Computer Hope

Software => Computer viruses and spyware => Topic started by: Anna_Pyr on February 25, 2012, 06:17:39 PM

Title: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on February 25, 2012, 06:17:39 PM
Hi! My laptop is becoming increasingly slow as if there is a virus. Firefox keeps asking me whether I can to stop a script, google chrom says about a plugin that has crashed but in general sometimes I think it has frozen all together.

I just for that on a screen a while ago

resource:///components/nsSessionStore.js:402

Any idea as to what it is and above all what I can do for my computer to run properly?

thanks,
 
Title: Re: resource:///components/nsSessionStore.js:402
Post by: SuperDave on February 25, 2012, 07:17:11 PM
Hello and welcome to GeekPolice.Net My name is Dave. I will be helping you out with your particular problem on your computer. 

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*****************************************************************
SUPERAntiSpyware

If you already have SUPERAntiSpyware be sure to check for updates before scanning!

Download SuperAntispyware Free Edition (SAS) (http://www.superantispyware.com/download.html)
* Double-click the icon on your desktop to run the installer.
* When asked to Update the program definitions, click Yes
* If you encounter any problems while downloading the updates, manually download and unzip them from here (http://www.softpedia.com/get/Others/Signatures-Updates/SUPERAntiSpyware-Database-Definitions-Updates.shtml)
* Next click the Preferences button.

•Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
* Click the Scanning Control tab.
* Under Scanner Options make sure only the following are checked:

•Close browsers before scanning
•Scan for tracking cookies
•Terminate memory threats before quarantining
Please leave the others unchecked

•Click the Close button to leave the control center screen.

* On the main screen click Scan your computer
* On the left check the box for the drive you are scanning.
* On the right choose Perform Complete Scan
* Click Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete a summary box will appear. Click OK
* Make sure everything in the white box has a check next to it, then click Next
* It will quarantine what it found and if it asks if you want to reboot, click Yes

•To retrieve the removal information please do the following:
•After reboot, double-click the SUPERAntiSpyware icon on your desktop.
•Click Preferences. Click the Statistics/Logs tab.

•Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

•It will open in your default text editor (preferably Notepad).
•Save the notepad file to your desktop by clicking (in notepad) File > Save As...

* Save the log somewhere you can easily find it. (normally the desktop)
* Click close and close again to exit the program.
*Copy and Paste the log in your post.
*********************************************
(http://i424.photobucket.com/albums/pp322/digistar/mbamicontw5.gif) Please download Malwarebytes Anti-Malware from here. (http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe)
Double Click mbam-setup.exe to install the application.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
************************************************************************
Download DDS from HERE (http://download.bleepingcomputer.com/sUBs/dds.scr) or HERE (http://www.forospyware.com/sUBs/dds) and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.
* Save both reports to your desktop.
* The instructions here ask you to attach the Attach.txt.

(http://i424.photobucket.com/albums/pp322/digistar/DDS.jpg)

1) DDS.txt
2) Attach.txt
Instead of attaching, please copy/past both logs into your Thread

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copying and pasting it into the reply.

•Close the program window, and delete the program from your desktop.

Please note: You may have to disable any script protection running if the scan fails to run.
After downloading the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control HERE  (http://www.bleepingcomputer.com/forums/topic114351.html).Then post your DDS logs. (DDS.txt and Attach.txt )
Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on February 26, 2012, 10:38:06 AM
Thanks. This is the SUPERAntiSpyware Scan Log

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/26/2012 at 04:52 PM

Application Version : 5.0.1144

Core Rules Database Version : 8279
Trace Rules Database Version: 6091

Scan type       : Complete Scan
Total Scan Time : 09:59:07

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 576
Memory threats detected   : 0
Registry items scanned    : 66358
Registry threats detected : 4
File items scanned        : 261118
File threats detected     : 556

Browser Hijacker.Deskbar
   (x86) HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
   (x86) HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid32
   (x86) HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib
   (x86) HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib#Version

Adware.Tracking Cookie
   C:\Users\marina\AppData\Roaming\Microsoft\Windows\Cookies\YVRJ2FYS.txt [ /c.atdmt.com ]
   C:\Users\marina\AppData\Roaming\Microsoft\Windows\Cookies\V5NB1UG9.txt [ /mywebsearch.com ]
   C:\Users\marina\AppData\Roaming\Microsoft\Windows\Cookies\CT0ZAN1V.txt [ /atdmt.com ]
   C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\1I6Y6E7X.txt [ Cookie:[email protected]/ ]
   C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\WA530UF2.txt [ Cookie:[email protected]/adServe/banners ]
   C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\H48NWYV4.txt [ Cookie:[email protected]/cgi-bin ]
   C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\LWOTI6EC.txt [ Cookie:[email protected]/ ]
   C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZJYAWTEW.txt [ Cookie:[email protected]/ ]
   C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\YEP7UH7S.txt [ Cookie:[email protected]/ ]
   C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\XES36DXK.txt [ Cookie:[email protected]/ ]
   C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\JAILEL10.txt [ Cookie:[email protected]/ ]
   C:\USERS\MARINA\AppData\Roaming\Microsoft\Windows\Cookies\Low\TM2QR2BS.txt [ Cookie:[email protected]/ ]
   C:\USERS\MARINA\Cookies\YVRJ2FYS.txt [ Cookie:[email protected]/ ]
   C:\USERS\MARINA\Cookies\V5NB1UG9.txt [ Cookie:[email protected]/ ]
   C:\USERS\MARINA\Cookies\CT0ZAN1V.txt [ Cookie:[email protected]/ ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .atdmt.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .atdmt.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .imrworldwide.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .imrworldwide.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .apmebf.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .mediaplex.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adbrite.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   rotator.adjuggler.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   rotator.adjuggler.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   rotator.adjuggler.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   track.adform.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ru4.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .specificclick.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adviva.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .doubleclick.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .apmebf.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adxvalue.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .fastclick.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adinterax.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .zanox.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.zanox.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tradedoubler.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tradedoubler.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tradedoubler.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .uk.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tacoda.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tacoda.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tacoda.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tacoda.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tacoda.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tacoda.at.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ar.atwola.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .tribalfusion.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .pro-market.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adxpose.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adbrite.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .wpni.112.2o7.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   statse.webtrendslive.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .chitika.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .mm.chitika.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .histats.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .weborama.fr [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .baa.solution.weborama.fr [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .baa.solution.weborama.fr [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .baa.solution.weborama.fr [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .baa.solution.weborama.fr [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .histats.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .lucidmedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .yieldmanager.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adinterax.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   eas.apm.emediate.eu [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   eas.apm.emediate.eu [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .questionmarket.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   accounts.google.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   server.adformdsp.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adformdsp.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adform.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .bs.serving-sys.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   track.adform.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .adform.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .247realmedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ads.audience2media.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ads.audience2media.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .audience2media.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .doubleclick.net [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .247realmedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .247realmedia.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .ru4.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   .mediaplex.com [ C:\USERS\MARINA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
   ad.insightexpressai.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   cdn2.baronsmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   cloud.video.unrulymedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   cloudfront.mediamatters.org [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   content.oddcast.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   content.yieldmanager.edgesuite.net [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   ds.serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   ec.atdmt.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   ia.media-imdb.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   media.buto.tv [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   media.kyte.tv [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   media.mtvnservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   media.npr.org [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   media.scanscout.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   media.socialvibe.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   media1.break.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   media3.break.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   msnbcmedia.msn.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   s0.2mdn.net [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   secure-uk.imrworldwide.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   secure-us.imrworldwide.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   spe.atdmt.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   stat.easydate.biz [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   tracking.onefeed.co.uk [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   www.99counters.com [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   www.al-anon.alateen.org [ C:\USERS\MARINA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3BXS5EM8 ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .casalemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .getclicky.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .static.getclicky.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   in.getclicky.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   track.solocpm.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   track.solocpm.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   track.solocpm.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adviva.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   eas.apm.emediate.eu [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   eas4.emediate.eu [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .indoormedia.co.uk [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   max.bannermanager.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .tradedoubler.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .tradedoubler.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .tradedoubler.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   openx1.overadmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .accounts.google.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .accounts.google.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   accounts.google.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   accounts.google.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .mjtracking.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .mjtracking.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   islamicinsights.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .islamicinsights.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .islamicinsights.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .richmedia.yahoo.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .apmebf.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .apmebf.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .mediafire.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .mediafire.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .mediafire.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   server.adformdsp.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adformdsp.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   stats.e-go.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   *Blocked Russian URL* [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .game-advertising-online.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   track.adform.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adform.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .statcounter.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   cdmedia.rotator.hadj7.adjuggler.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   cdmedia.rotator.hadj7.adjuggler.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   vidasco.rotator.hadj7.adjuggler.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   vidasco.rotator.hadj7.adjuggler.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adjuggler.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adinterax.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adinterax.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .amazon-adsystem.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .amazon-adsystem.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .zedo.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   uk.sitestat.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   uk.sitestat.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .harrenmedianetwork.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .fastclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .fastclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ad-emea.doubleclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ad-emea.doubleclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .doubleclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .doubleclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .www.cdmediallc.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   statse.webtrendslive.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   tracking.hostgator.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ox.mediabistro.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .find-me-a-gift.co.uk [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .find-me-a-gift.co.uk [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .e-2dj6wjlyundpgeo.stats.esomniture.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .imrworldwide.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .imrworldwide.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   wstat.wibiya.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .atdmt.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .atdmt.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .yieldmanager.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .histats.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .histats.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .legolas-media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .legolas-media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .legolas-media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .tripod.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .tripod.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   leads.383media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   leads.383media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .mm.chitika.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ads.24media.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ads.24media.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .service.24media.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .service.24media.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ads.audience2media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .audience2media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ads.audience2media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .audience2media.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   httptrack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtech.de [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .clickfuse.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .clickfuse.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .clickfuse.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   findnsave.sacbee.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .c.gigcount.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .247realmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .247realmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .247realmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.googleadservices.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .collective-media.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .collective-media.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .collective-media.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .collective-media.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   doublespeed.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   doublespeed.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   help.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   help.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   my.virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .virginmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revsci.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adbrite.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adbrite.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adbrite.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adbrite.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adbrite.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   dc.tremormedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .nextag.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .nextag.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .nextag.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .nextag.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .womanmediagroup.es [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.zanox.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .zanox.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adxpose.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ads.saymedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ads.saymedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   clickztrax.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   clickztrax.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .clicksor.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .clicksor.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .smartadserver.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www4.smartadserver.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .unrulymedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .eyewonder.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .eyewonder.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .technoratimedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .lucidmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   publishers.clickbooth.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.findaproperty.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .findaproperty.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .findaproperty.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .findaproperty.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad2.adfarm1.adition.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ads.pointroll.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .specificclick.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .revenuemantra.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .xm.xtendmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   accounts.youtube.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .lfstmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .lfstmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .lfstmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .lfstmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .pro-market.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .advertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .overture.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .overture.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .perf.overture.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   network.clickbanner.gr [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .kantarmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .kantarmedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .files.bannersnack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .files.bannersnack.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adxvalue.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .interclick.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .interclick.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .a1.interclick.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .a1.interclick.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .interclick.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .interclick.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ru4.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .ru4.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .mediaplex.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .mediaplex.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   *Blocked Russian URL* [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   *Blocked Russian URL* [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adtechus.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adserver.adtechus.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.burstnet.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .www.burstnet.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .burstnet.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   www.burstnet.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .at.atwola.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .uk.at.atwola.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .uk.at.atwola.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .uk.at.atwola.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .bs.serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .hearstmagazines.112.2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .wpni.112.2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .highbeam.122.2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .112.2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .opodo.122.2o7.net [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .traveladvertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .traveladvertising.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .media6degrees.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .questionmarket.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .questionmarket.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adfarm1.adition.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adfarm1.adition.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   adfarm1.adition.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   eas.apm.emediate.eu [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   eas.apm.emediate.eu [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .tribalfusion.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .adinterax.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .serving-sys.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   ad.yieldmanager.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .mediaplex.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
   .invitemedia.com [ C:\USERS\MARINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2Y9B2IKI.DEFAULT\COOKIES.SQLITE ]
Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on February 26, 2012, 04:42:00 PM
Malwarebytes Anti-Malware (Trial) 1.60.1.1000
www.malwarebytes.org

