk [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         menmedia.co.uk [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .media.photobucket.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         clicks.search312.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .interclick.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .legolas-media.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         ad1.clickhype.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .interclick.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         optimize.indieclick.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .mediaforgews.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .crackle.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .crackle.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .crackle.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .crackle.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .crackle.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .crackle.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .adserving.contextualmarketplace.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .adserving.contextualmarketplace.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .chitika.net [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         support.mediafire.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .support.mediafire.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .support.mediafire.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .lfstmedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .lfstmedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .lfstmedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         adply.plymedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .realmedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .network.realmedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .realmedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .realmedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .tribalfusion.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .atdmt.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .atdmt.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .doubleclick.net [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .apmebf.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .mediaplex.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .mediaplex.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .casalemedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .casalemedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .casalemedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .casalemedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .casalemedia.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         .questionmarket.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         ad.yieldmanager.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         ad.yieldmanager.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gbhebkg8.default\cookies.sqlite ]
         ad.yieldmanager.com [ H:\MQ\Linh tinh\PortableHammerfight1.004\Thinstall\Hammerfight\%AppData%\Mozilla\Firefox\Profiles\gb

      harry 48



        Egghead

      • lay back , relax and chill out
      • Thanked: 129
        • Yes
        • Yes
        • Yes
        • Dribbling Pensioner
      • Certifications: List
      • Experience: Familiar
      • OS: Windows 7
      go here , run highjack this and post the log , harry

      http://www.computerhope.com/forum/index.php/topic,46313.0.html

      reddevils235

        Topic Starter


        Starter

        Thanks for your help.
        But I can't run HJT in normal mode. When I turn on safe mode, it says "The Windows Installer is not accessible in safe mode..."
        What should I do now?

        harry 48



          Egghead

        • lay back , relax and chill out
        • Thanked: 129
          • Yes
          • Yes
          • Yes
          • Dribbling Pensioner
        • Certifications: List
        • Experience: Familiar
        • OS: Windows 7
        rename it to snipper.exe and try

        reddevils235

          Topic Starter


          Starter

          Ok. Here is my HJT log:

          Logfile of Trend Micro HijackThis v2.0.4
          Scan saved at 5:38:31 PM, on 8/15/2010
          Platform: Windows 7  (WinNT 6.00.3504)
          MSIE: Internet Explorer v8.00 (8.00.7600.16385)
          Boot mode: Normal

          Running processes:
          C:\Users\khai\AppData\Local\Google\Update\GoogleUpdate.exe
          C:\Program Files\Internet Download Manager\IDMan.exe
          C:\Program Files (x86)\UniKey\UniKeyNT.exe
          C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe
          C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
          C:\Program Files (x86)\voip\voip platform\Bin\PhoneMIdServerUI.exe
          C:\Program Files (x86)\Adobe\Reader 8.0\Reader\reader_sl.exe
          C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe
          C:\Program Files (x86)\D-Link\D-Link Wireless 108G DWA-120\AirPlusCFG.exe
          C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
          C:\Program Files\Alwil Software\Avast5\AvastUI.exe
          C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
          C:\Windows\SysWOW64\ctfmon.exe
          C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=bestbuy&pf=cndt
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zing.vn/zing/?utm_source=hp&utm_medium=boom
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=bestbuy&pf=cndt
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=bestbuy&pf=cndt
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
          O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~2\FlashGet\jccatch.dll
          O2 - BHO: FlashGetBHO - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Users\khai\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll
          O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
          O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files (x86)\FlashGet\getflash.dll
          O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
          O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
          O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
          O4 - HKLM\..\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
          O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe
          O4 - HKLM\..\Run: [D-Link D-Link Wireless 108G DWA-120] C:\Program Files (x86)\D-Link\D-Link Wireless 108G DWA-120\AirPlusCFG.exe
          O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
          O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
          O4 - HKCU\..\Run: [Google Update] "C:\Users\khai\AppData\Local\Google\Update\GoogleUpdate.exe" /c
          O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
          O4 - HKCU\..\Run: [UniKey] C:\Program Files (x86)\UniKey\UniKeyNT.exe
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files (x86)\Logitech\Logitech Vid\vid.exe" -bootmode
          O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
          O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
          O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
          O4 - Startup: DesktopVideoPlayer.LNK = C:\Program Files (x86)\vghd\vghd.exe
          O4 - Startup: IDMan.lnk = C:\Program Files\Internet Download Manager\IDMan.exe
          O4 - Global Startup: PhoneMidServerUI.lnk = ?
          O8 - Extra context menu item: &Download All with FlashGet - C:\PROGRA~2\FlashGet\jc_all.htm
          O8 - Extra context menu item: &Download with FlashGet - C:\PROGRA~2\FlashGet\jc_link.htm
          O8 - Extra context menu item: Download All By FlashGet3 - C:\Users\khai\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
          O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
          O8 - Extra context menu item: Download By FlashGet3 - C:\Users\khai\AppData\Roaming\FlashGetBHO\GetUrl.htm
          O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
          O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\BOXOFF~1\Office12\EXCEL.EXE/3000
          O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\BOXOFF~1\Office12\ONBttnIE.dll
          O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\BOXOFF~1\Office12\ONBttnIE.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\BOXOFF~1\Office12\REFIEBAR.DLL
          O15 - Trusted Zone: http://software.kuaiche.com
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
          O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
          O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agr64svc.exe
          O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
          O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
          O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
          O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
          O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
          O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
          O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
          O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files (x86)\D-Link\D-Link Wireless 108G DWA-120\JSWUtilVst\jswpsapi.exe
          O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
          O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
          O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
          O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
          O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
          O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
          O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
          O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
          O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
          O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
          O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
          O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
          O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
          O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
          O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
          O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
          O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
          O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
          O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
          O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
          O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