Database version: v2012.02.26.04

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
marina :: SAMMADHITTI [administrator]

Protection: Enabled

26/02/2012 17:54:58
mbam-log-2012-02-26 (17-54-58).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 535028
Time elapsed: 5 hour(s), 8 minute(s), 7 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
C:\Program Files (x86)\27res.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Users\marina\AppData\LocalLow\OurBabyMaker_27EI\Installr\Cache\023EC878.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.

(end)
Title: Re: resource:///components/nsSessionStore.js:402
Post by: SuperDave on February 26, 2012, 07:16:45 PM
I will need to see the DDS logs; both of them.
Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on February 26, 2012, 08:55:43 PM
Thanks. Here is the first (the DDS)

.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421  BrowserJavaVersion: 1.6.0_31
Run by marina at 3:49:45 on 2012-02-27
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.44.1033.18.3999.1335 [GMT 0:00]
.
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Windows\SysWOW64\svchost.exe -k Akamai
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\SysWOW64\svchost.exe -k netsvcs
C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files (x86)\Giraffic\Veoh_Giraffic.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\marina\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Users\marina\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\SecureW2\sw2_tray.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVH.EXE
C:\Users\marina\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
C:\Program Files (x86)\real\realplayer\Update\realsched.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\NOTEPAD.EXE
Q:\140062.enu\Office14\ONENOTEM.EXE
C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\splwow64.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
Q:\140062.enu\Office14\WINWORD.EXE
C:\Windows\system32\svchost.exe -k defragsvc
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://start.facemoods.com/?a=axl
uInternet Settings,ProxyOverride = 127.0.0.1:9421;*.local
mSearchAssistant = hxxp://start.facemoods.com/?a=axl&s={searchTerms}&f=4
BHO: Shopping Assistant Plugin: {1631550f-191d-4826-b069-d9439253d926} - C:\Program Files (x86)\PriceGong\2.5.2\PriceGongIE.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Babylon toolbar helper: {2eecd738-5844-4a99-b4b6-146bf802613b} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO: Norton Identity Protection: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll
BHO: CescrtHlpr Object: {64182481-4f71-486b-a045-b233bd0da8fc} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll
BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\IPS\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - C:\Program Files (x86)\WOT\WOT.dll
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: TBLA06779 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - C:\Program Files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll
TB: ListenArabic Toolbar: {f569cf08-edf6-4fab-8c8a-eec184358372} - C:\Program Files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll
TB: @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll
TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - C:\Program Files (x86)\WOT\WOT.dll
TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarTlbr.dll
TB: facemoods Toolbar: {db4e9724-f518-4dfd-9c7c-78b52103cab9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
uRun: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
uRun: [VeohPlugin] "C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
uRun: [Akamai NetSession Interface] "C:\Users\marina\AppData\Local\Akamai\netsession_win.exe"
mRun: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
mRun: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [SecureW2 Tray] C:\Program Files (x86)\SecureW2\sw2_tray.exe
mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [NBAgent] "C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" /WinStart
mRun: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
mRun: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe" /md I
mRun: [TkBellExe] "C:\Program Files (x86)\real\realplayer\update\realsched.exe"  -osboot
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
StartupFolder: C:\Users\marina\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\BBCIPL~1.LNK -
StartupFolder: C:\Users\marina\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\marina\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\marina\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
StartupFolder: C:\Users\marina\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\FLIPTO~1.LNK - C:\Program Files (x86)\Fliptoast\fliptoast.exe
StartupFolder: C:\Users\marina\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVH.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: HideFastUserSwitching = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {F569CF08-EDF6-4FAB-8C8A-EEC184358372} - {F569CF08-EDF6-4FAB-8C8A-EEC184358372} - C:\Program Files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{6BA18F65-FA7D-4561-B466-FF1BDBAC958E} : DhcpNameServer = 193.63.73.32
TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B} : DhcpNameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B}\249627B6265636B6D27514D4 : DhcpNameServer = 193.61.1.250
TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B}\24F646C6569616E6D2C49626271627965637 : DhcpNameServer = 163.1.2.1 129.67.1.1 129.67.1.180
TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B}\36F6374716 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B}\478656169627C696E656 : DhcpNameServer = 10.81.93.254 10.81.93.254
TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B}\9435D434D214B455 : DhcpNameServer = 217.13.1.28 83.218.143.36
TCP: Interfaces\{B56D9987-1A01-4B59-AB71-BD1DFCE6B55B}\B49405F4350234146454 : DhcpNameServer = 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll
SEH: EasyBits ShellExecute Hook: {e54729e8-bb3d-4270-9d49-7389ea579090} - C:\Windows\SysWow64\EZUPBH~1.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
BHO-X64: Shopping Assistant Plugin: {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.5.2\PriceGongIE.dll
BHO-X64:     PriceGong - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64:     AcroIEHelperStub - No File
BHO-X64: Babylon toolbar helper: {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll
BHO-X64:     Babylon toolbar helper - No File
BHO-X64: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO-X64: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll
BHO-X64:     Norton Identity Protection - No File
BHO-X64: CescrtHlpr Object: {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll
BHO-X64:     facemoods Helper - No File
BHO-X64: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\IPS\IPSBHO.DLL
BHO-X64:     Norton Vulnerability Protection - No File
BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO-X64:     Search Helper - No File
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
BHO-X64:     URLRedirectionBHO - No File
BHO-X64: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll
BHO-X64: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: TBLA06779 Class: {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll
BHO-X64:     TBLA06779 - No File
TB-X64: ListenArabic Toolbar: {F569CF08-EDF6-4FAB-8C8A-EEC184358372} - C:\Program Files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll
TB-X64: @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll
TB-X64: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll
TB-X64: Babylon Toolbar: {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarTlbr.dll
TB-X64: facemoods Toolbar: {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll
mRun-x64: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun-x64: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
mRun-x64: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun-x64: [SecureW2 Tray] C:\Program Files (x86)\SecureW2\sw2_tray.exe
mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [NBAgent] "C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" /WinStart
mRun-x64: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
mRun-x64: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe" /md I
mRun-x64: [TkBellExe] "C:\Program Files (x86)\real\realplayer\update\realsched.exe"  -osboot
mRun-x64: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun-x64: [(Default)]
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
SEH-X64: EasyBits ShellExecute Hook: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWow64\EZUPBH~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\marina\AppData\Roaming\Mozilla\Firefox\Profiles\2y9b2iki.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.soas.ac.uk/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=2&q=
FF - prefs.js: network.proxy.gopher -
FF - prefs.js: network.proxy.type - 4
FF - plugin: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\npBrowserPlugin.dll
FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Users\marina\AppData\Roaming\Move Networks\plugins\npqmp071700000016.dll
FF - plugin: C:\Users\marina\AppData\Roaming\Mozilla\Firefox\Profiles\2y9b2iki.default\extensions\[email protected]\plugins\NPLoaderFF.dll
FF - plugin: C:\Users\marina\AppData\Roaming\Mozilla\plugins\np-mswmp.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true
.
============= SERVICES / DRIVERS ===============
.
R0 NBVol;Nero Backup Volume Filter Driver;C:\Windows\system32\DRIVERS\NBVol.sys --> C:\Windows\system32\DRIVERS\NBVol.sys [?]
R0 NBVolUp;Nero Backup Volume Upper Filter Driver;C:\Windows\system32\DRIVERS\NBVolUp.sys --> C:\Windows\system32\DRIVERS\NBVolUp.sys [?]
R0 SymDS;Symantec Data Store;C:\Windows\system32\drivers\NISx64\1305000.091\SYMDS64.SYS --> C:\Windows\system32\drivers\NISx64\1305000.091\SYMDS64.SYS [?]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\system32\drivers\NISx64\1305000.091\SYMEFA64.SYS --> C:\Windows\system32\drivers\NISx64\1305000.091\SYMEFA64.SYS [?]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\BASHDefs\20120215.001\BHDrvx64.sys [2012-2-16 1157240]
R1 ccSet_NIS;Norton Internet Security Settings Manager;C:\Windows\system32\drivers\NISx64\1305000.091\ccSetx64.sys --> C:\Windows\system32\drivers\NISx64\1305000.091\ccSetx64.sys [?]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\IPSDefs\20120224.002\IDSviA64.sys [2012-2-24 488568]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 SymIRON;Symantec Iron Driver;C:\Windows\system32\drivers\NISx64\1305000.091\Ironx64.SYS --> C:\Windows\system32\drivers\NISx64\1305000.091\Ironx64.SYS [?]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\system32\Drivers\NISx64\1305000.091\SYMNETS.SYS --> C:\Windows\system32\Drivers\NISx64\1305000.091\SYMNETS.SYS [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2010-6-30 89600]
R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-13 20992]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624]
R2 ezSharedSvc;Easybits Shared Services for Windows;C:\Windows\system32\svchost.exe -k netsvcs [2009-7-13 20992]
R2 Giraffic;Veoh Giraffic Video Accelerator;C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe --service --> C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe --service [?]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-3-28 94264]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-5-4 652360]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-9-23 641832]
R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\ccsvchst.exe [2012-1-31 138248]
R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2011-10-12 4700824]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776]
R3 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-11-7 227896]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-2-7 138360]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;C:\Windows\system32\drivers\IntcHdmi.sys --> C:\Windows\system32\drivers\IntcHdmi.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys --> C:\Windows\system32\DRIVERS\Sftfslh.sys [?]
R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys --> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?]
R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys --> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?]
R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys --> C:\Windows\system32\DRIVERS\Sftvollh.sys [?]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-31 136176]
S2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-9-9 86072]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-31 136176]
S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys --> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS --> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS --> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS --> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
.
=============== Created Last 30 ================
.
2012-02-26 17:00:58   --------   d-----w-   C:\Users\marina\AppData\Local\{D99E6408-6589-41E0-BA0D-B098D5082C64}
2012-02-26 17:00:30   --------   d-----w-   C:\Users\marina\AppData\Local\{017CAE32-ABCB-4464-B7BD-71CF6398EBC9}
2012-02-26 06:42:25   --------   d-----w-   C:\Users\marina\AppData\Roaming\SUPERAntiSpyware.com
2012-02-26 06:41:56   --------   d-----w-   C:\Program Files\SUPERAntiSpyware
2012-02-26 06:41:55   --------   d-----w-   C:\ProgramData\SUPERAntiSpyware.com
2012-02-26 00:32:43   --------   d-----w-   C:\Users\marina\AppData\Local\{7B3394B8-F42F-43EC-B37C-0808475E0F16}
2012-02-26 00:32:16   --------   d-----w-   C:\Users\marina\AppData\Local\{9A0DD797-9B50-4819-A68C-C6B440A483E8}
2012-02-23 08:39:58   --------   d-----w-   C:\Users\marina\AppData\Local\{B43DA613-BCA4-40B9-AD3B-188ABD753A68}
2012-02-23 08:39:42   --------   d-----w-   C:\Users\marina\AppData\Local\{D4045162-63B9-4EE8-B67B-8A5461CFD840}
2012-02-22 12:39:28   --------   d-----w-   C:\Users\marina\AppData\Local\{97F142C7-5B8D-4A3E-A2A5-F3E075451A80}
2012-02-22 12:39:12   --------   d-----w-   C:\Users\marina\AppData\Local\{BA3EEA9B-68BC-4BF4-9CF2-5A6ACEE01010}
2012-02-21 22:08:25   --------   d-----w-   C:\Users\marina\AppData\Local\{1AB97308-BA12-4912-B470-90ACD4BF5D01}
2012-02-21 22:08:24   --------   d-----w-   C:\Users\marina\AppData\Local\{C5C365A5-EFDF-4565-B8BC-CC390EF098B3}
2012-02-21 10:07:54   --------   d-----w-   C:\Users\marina\AppData\Local\{12C36157-1412-492B-B45A-CE97FC6F213D}
2012-02-20 22:07:14   --------   d-----w-   C:\Users\marina\AppData\Local\{4E76EBDC-2BA3-485B-ADA7-9850A2986377}
2012-02-20 10:06:37   --------   d-----w-   C:\Users\marina\AppData\Local\{D2663F44-A3B5-49E7-A18C-4584E6E55E7C}
2012-02-20 10:06:26   --------   d-----w-   C:\Users\marina\AppData\Local\{8E61D92A-2012-4E61-92B0-36ED0DD0551B}
2012-02-20 10:06:14   --------   d-----w-   C:\Users\marina\AppData\Local\{C41EBCCA-1024-4F31-A7DE-4182EA5AEE21}
2012-02-19 22:05:36   --------   d-----w-   C:\Users\marina\AppData\Local\{D596DBB8-6166-4F26-A3CC-97BA84205D87}
2012-02-19 10:04:58   --------   d-----w-   C:\Users\marina\AppData\Local\{CE09F457-4120-4A65-A4CA-1330AD011899}
2012-02-19 10:04:35   --------   d-----w-   C:\Users\marina\AppData\Local\{587E0FB2-D6A6-4338-A830-DA39D588B73A}
2012-02-18 22:04:06   --------   d-----w-   C:\Users\marina\AppData\Local\{BD466FBC-807A-4DD3-9FEE-011813B72995}
2012-02-18 22:03:43   --------   d-----w-   C:\Users\marina\AppData\Local\{2618F9A5-29EA-4A4D-84C0-E1567B27660E}
2012-02-18 10:02:48   --------   d-----w-   C:\Users\marina\AppData\Local\{126B6BC5-CA38-4B1B-93A4-963E230286A2}
2012-02-18 10:02:33   --------   d-----w-   C:\Users\marina\AppData\Local\{AC00071A-AF7F-4B73-9953-97B1F8E36CDF}
2012-02-17 20:43:15   --------   d-----w-   C:\Users\marina\AppData\Local\{C3ECA418-0C05-4FF2-8E0D-B129A50FC09B}
2012-02-17 08:42:38   --------   d-----w-   C:\Users\marina\AppData\Local\{C3ADA18E-767E-43C9-A061-A2358AEE4C9E}
2012-02-16 20:36:22   --------   d-----w-   C:\Users\marina\AppData\Local\{924BA057-6F9B-4A3A-A8B1-4D8C90EE447B}
2012-02-16 20:35:59   --------   d-----w-   C:\Users\marina\AppData\Local\{4F9BB7C1-12ED-44B3-B6F0-DE4000F0CB80}
2012-02-16 08:35:11   --------   d-----w-   C:\Users\marina\AppData\Local\{77C03757-398F-4C92-944D-7A8BE2F52026}
2012-02-16 08:34:57   --------   d-----w-   C:\Users\marina\AppData\Local\{052B150C-50F3-4941-B5FE-72B1518C4B10}
2012-02-15 12:20:37   --------   d-----w-   C:\Users\marina\AppData\Local\{74F3AED9-B0F5-4602-B279-BCDAD2BC8E48}
2012-02-15 08:30:29   509952   ----a-w-   C:\Windows\System32\ntshrui.dll
2012-02-15 08:30:29   442880   ----a-w-   C:\Windows\SysWow64\ntshrui.dll
2012-02-15 08:30:28   515584   ----a-w-   C:\Windows\System32\timedate.cpl
2012-02-15 08:30:28   478720   ----a-w-   C:\Windows\SysWow64\timedate.cpl
2012-02-15 08:30:27   3145728   ----a-w-   C:\Windows\System32\win32k.sys
2012-02-15 08:30:25   498688   ----a-w-   C:\Windows\System32\drivers\afd.sys
2012-02-15 08:30:21   690688   ----a-w-   C:\Windows\SysWow64\msvcrt.dll
2012-02-15 08:30:21   634880   ----a-w-   C:\Windows\System32\msvcrt.dll
2012-02-15 00:19:59   --------   d-----w-   C:\Users\marina\AppData\Local\{3BB23024-0975-41F4-984D-02144E1C502E}
2012-02-14 12:19:20   --------   d-----w-   C:\Users\marina\AppData\Local\{B724E541-12D0-4293-9234-3F8811FA1436}
2012-02-14 07:24:00   --------   d-----w-   C:\ProgramData\{A8DA1505-E615-42BB-BB77-74D5CC91FE7E}
2012-02-14 00:18:20   --------   d-----w-   C:\Users\marina\AppData\Local\{D70CBE41-0C86-4C65-B9B0-90EBB3656462}
2012-02-14 00:17:51   --------   d-----w-   C:\Users\marina\AppData\Local\{2DF0ACF9-7C36-4BFC-AB1A-F50144FD263A}
2012-02-13 18:22:30   476904   ----a-w-   C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2012-02-13 12:17:20   --------   d-----w-   C:\Users\marina\AppData\Local\{78709EDC-D9DF-4FAA-B978-4F0C8EECA182}
2012-02-12 23:46:13   --------   d-----w-   C:\Users\marina\AppData\Local\{01E5DAFD-20A9-41A8-8CEB-39D71ADEB301}
2012-02-12 11:45:25   --------   d-----w-   C:\Users\marina\AppData\Local\{0DBEC31D-3AD8-4ACF-9125-35026BEEA5FF}
2012-02-11 23:44:44   --------   d-----w-   C:\Users\marina\AppData\Local\{03A3DD3A-381D-4766-B47F-963AC65A6073}
2012-02-11 11:44:06   --------   d-----w-   C:\Users\marina\AppData\Local\{05DAA6DF-7F93-4CFF-9738-2CA0C9D0F4F1}
2012-02-10 23:43:28   --------   d-----w-   C:\Users\marina\AppData\Local\{995C33D3-81ED-4CE6-BDD1-808493D106FE}
2012-02-10 11:42:50   --------   d-----w-   C:\Users\marina\AppData\Local\{4AE3DEC7-9062-4007-A279-B66B3E8730FF}
2012-02-10 11:42:27   --------   d-----w-   C:\Users\marina\AppData\Local\{3A212164-740A-4E05-917B-A7911CB7F5B3}
2012-02-09 23:41:58   --------   d-----w-   C:\Users\marina\AppData\Local\{D0F2561A-ABB6-49FE-AD44-CCFEE1776D1E}
2012-02-09 23:41:35   --------   d-----w-   C:\Users\marina\AppData\Local\{820FF5C9-CAD9-4878-916E-9A9693222499}
2012-02-09 11:41:03   --------   d-----w-   C:\Users\marina\AppData\Local\{46BB1FD4-FA32-4874-8611-9F03C8ADD4B1}
2012-02-09 11:40:48   --------   d-----w-   C:\Users\marina\AppData\Local\{522FD6FD-35B5-4EFA-8956-3EDBF4FC889B}
2012-02-08 23:20:59   --------   d-----w-   C:\Users\marina\AppData\Local\{A1515CB7-60EC-4EBE-B810-ACDC8335B1C4}
2012-02-08 11:20:20   --------   d-----w-   C:\Users\marina\AppData\Local\{F5B578C9-5CD3-4634-BD10-1748A17622E3}
2012-02-08 11:19:57   --------   d-----w-   C:\Users\marina\AppData\Local\{844A91F3-4EAC-4F93-AB07-90FD02E213DC}
2012-02-07 23:19:39   --------   d-----w-   C:\Users\marina\AppData\Local\{E311FC56-9106-431B-ABBF-541F55441850}
2012-02-07 23:19:38   --------   d-----w-   C:\Users\marina\AppData\Local\{ED473BA8-D36B-4CC6-AF40-E7E825D5E9E0}
2012-02-07 11:14:57   --------   d-----w-   C:\Users\marina\AppData\Local\{2F574A1E-401A-4DC7-8152-AFCB215E36BE}
2012-02-06 23:14:21   --------   d-----w-   C:\Users\marina\AppData\Local\{F11D66AB-3D23-4C4F-AAE6-2CDE923A2BB4}
2012-02-06 11:13:56   --------   d-----w-   C:\Users\marina\AppData\Local\{413950EE-612C-4232-9FE2-54DAD651D1BC}
2012-02-05 23:04:19   --------   d-----w-   C:\Users\marina\AppData\Local\{EC815D95-A1D6-4FB4-8621-5720BC3965F3}
2012-02-05 11:03:53   --------   d-----w-   C:\Users\marina\AppData\Local\{B4A3F3B2-0DEB-429E-A68B-21657163FA17}
2012-02-04 23:03:17   --------   d-----w-   C:\Users\marina\AppData\Local\{72C8D4C3-737F-48F8-BBC9-C124517ABFEC}
2012-02-04 11:02:40   --------   d-----w-   C:\Users\marina\AppData\Local\{21DED89F-1A40-4A58-A0E2-3C12C91921A8}
2012-02-03 23:02:02   --------   d-----w-   C:\Users\marina\AppData\Local\{D9BB0D6C-88D8-4667-A835-8B12002AB044}
2012-02-03 11:01:25   --------   d-----w-   C:\Users\marina\AppData\Local\{DAE1B859-76F7-49A2-B171-7F77C912D2DC}
2012-02-02 22:15:39   --------   d-----w-   C:\Users\marina\AppData\Local\{A08348E7-39C5-4B5A-83F3-FE03786D12A3}
2012-02-02 10:17:37   --------   d-----w-   C:\Program Files\iTunes
2012-02-02 10:14:57   --------   d-----w-   C:\Users\marina\AppData\Local\{38D86300-CED2-4D9E-B700-48EE7B230496}
2012-02-02 10:14:31   --------   d-----w-   C:\Users\marina\AppData\Local\{7ADF098C-749A-4355-BBB2-89940D6641E5}
2012-02-02 10:08:43   --------   d-----w-   C:\Program Files\Bonjour
2012-02-02 10:08:43   --------   d-----w-   C:\Program Files (x86)\Bonjour
2012-02-02 02:37:00   120368   ----a-w-   C:\Windows\SysWow64\ezuninst.exe
2012-02-02 02:37:00   117808   ----a-w-   C:\Windows\SysWow64\ezshellstart.exe
2012-02-01 22:14:01   --------   d-----w-   C:\Users\marina\AppData\Local\{960D9650-F51E-4D72-BEFC-87632EED221A}
2012-02-01 10:13:20   --------   d-----w-   C:\Users\marina\AppData\Local\{9DE140E0-297F-4FBD-A374-A23F604D51D3}
2012-02-01 10:12:56   --------   d-----w-   C:\Users\marina\AppData\Local\{7B3F2776-4D10-4B94-A3A7-A66F73565F63}
2012-01-31 22:13:17   --------   d-----w-   C:\Users\marina\AppData\Local\WiredRed
2012-01-31 22:12:37   --------   d-----w-   C:\Users\marina\AppData\Local\{1C8565F4-D7F5-45C3-A854-ADBD047AF93D}
2012-01-31 22:12:36   --------   d-----w-   C:\Users\marina\AppData\Local\{45514A8E-1666-445B-AB59-B94A6B1EEB21}
2012-01-31 12:52:20   738936   ----a-w-   C:\Windows\System32\drivers\NISx64\1305000.091\srtsp64.sys
2012-01-31 12:52:20   451192   ----a-r-   C:\Windows\System32\drivers\NISx64\1305000.091\symds64.sys
2012-01-31 12:52:20   405624   ----a-w-   C:\Windows\System32\drivers\NISx64\1305000.091\symnets.sys
2012-01-31 12:52:20   37496   ----a-w-   C:\Windows\System32\drivers\NISx64\1305000.091\srtspx64.sys
2012-01-31 12:52:20   190072   ----a-w-   C:\Windows\System32\drivers\NISx64\1305000.091\ironx64.sys
2012-01-31 12:52:20   1092728   ----a-w-   C:\Windows\System32\drivers\NISx64\1305000.091\symefa64.sys
2012-01-31 12:52:19   167048   ----a-w-   C:\Windows\System32\drivers\NISx64\1305000.091\ccsetx64.sys
2012-01-31 12:52:04   --------   d-----w-   C:\Windows\System32\drivers\NISx64\1305000.091
2012-01-31 10:12:09   --------   d-----w-   C:\Users\marina\AppData\Local\{CE0C35F1-DC5D-4FA3-A1F5-2F652B6631D9}
2012-01-30 22:11:30   --------   d-----w-   C:\Users\marina\AppData\Local\{DB1F1FBB-08BB-483D-BA17-96358785683C}
2012-01-30 10:10:54   --------   d-----w-   C:\Users\marina\AppData\Local\{55263DC9-BDC6-40F4-9C9B-6B4998AF84A2}
2012-01-29 22:10:17   --------   d-----w-   C:\Users\marina\AppData\Local\{2EF1D81D-ADE2-469F-84EC-EE9BD5A71825}
2012-01-29 10:09:41   --------   d-----w-   C:\Users\marina\AppData\Local\{A1EB882C-65CE-403B-BB40-45048E796CB6}
2012-01-28 21:26:45   --------   d-----w-   C:\Users\marina\AppData\Local\{E4CC6B2D-86DD-4570-9292-89EAB488CFFD}
2012-01-28 09:26:09   --------   d-----w-   C:\Users\marina\AppData\Local\{66588035-62A9-4C49-970B-F5D68FD54D62}
.
==================== Find3M  ====================
.
2012-02-25 21:15:15   472808   ----a-w-   C:\Windows\SysWow64\deployJava1.dll
2012-02-07 11:43:54   60   ----a-w-   C:\Windows\wpd99.drv
2012-01-31 12:52:30   175736   ----a-w-   C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2012-01-22 21:13:10   414368   ----a-w-   C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-12-14 07:11:03   2308096   ----a-w-   C:\Windows\System32\jscript9.dll
2011-12-14 07:04:30   1390080   ----a-w-   C:\Windows\System32\wininet.dll
2011-12-14 07:03:38   1493504   ----a-w-   C:\Windows\System32\inetcpl.cpl
2011-12-14 06:57:28   2382848   ----a-w-   C:\Windows\System32\mshtml.tlb
2011-12-14 03:04:54   1798656   ----a-w-   C:\Windows\SysWow64\jscript9.dll
2011-12-14 02:57:18   1127424   ----a-w-   C:\Windows\SysWow64\wininet.dll
2011-12-14 02:56:58   1427456   ----a-w-   C:\Windows\SysWow64\inetcpl.cpl
2011-12-14 02:50:04   2382848   ----a-w-   C:\Windows\SysWow64\mshtml.tlb
2011-12-10 15:24:08   23152   ----a-w-   C:\Windows\System32\drivers\mbam.sys
2011-12-01 08:18:06   499712   ----a-w-   C:\Windows\SysWow64\msvcp71.dll
2011-12-01 08:18:06   348160   ----a-w-   C:\Windows\SysWow64\msvcr71.dll
.
============= FINISH:  3:50:48.48 ===============
Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on February 26, 2012, 08:57:20 PM
And the attach