          --
          End of file - 11382 bytes

          SuperDave

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Open HijackThis and select Do a system scan only

          Place a check mark next to the following entries: (if there)

          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522

          Internet Explorer's security is based upon a set of zones. Each zone has different security in terms of what scripts and applications can be run from a site that is in that zone. There is a security zone called the Trusted Zone. This zone has the lowest security and allows scripts and applications from sites in this zone to run without your knowledge. It is therefore a popular setting for malware sites to use so that future infections can be easily done on your computer without your knowledge as these sites will be in the Trusted Zone. Therefore, I recommend that nothing be allowed in the trusted zone. If you agree, please do the following. Place a check mark next to this line also.

          O15 - Trusted Zone: http://software.kuaiche.com

          Important: Close all open windows except for HijackThis and then click Fix checked.

          Once completed, exit HijackThis.

          *****************************************

          Download OTL  to your Desktop
          • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
          • Under the Custom Scan box paste this in
          netsvcs
          msconfig
          safebootminimal
          safebootnetwork
          activex
          drivers32
          %SYSTEMDRIVE%\*.exe
          %systemroot%\*. /mp /s
          c:\$recycle.bin\*.* /s
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
          /md5start
          eventlog.dll
          scecli.dll
          netlogon.dll
          cngaudit.dll
          sceclt.dll
          ntelogon.dll
          logevent.dll
          iaStor.sys
          nvstor.sys
          nvstor32.sys
          atapi.sys
          IdeChnDr.sys
          viasraid.sys
          AGP440.sys
          vaxscsi.sys
          nvatabus.sys
          viamraid.sys
          nvata.sys
          nvgts.sys
          iastorv.sys
          ViPrt.sys
          eNetHook.dll
          explorer.exe
          svchost.exe
          userinit.exe
          qmgr.dll
          ws2_32.dll
          proquota.exe
          imm32.dll
          kernel32.dll
          ndis.sys
          autochk.exe
          spoolsv.exe
          xmlprov.dll
          ntmssvc.dll
          mswsock.dll
          Beep.SYS
          ntfs.sys
          termsrv.dll
          sfcfiles.dll
          st3shark.sys
          ahcix86.sys
          srsvc.dll
          nvrd32.sys
          /md5stop
          %systemroot%\system32\*.dll /lockedfiles
          %systemroot%\Tasks\*.job /lockedfiles

          • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
            • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
            • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time
          Windows 8 and Windows 10 dual boot with two SSD's