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 01/04/2010 11:52:49
System Uptime: 27/02/2012 00:17:23 (3 hours ago)
.
Motherboard: Hewlett-Packard |  | 3069
Processor: Pentium(R) Dual-Core CPU       T4300  @ 2.10GHz | CPU | 2100/800mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 285 GiB total, 161.411 GiB free.
D: is FIXED (NTFS) - 12 GiB total, 2.048 GiB free.
E: is CDROM (CDFS)
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP229: 13/02/2012 18:20:55 - Installed Java(TM) 6 Update 30
RP230: 14/02/2012 07:24:16 - Installed HP Support Assistant
RP231: 14/02/2012 07:28:34 - Windows Modules Installer
RP232: 14/02/2012 07:29:44 - Windows Modules Installer
RP233: 14/02/2012 18:08:47 - HPSF Applying updates
RP234: 16/02/2012 08:35:27 - Windows Update
RP235: 16/02/2012 16:30:43 - Windows Update
RP236: 18/02/2012 16:48:22 - Windows Update
RP237: 25/02/2012 21:02:52 - Installed Java(TM) 6 Update 31
.
==== Installed Programs ======================
.
7-Zip 9.20
Acrobat.com
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Reader X (10.1.2)
Adobe Shockwave Player
Akamai NetSession Interface
Akamai NetSession Interface Service
Apple Application Support
Apple Software Update
Babylon toolbar on IE
BBC iPlayer Desktop
Bing Bar
Bing Bar Platform
Camera Access Library
Camera Support Core Library
Camera Window DS
Camera Window DVC
Camera Window MC
Canon Camera Access Library
Canon Camera Support Core Library
Canon Camera Window DC_DV 5 for ZoomBrowser EX
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window DSLR 5 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
CANON iMAGE GATEWAY Task
CANON iMAGE GATEWAY Task for ZoomBrowser EX
Canon Internet Library for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon Utilities PhotoStitch 3.1
Canon ZoomBrowser EX (E)
Compatibility Pack for the 2007 Office system
CyberLink DVD Suite
CyberLink MediaShow
CyberLink PowerDVD 8
CyberLink YouCam
D3DX10
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Dropbox
Dudeism.com Relaxer
Easy Burner
EndNote
ERUNT 1.1j
ESET Online Scanner v3
Facemoods Toolbar
FreeMind
FYZip 1.00
GamePlayLabs Plugin
Google Chrome
Google Update Helper
Hewlett-Packard ACLM.NET v1.1.2.0
High-Definition Video Playback
HP Advisor
HP Customer Experience Enhancements
HP Games
HP Quick Launch Buttons
HP Setup
HP Support Assistant
HP Update
HP User Guides 0148
HP Wireless Assistant
Huawei modem
IDT Audio
Internet Library
ISI ResearchSoft - Export Helper
Java Auto Updater
Java(TM) 6 Update 31
Junk Mail filter update
KeePass Password Safe 1.19b
LabelPrint
LightScribe System Software
ListenArabic Toolbar
Magic Desktop
Malwarebytes Anti-Malware version 1.60.1.1000
McAfee Security Scan Plus
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Click-to-Run 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Home and Business 2010 - English
Microsoft Office Home and Student 2010
Microsoft Office Live Add-in 1.5
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Single Image 2010
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2010
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
Microsoft Works
Moozy
Move Media Player
MovieEdit Task
Mozilla Firefox 10.0.2 (x86 en-US)
MSVCRT
MSVCRT_amd64
muvee Reveal
Nero 11
Nero 11 Disc Menus Basic
Nero 11 Effects Basic
Nero 11 Image Samples
Nero 11 Kwik Themes Basic
Nero 11 PiP Effects Basic
Nero Audio Pack 1
Nero BackItUp 11
Nero BackItUp 11 Help (CHM)
Nero Burning ROM 11
Nero Burning ROM 11 Help (CHM)
Nero ControlCenter 11
Nero ControlCenter 11 Help (CHM)
Nero Core Components 11
Nero CoverDesigner 11
Nero CoverDesigner 11 Help (CHM)
Nero Express 11
Nero Express 11 Help (CHM)
Nero Kwik Media
Nero Kwik Media Help (CHM)
Nero Recode 11
Nero Recode 11 Help (CHM)
Nero RescueAgent 11
Nero RescueAgent 11 Help (CHM)
Nero SoundTrax 11
Nero SoundTrax 11 Help (CHM)
Nero Update
Nero Video 11
Nero Video 11 Help (CHM)
Nero WaveEditor 11
Nero WaveEditor 11 Help (CHM)
nero.prerequisites.msi
Norton Internet Security
Norton Online Backup
Pdf995
PhotoStitch
Power2Go
PowerDirector
PriceGong 2.5.2
QLBCASL
QuickTime
RAW Image Task 2.2
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek 8136 8168 8169 Ethernet Driver
Realtek USB 2.0 Card Reader
RealUpgrade 1.1
Recovery Manager
Safari
SecureW2 Enterprise Client 3.4.6
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft Office 2010 (KB2553091)
Security Update for Microsoft Office 2010 (KB2553096)
Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition
Security Update for Microsoft SharePoint Workspace 2010 (KB2566445)
Security Update for Microsoft Visio Viewer 2010 (KB2597170) 32-Bit Edition
Signature995
Skype™ 5.5
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft Excel 2010 (KB2553439) 32-Bit Edition
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553385) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2597091) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2553323) 32-Bit Edition
Update for Microsoft Outlook Social Connector (KB2583935)
Veoh Giraffic Video Accelerator
Veoh Web Player
welcome
Windows iLivid Toolbar
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WOT for Internet Explorer
.
==== Event Viewer Messages From Past Week ========
.
27/02/2012 03:44:51, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the NIS service.
26/02/2012 23:18:35, Error: Service Control Manager [7022]  - The Windows Update service hung on starting.
26/02/2012 23:13:58, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the HP Support Assistant Service service to connect.
26/02/2012 23:13:58, Error: Service Control Manager [7000]  - The HP Support Assistant Service service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
26/02/2012 06:05:24, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the iphlpsvc service.
26/02/2012 06:04:54, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the RasMan service.
26/02/2012 00:31:37, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Windows Presentation Foundation Font Cache 3.0.0.0 service to connect.
26/02/2012 00:31:37, Error: Service Control Manager [7000]  - The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
26/02/2012 00:27:43, Error: Service Control Manager [7001]  - The Client Virtualization Handler service depends on the Application Virtualization Client service which failed to start because of the following error:  The service did not respond to the start or control request in a timely fashion.
26/02/2012 00:27:40, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Application Virtualization Client service to connect.
26/02/2012 00:27:40, Error: Service Control Manager [7000]  - The Application Virtualization Client service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
24/02/2012 09:46:38, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Windows Error Reporting Service service to connect.
24/02/2012 04:25:31, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Browser service.
24/02/2012 04:25:31, Error: Service Control Manager [7000]  - The Computer Browser service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
.
==== End Of File ===========================
Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on February 27, 2012, 04:18:59 AM
One thing that might be of significance is that I did not disable Norton Internet security while I was running the DDSs. If you think this will affect the result please let me know and I will do it again with the Norton disabled
Title: Re: resource:///components/nsSessionStore.js:402
Post by: SuperDave on February 27, 2012, 01:01:50 PM
Download OTL (http://oldtimer.geekstogo.com/OTL.exe) to your desktop.

* Open OTL
* Copy and Paste the following text in the codebox into the Custom Scans/Fixes window.

Code: [Select]
:OTL

BHO: Shopping Assistant Plugin: {1631550f-191d-4826-b069-d9439253d926} - C:\Program Files (x86)\PriceGong\2.5.2\PriceGongIE.dll
BHO: Babylon toolbar helper: {2eecd738-5844-4a99-b4b6-146bf802613b} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll
BHO: CescrtHlpr Object: {64182481-4f71-486b-a045-b233bd0da8fc} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll
TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarTlbr.dll
TB: facemoods Toolbar: {db4e9724-f518-4dfd-9c7c-78b52103cab9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll
mRun: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe" /md I
BHO-X64:     PriceGong - No File
BHO-X64:     AcroIEHelperStub - No File
BHO-X64: Babylon toolbar helper: {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll
BHO-X64:     Babylon toolbar helper - No File
BHO-X64: CescrtHlpr Object: {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll
BHO-X64:     facemoods Helper - No File
BHO-X64:     Search Helper - No File
BHO-X64:     URLRedirectionBHO - No File
BHO-X64:     TBLA06779 - No File
TB-X64: facemoods Toolbar: {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll
mRun-x64: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe" /md I

:folders
C:\Program Files (x86)\PriceGong
C:\Program Files (x86)\BabylonToolbar\BabylonToolbar
C:\Program Files (x86)\facemoods.com\facemoods

:COMMANDS
[resethosts]
[purity]
[start explorer]

* Click Run Fix
* OTLI2 may ask to reboot the machine. Please do so if asked.
* Click OK
* A report will open. Copy and Paste that report in your next reply.
************************************************************
Download Combofix from any of the links below, and save it to your desktop

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
Link 3 (http://subs.geekstogo.com/ComboFix.exe)

To prevent your anti-virus application interfering with  ComboFix we need to disable it. See here (http://"http://www.pchelpforum.com/anti-virus/110194-how-disable-your-security-applications.html") for a tutorial regarding how to do so if you are unsure.
(http://i424.photobucket.com/albums/pp322/digistar/NSIS_disclaimer_ENG.png)

Click I Agree to start the program.

ComboFix will then extract the necessary files and you will see this:

(http://i424.photobucket.com/albums/pp322/digistar/NSIS_extraction.png)

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to  have this pre-installed on your machine before doing any malware  removal. This will not occur in Windows Vista and 7

It will allow you to boot up into a special recovery/repair  mode that will allow us to more easily help you should your computer  have a problem after an attempted removal of malware.

If you did not have it installed, you will see the prompt below. Choose YES.

(http://i424.photobucket.com/albums/pp322/digistar/RcAuto1.gif)

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

(http://i424.photobucket.com/albums/pp322/digistar/whatnext.png)

Click on Yes, to continue scanning for malware.

When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.
Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on February 27, 2012, 01:50:05 PM
Still problem with the script. While I was trying to talk on Skype the following appeared

A script on this page may be busy, or it may have stopped responding. You can stop the script now, or you can continue to see if the script will complete.

Script: http://mail.yimg.com/zz/combo?nq/3909/yui/yui-min.js&nq/3909/oop/oop-min.js&nq/3909/dom/dom-min.js&nq/3909/event/event-min.js&nq/3909/event-custom/event-custom-min.js&nq/3909/base/base-base-min.js&nq/3909/plugin/plugin-min.js&nq/3909/pluginhost/pluginhost-min.js&nq/3909/node/node-min.js&nq/3909/attribute/attribute-min.js&nq/3909/json/json-min.js&nq/3909/intl/intl-min.js&nq/3909/datatype/lang/datatype-date.js&nq/3909/datatype/datatype-date-min.js&nq/3909/datatype/datatype-xml-min.js&nq/3909/cookie/cookie-min.js&nq/3909/async-queue/async-queue-min.js&nq/3909/collection/array-extras-min.js&nq/3909/querystring/querystring-parse-simple-min.js&nq/3909/querystring/querystring-stringify-simple-min.js&nq/3909/loader/loader-min.js:13
Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on February 27, 2012, 03:43:06 PM
OTL did not ask me to reboot. This is the log. Is there something wrong? I will try to do it once again

========== OTL ==========
Error: Unable to interpret <:folders> in the current context!
Error: Unable to interpret <C:\Program Files (x86)\PriceGong> in the current context!
Error: Unable to interpret <C:\Program Files (x86)\BabylonToolbar\BabylonToolbar> in the current context!
Error: Unable to interpret <C:\Program Files (x86)\facemoods.com\facemoods> in the current context!
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.33.2 log created on 02272012_224127
Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on February 27, 2012, 03:44:53 PM
I tried again. Same message. Hope is fine
Title: Re: resource:///components/nsSessionStore.js:402
Post by: SuperDave on February 27, 2012, 06:02:21 PM
That's ok. Please uninstall these programs
Babylon toolbar on IE
Facemoods Toolbar
PriceGong 2.5.2

They are malicious.
Then, please proceed with ComboFix.
Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on February 28, 2012, 03:20:38 PM
Thanks. I deleted the programs you told me and run ComboFix (it took several attempts, quite some time and a reboot)

When I tried to open any of the different browsers so that I could send you the log the following message appeared

"c:\Program Files (x86) Mozilla Firefox/firefox.exe
Illegal Operation attempted on a registry item that has been marked to delete"

The same with IE and Google Chrone

Fortunately it worked OK after another reboot but I just thought I will tell you anyway

Also: while I have been trying to write this the following message appeared

"A script on this page may be busy, or it may have stopped responding. You can stop the script now, or you can continue to see if the script will complete.

Script: http://d3lvr7yuk4uaui.cloudfront.net/items/it/js/itn.js:46"

I get those messages daily sometimes several times. I am tired of them. Any suggestions as to what to do?
Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on February 28, 2012, 03:22:15 PM
And the Combo Fix log

ComboFix 12-02-27.02 - marina 28/02/2012  20:50:35.10.2 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.44.1033.18.3999.1950 [GMT 0:00]
Running from: c:\users\marina\Desktop\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\boost_interprocess\20120228140443.359599
c:\programdata\boost_interprocess\20120228140443.359599\Nobu64AgentService
c:\programdata\boost_interprocess\20120228140443.359599\Nobu64TrayIcon
.
.
(((((((((((((((((((((((((   Files Created from 2012-01-28 to 2012-02-28  )))))))))))))))))))))))))))))))
.
.
2012-02-28 21:18 . 2012-02-28 21:18   --------   d-----w-   c:\users\Public\AppData\Local\temp
2012-02-28 21:18 . 2012-02-28 21:18   --------   d-----w-   c:\users\Default\AppData\Local\temp
2012-02-27 22:41 . 2012-02-27 22:41   --------   d-----w-   C:\_OTL
2012-02-26 06:42 . 2012-02-26 06:42   --------   d-----w-   c:\users\marina\AppData\Roaming\SUPERAntiSpyware.com
2012-02-26 06:41 . 2012-02-26 06:44   --------   d-----w-   c:\program files\SUPERAntiSpyware
2012-02-26 06:41 . 2012-02-26 06:41   --------   d-----w-   c:\programdata\SUPERAntiSpyware.com
2012-02-25 21:17 . 2012-02-25 21:17   --------   d-----w-   c:\program files (x86)\Common Files\Java
2012-02-15 08:30 . 2012-01-04 10:44   509952   ----a-w-   c:\windows\system32\ntshrui.dll
2012-02-15 08:30 . 2012-01-04 08:58   442880   ----a-w-   c:\windows\SysWow64\ntshrui.dll
2012-02-15 08:30 . 2011-12-30 06:26   515584   ----a-w-   c:\windows\system32\timedate.cpl
2012-02-15 08:30 . 2011-12-30 05:27   478720   ----a-w-   c:\windows\SysWow64\timedate.cpl
2012-02-15 08:30 . 2012-01-14 04:06   3145728   ----a-w-   c:\windows\system32\win32k.sys
2012-02-15 08:30 . 2011-12-28 03:59   498688   ----a-w-   c:\windows\system32\drivers\afd.sys
2012-02-15 08:30 . 2011-12-16 08:46   634880   ----a-w-   c:\windows\system32\msvcrt.dll
2012-02-15 08:30 . 2011-12-16 07:52   690688   ----a-w-   c:\windows\SysWow64\msvcrt.dll
2012-02-14 07:24 . 2012-02-14 07:24   --------   d-----w-   c:\programdata\{A8DA1505-E615-42BB-BB77-74D5CC91FE7E}
2012-02-13 18:22 . 2012-02-25 21:15   476904   ----a-w-   c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2012-02-02 10:12 . 2012-02-02 10:12   159744   ----a-w-   c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
2012-02-02 10:08 . 2012-02-02 10:08   --------   d-----w-   c:\program files\Bonjour
2012-02-02 10:08 . 2012-02-02 10:08   --------   d-----w-   c:\program files (x86)\Bonjour
2012-02-02 02:37 . 2012-02-02 02:37   120368   ----a-w-   c:\windows\SysWow64\ezuninst.exe
2012-02-02 02:37 . 2012-02-02 02:37   117808   ----a-w-   c:\windows\SysWow64\ezshellstart.exe
2012-01-31 22:13 . 2012-02-22 20:20   --------   d-----w-   c:\users\marina\AppData\Local\WiredRed
2012-01-31 12:52 . 2012-02-01 00:44   --------   d-----w-   c:\windows\system32\drivers\NISx64\1305000.091
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-25 21:15 . 2010-05-02 11:55   472808   ----a-w-   c:\windows\SysWow64\deployJava1.dll
2012-01-31 12:52 . 2011-05-12 15:12   175736   ----a-w-   c:\windows\system32\drivers\SYMEVENT64x86.SYS
2012-01-22 21:13 . 2011-06-12 05:22   414368   ----a-w-   c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-12-10 15:24 . 2011-05-04 13:55   23152   ----a-w-   c:\windows\system32\drivers\mbam.sys
2011-12-01 08:18 . 2011-12-01 08:18   499712   ----a-w-   c:\windows\SysWow64\msvcp71.dll
2011-12-01 08:18 . 2011-12-01 08:18   348160   ----a-w-   c:\windows\SysWow64\msvcr71.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{F569CF08-EDF6-4FAB-8C8A-EEC184358372}"= "c:\program files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll" [2009-06-02 2695168]
.
[HKEY_CLASSES_ROOT\clsid\{f569cf08-edf6-4fab-8c8a-eec184358372}]
[HKEY_CLASSES_ROOT\TBLA06779.TBLA06779.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBLA06779.TBLA06779]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12   94208   ----a-w-   c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12   94208   ----a-w-   c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12   94208   ----a-w-   c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12   94208   ----a-w-   c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2011-03-04 2741616]
"HPADVISOR"="c:\program files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2010-06-30 1689144]
"VeohPlugin"="c:\program files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2011-08-25 2816328]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"Akamai NetSession Interface"="c:\users\marina\AppData\Local\Akamai\netsession_win.exe" [2012-02-02 3329824]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2010-02-25 323640]
"Easybits Recovery"="c:\program files (x86)\EasyBits For Kids\ezRecover.exe" [2009-09-02 60464]
"WirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2010-03-23 500792]
"SecureW2 Tray"="c:\program files (x86)\SecureW2\sw2_tray.exe" [2010-07-28 200584]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-11-02 59240]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"NBAgent"="c:\program files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" [2011-09-20 1493288]
"Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2011-10-12 3151000]
"TkBellExe"="c:\program files (x86)\real\realplayer\update\realsched.exe" [2011-12-01 296056]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-01-16 421736]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-31 460872]
.
c:\users\marina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
BBC iPlayer Desktop.lnk -  [N/A]
Dropbox.lnk - c:\users\marina\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-2-14 24246216]
ERUNT AutoBackup.lnk - c:\program files (x86)\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
fliptoast.lnk - c:\program files (x86)\Fliptoast\fliptoast.exe [N/A]
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVH.EXE [2012-1-4 3208032]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages   REG_MULTI_SZ      kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-31 136176]
R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-09 86072]
R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-02-25 227896]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-31 136176]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys
S0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\DRIVERS\NBVol.sys
S0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\DRIVERS\NBVolUp.sys
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1305000.091\SYMDS64.SYS
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1305000.091\SYMEFA64.SYS
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\BASHDefs\20120215.001\BHDrvx64.sys [2012-02-07 1157240]
S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NISx64\1305000.091\ccSetx64.sys
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.1.3\Definitions\IPSDefs\20120225.004\IDSvia64.sys [2011-12-15 488568]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1305000.091\Ironx64.SYS
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1305000.091\SYMNETS.SYS
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2010-06-30 89600]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2009-07-14 27136]
S2 Giraffic;Veoh Giraffic Video Accelerator;c:\program files (x86)\Giraffic\Veoh_GirafficWatchdog.exe [2012-01-22 2230416]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-28 94264]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-31 652360]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-09-23 641832]
S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe [2011-11-30 138248]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-02-07 138360]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai   REG_MULTI_SZ      Akamai
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-03-04 11:29   451872   ----a-w-   c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-31 15:52]
.
2012-02-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-31 15:52]
.
2012-02-26 c:\windows\Tasks\HPCeeScheduleFormarina.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-13 22:15]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12   97792   ----a-w-   c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12   97792   ----a-w-   c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12   97792   ----a-w-   c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12   97792   ----a-w-   c:\users\marina\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-10 165912]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-10 387608]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-10 365592]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-06-30 487424]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.alwaraq.net/Core/index.jsp?option=1
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = 127.0.0.1:9421;*.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105
IE: {{F569CF08-EDF6-4FAB-8C8A-EEC184358372} - {F569CF08-EDF6-4FAB-8C8A-EEC184358372} - c:\program files (x86)\ListenArabic\ListenArabic Toolbar\tbcore3.dll
TCP: DhcpNameServer = 193.63.73.32
FF - ProfilePath - c:\users\marina\AppData\Roaming\Mozilla\Firefox\Profiles\2y9b2iki.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.soas.ac.uk/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=2&q=
FF - prefs.js: network.proxy.gopher -
FF - prefs.js: network.proxy.type - 4
FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe
Toolbar-10 - (no file)
WebBrowser-{F569CF08-EDF6-4FAB-8C8A-EEC184358372} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe
AddRemove-Searchqu 406 MediaBar - c:\program files (x86)\Windows iLivid Toolbar\uninstall.exe
AddRemove-{6F44AF95-3CDE-4513-AD3F-6D45F17BF324} - c:\program files (x86)\InstallShield Installation Information\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\19.5.0.145\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\Akamai]
"ServiceDll"="c:\program files (x86)\common files\akamai/netsession_win_7de0ed9.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\CyberLink\Shared files\RichVideo.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Giraffic\Veoh_Giraffic.exe
c:\program files (x86)\Canon\CAL\CALMAIN.exe
.
**************************************************************************
.
Completion time: 2012-02-28  21:33:45 - machine was rebooted
ComboFix-quarantined-files.txt  2012-02-28 21:33
.
Pre-Run: 174,577,553,408 bytes free
Post-Run: 177,564,450,816 bytes free
.
- - End Of File - - FE017AF54B38363089461AA075AD570E
Title: Re: resource:///components/nsSessionStore.js:402
Post by: SuperDave on February 28, 2012, 04:53:08 PM
Quote
I deleted the programs you told me
You should not delete program. You should uninstall them or use their built-in uninstaller.

Quote
Illegal Operation attempted on a registry item that has been marked to delete"
This will disappear when you re-boot.
BTW, that link doesn't work for me.

Please download Rooter (http://eric71.geekstogo.com/tools/Rooter.exe) and Save it to your desktop.
Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on February 28, 2012, 05:58:03 PM
Thank you. Yes, this is what I did, uninstalled the programs, not deleted

Here are the Router1 Llogs

Rooter.exe (v1.0.2) by Eric_71
.
The token does not have the SeDebugPrivilege privilege ! (error:1300)
Can not acquire SeDebugPrivilege !
Please run the tool as administrator ..

.
Windows 7 Home Edition (6.1.7601) Service Pack 1
[32_bits] - Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
.
Error OpenService (wscsvc) : 6
Error OpenSCManager : 5
Error OpenService (MpsSvc) : 6
Windows Defender -> Enabled
User Account Control (UAC) -> Enabled
.
Internet Explorer 9.0.8112.16421
Mozilla Firefox 10.0.2 (en-US)
.
C:\  [Fixed-NTFS] .. ( Total:285 Go - Free:165 Go )
D:\  [Fixed-NTFS] .. ( Total:12 Go - Free:2 Go )
E:\  [CD_Rom]
Q:\  [Fixed-CDFS] .. ( Total:0 Go - Free:0 Go )
.
Scan : 00:48.04
Path : C:\Users\marina\Desktop\Rooter.exe
User : marina ( Administrator -> YES )
.
----------------------\\ Processes
.
Locked [System Process] (0)
Locked System (4)
Locked smss.exe (284)
Locked csrss.exe (380)
Locked wininit.exe (444)
Locked csrss.exe (456)
Locked services.exe (500)
Locked lsass.exe (516)
Locked lsm.exe (524)
Locked winlogon.exe (552)
Locked svchost.exe (672)
Locked svchost.exe (752)
Locked svchost.exe (828)
Locked svchost.exe (880)
Locked svchost.exe (912)
Locked stacsv64.exe (976)
Locked audiodg.exe (400)
Locked svchost.exe (600)
Locked svchost.exe (1088)
Locked wlanext.exe (1208)
Locked conhost.exe (1216)
Locked spoolsv.exe (1288)
Locked svchost.exe (1316)
Locked SASCore64.exe (1432)
Locked armsvc.exe (1452)
Locked AESTSr64.exe (1516)
Locked svchost.exe (1564)
Locked AppleMobileDeviceService.exe (1608)
______ ????????? (1624)
______ ????????? (1708)
______ ????????? (1788)
Locked mDNSResponder.exe (1156)
Locked svchost.exe (1420)
Locked Veoh_GirafficWatchdog.exe (1752)
Locked HPDrvMntSvc.exe (1552)
Locked LSSrvc.exe (2028)
Locked ccsvchst.exe (2060)
Locked NOBuAgent.exe (2152)
______ ????????? (2176)
______ ????????? (2212)
______ ????????? (2240)
Locked ccsvchst.exe (2312)
Locked RichVideo.exe (2384)
Locked SeaPort.exe (2420)
______ ????????? (2516)
______ ????????? (2524)
______ C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (2536)
______ C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe (2544)
Locked Veoh_Giraffic.exe (2552)
______ C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (2560)
______ C:\Program Files (x86)\Skype\Phone\Skype.exe (2568)
______ C:\Users\marina\AppData\Local\Akamai\netsession_win.exe (2576)
______ C:\Users\marina\AppData\Local\Akamai\netsession_win.exe (2596)
______ C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe (2700)
______ ????????? (2716)
______ ????????? (2728)
______ ????????? (2780)
______ C:\Program Files (x86)\real\realplayer\Update\realsched.exe (2796)
______ C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe (2820)
______ C:\Program Files (x86)\iTunes\iTunesHelper.exe (2916)
______ C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (2928)
______ C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (2940)
______ C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (3016)
______ C:\Users\marina\AppData\Roaming\Dropbox\bin\Dropbox.exe (3036)
______ C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVH.EXE (2072)
Locked sftvsa.exe (3360)
Locked svchost.exe (3384)
Locked svchost.exe (3500)
______ C:\Program Files (x86)\Mozilla Firefox\firefox.exe (4028)
Locked CALMAIN.exe (1012)
Locked sftlist.exe (1108)
Locked CVHSVC.EXE (4492)
Locked iPodService.exe (4844)
Locked SearchIndexer.exe (4916)
Locked SynTPHelper.exe (4036)
Locked hpqWmiEx.exe (1528)
Locked WmiPrvSE.exe (328)
Locked svchost.exe (3372)
______ C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (3100)
Locked taskeng.exe (944)
Locked HPSFMsgr.exe (3908)
Locked Com4QLBEx.exe (3424)
______ Q:\140062.enu\Office14\ONENOTEM.EXE (5504)
______ C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe (5532)
______ ????????? (5568)
______ C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe (5792)
Locked SearchProtocolHost.exe (5888)
Locked PresentationFontCache.exe (6136)
Locked HPSA_Service.exe (3712)
Locked mbamservice.exe (3952)
Locked NASvc.exe (3808)
Locked sppsvc.exe (3612)
Locked taskeng.exe (5216)
Locked taskhost.exe (6092)
______ C:\Users\marina\Desktop\Rooter.exe (5632)
Locked SearchFilterHost.exe (5292)
Locked WmiPrvSE.exe (1072)
Locked TrustedInstaller.exe (5596)
.
----------------------\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 --[ MBR ]-- (Start_Offset:1048576 | Length:208666624)
\Device\Harddisk0\Partition2 (Start_Offset:209715200 | Length:306469404672)
\Device\Harddisk0\Partition3 (Start_Offset:306679119872 | Length:13392412672)
.
----------------------\\ Scheduled Tasks
.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\Tasks\HPCeeScheduleFormarina.job
C:\Windows\Tasks\SA.DAT
C:\Windows\Tasks\SCHEDLGU(36).TXT
C:\Windows\Tasks\SCHEDLGU.TXT
.
----------------------\\ Registry
.
.
----------------------\\ Files & Folders
.
----------------------\\ Scan completed at 00:50.19
.
C:\Rooter$\Rooter_1.txt - (29/02/2012 | 00:50.19)


Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on February 29, 2012, 04:17:40 AM
Α warning message: unresponsive script again

A script on this page may be busy, or it may have stopped responding. You can stop the script now, or you can continue to see if the script will complete.

Script: http://d3lvr7yuk4uaui.cloudfront.net/items/it/js/itn.js:46

Also: those high CPU messages keep appearing daily. I never used to get them before
Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on February 29, 2012, 06:25:30 AM
More script and high CPU messages  :(

--
A script on this page may be busy, or it may have stopped responding. You can stop the script now, or you can continue to see if the script will complete.
Script: chrome://veoh_web_player/content/ctoolbar.js:30697
--
A script on this page may be busy, or it may have stopped responding. You can stop the script now, or you can continue to see if the script will complete.
Script: http://static.ak.fbcdn.net/rsrc.php/v1/yK/r/O6YPTSytvqd.js:19
--
Title: Re: resource:///components/nsSessionStore.js:402
Post by: SuperDave on February 29, 2012, 11:37:40 AM
Quote
? warning message: unresponsive script again
This (http://kb.mozillazine.org/Unresponsive_Script_Warning) may help you. Could you give me more information about those high CPU warnings?

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
 ESET OnlineScan (http://eset.com/onlinescan)
•Click the (http://i424.photobucket.com/albums/pp322/digistar/esetOnline.png) button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Check (http://i424.photobucket.com/albums/pp322/digistar/esetAcceptTerms.png)
•Click the (http://i424.photobucket.com/albums/pp322/digistar/esetStart.png) button.
•Accept any security warnings from your browser.
•Check (http://i424.photobucket.com/albums/pp322/digistar/esetScanArchives.png)
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push (http://i424.photobucket.com/albums/pp322/digistar/esetListThreats.png)
•Push (http://i424.photobucket.com/albums/pp322/digistar/esetExport.png), and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the (http://i424.photobucket.com/albums/pp322/digistar/esetBack.png) button.
•Push (http://i424.photobucket.com/albums/pp322/digistar/esetFinish.png)
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on February 29, 2012, 03:06:30 PM
While I am waiting for ESET to run

1. I went to error control to find the script that's causing the problem (trying to following the advice of the link you sent me) and the following came up. Always the same even though warning messages do not always show the same script. This is what I found

.addcontactwindow body{background:none;}.addignorewindow label{margin:5px 0;display:block;}html,body{height:100%;width:100%;}body{font-family:Arial,Helvetica,sans-serif;

Any advice on what to do?

2. The UCP messages are not all the same. Sometimes they refer to skype or firefox plugin or some other exe thing that I am not sure what it is

Will send you the ESET scans in a while. Thanks
Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on February 29, 2012, 03:28:01 PM
Sorry I just had another script error and the error console led me to this. So what I told you is wrong. Sorry

#yUnivHead{font-size:12px;}#yUnivHead.yucs-mr-in #yuhead-bd #yuhead-search #yuhead-sform-cont form button{padding:0 15px;line-height:25px;max-height:24px;}#yUnivHead.yucs-hi-in #yuhead-bd #yuhead-search #yuhead-sform-cont form button{padding:0 15px;line-height:25px;max-height:24px;}#yUnivHead.yucs-ta-IN #yuhead-hd #yuhead-mepanel-cont,#yUnivHead.yucs-ta-in #yuhead-hd #yuhead-mepanel-cont{width:37%;}#yUnivHead.yucs-ta-IN #yuhead-hd #yuhead-promo,#yUnivHead.yucs-ta-in #yuhead-hd #yuhead-promo{width:27.5%;}#yUnivHead.yucs-lt-LT #yuhead-hd #yuhead-mepanel-cont,#yUnivHead.yucs-lt-lt #yuhead-hd #yuhead-mepanel-cont{width:40%;}#yUnivHead.yucs-lt-LT #yuhead-hd #yuhead-promo,#yUnivHead.yucs-lt-lt #yuhead-hd #yuhead-promo{width:24.5%;}#yUnivHead.yucs-ko-KR,#yUnivHead.yucs-ko-kr{font-size:11px;font-family:dotum;}#yUnivHead.yucs-ko-kr #yuhead-hd,#yUnivHead.yucs-ko-KR #yuhead-hd,#yUnivHead.yucs-mr-IN #yuhead-hd,#yUnivHead.yucs-mr-in #yuhead-hd{font-size:100%;}#yUnivHead.yucs-zh-CN,#yUnivHead.yucs-zh-cn,#yUnivHead.yucs-zh-HK,#yUnivHead.yucs-zh-hk,#yUnivHead.yucs-zh-Hans-CN,#yUnivHead.yucs-zh-hans-cn,#yUnivHead.yucs-zh-Hans-HK,#yUnivHead.yucs-zh-hans-hk,#yUnivHead.yucs-zh-Hans-US,#yUnivHead.yucs-zh-hans-us,#yUnivHead.yucs-zh-Hant-CN,#yUnivHead.yucs-zh-hant-cn,#yUnivHead.yucs-zh-Hant-HK,#yUnivHead.yucs-zh-hant-hk,#yUnivHead.yucs-zh-Hant-US,#yUnivHead.yucs-zh-hant-us{font-family:Arial,PMingLiu,taipei;font-size:13px;}#yUnivHead.yucs-zh-TW,#yUnivHead.yucs-zh-tw,#yUnivHead.yucs-zh-Hans-TW,#yUnivHead.yucs-zh-hans-tw,#yUnivHead.yucs-zh-Hant-TW,#yUnivHead.yucs-zh-hant-tw{font-family:Arial,helvetica,clean,sans-serif;font-size:13px;}#yUnivHead.yucs-ar-AE,#yUnivHead.yucs-ar-ae,#yUnivHead.yucs-ar-BH,#yUnivHead.yucs-ar-bh,#yUnivHead.yucs-ar-DZ,#yUnivHead.yucs-ar-dz,#yUnivHead.yucs-ar-EG,#yUnivHead.yucs-ar-eg,#yUnivHead.yucs-ar-JO,#yUnivHead.yucs-ar-jo,#yUnivHead.yucs-ar-KW,#yUnivHead.yucs-ar-kw,#yUnivHead.yucs-ar-LB,#yUnivHead.yucs-ar-lb,#yUnivHead.yucs-ar-LY,#yUnivHead.yucs-ar-ly,#yUnivHead.yucs-ar-MA,#yUnivHead.yucs-ar-ma,#yUnivHead.yucs-ar-OM,#yUnivHead.yucs-ar-om,#yUnivHead.yucs-ar-PS,#yUnivHead.yucs-ar-ps,#yUnivHead.yucs-ar-QA,#yUnivHead.yucs-ar-qa,#yUnivHead.yucs-ar-SA,#yUnivHead.yucs-ar-sa,#yUnivHead.yucs-ar-SD,#yUnivHead.yucs-ar-sd,#yUnivHead.yucs-ar-SY,#yUnivHead.yucs-ar-sy,#yUnivHead.yucs-ar-TN,#yUnivHead.yucs-ar-tn,#yUnivHead.yucs-ar-YE,#yUnivHead.yucs-ar-ye{font-family:Tahoma,sans-serif;}#yUnivHead .sp{background-image:url('http://l.yimg.com/a/lib/uh/20/uh-sprite-2-15.png');_background-image:url('http://l.yimg.com/a/lib/uh/20/uh-sprite-2-15.gif');background-repeat:no-repeat;}#yUnivHead .yuhead-clearfix:after{display:block;visibility:hidden;width:0;height:0;clear:both;content:".";}#yUnivHead .yuhead-clearfix{zoom:1;}#yUnivHead a:focus{outline:none;}#yUnivHead #yuhead-hd a:focus{text-decoration:underline;}#yUnivHead #yuhead-hd ul:focus{outline:none;}#yUnivHead #yuhead-hd ul li ul a:focus{text-decoration:none;}#yUnivHead .yuhead-logo h2 a:focus{outline:1px dotted;}#yUnivHead .yuhead-bullet-down{background-position:right -172px;}#yUnivHead .yuhead-ico-mail{background-position:0 1px;padding-left:20px;margin-left:-3px;height:15px;}#yUnivHead .yuhead-ico-home{background-position:0 -61px;padding-left:20px;display:inline-block;height:15px;}#yUnivHead .yuhead-ico-bell{background-position:0 -292px;padding-left:20px;}#yUnivHead .yuhead-ico-mglass{background-position:5px -225px;padding-left:20px;}#yUnivHead .hidden,#yUnivHead .hide{display:none!important;}#yUnivHead #yucs-shim{position:absolute;z-index:999;}#yUnivHead .yuhead-offscreen{float:left;text-indent:-999em;overflow:hidden;}#yUnivHead a.yuhead-offscreen:hover{text-decoration:none;}body{padding-top:0;margin-top:0;}#yUnivHead table{border-collapse:collapse;border-spacing:0;}#yUnivHead h2{margin:0;font-size:93%;font-weight:normal;}#yUnivHead #yuhead-hd em{font-style:normal;}#yUnivHead #yuhead-hd ul{margin:0;padding:0;}#yUnivHead #yuhead-hd ul li{margin:0;padding:0;list-style:none;height:10px;vertical-align:top;}#yUnivHead #yuhead-hd a{display:block;margin-top:-2px;_display:inline-block;_margin-top:0;}#yUnivHead #yuhead-hd ul li ul li{height:auto;}#yUnivHead #yuhead-hd ul li ul li a{margin-top:auto;}#yUnivHead #yuhead-bd img{border:0;}#yUnivHead #yuhead-bd form{margin:0;}#yUnivHead{width:100%;margin:0 auto;font-family:Arial;background:none;z-index:9999;position:relative;text-align:left;}#yUnivHead .yucs-trending-anim .yucs-trending-anim-fade{background:#fff;}#yUnivHead{background:#fff;}#yUnivHead .yucs-skipto-search{position:absolute;text-indent:-999em;overflow:hidden;}#yUnivHead{color:#676767;}#yUnivHead a{color:#676767;text-decoration:none;}#yUnivHead a:hover{color:#676767;text-decoration:none;}#yuhead-hd{padding:8px 10px 13px;font-size:93%;}#yuhead-hd #yuhead-mepanel-cont{float:left;width:35%;}#yuhead-hd #yuhead-mepanel-cont #yuhead-mepanel{margin-left:-7px;float:left;}#yuhead-hd #yuhead-mepanel-cont #yuhead-mepanel li{float:left;border-left:1px solid #d6d6d6;padding:0 9px;}#yuhead-hd #yuhead-mepanel-cont #yuhead-mepanel{padding-left:10px;}#yuhead-hd #yuhead-mepanel-cont #yuhead-mepanel li em{font-weight:bold;}#yuhead-hd #yuhead-mepanel-cont #yuhead-mepanel li em a{font-weight:normal;}#yuhead-hd li.yuhead-nodivide{border-left:none!important;}#yuhead-hd li.yuhead-nopad{padding-left:0!important;}#yuhead-hd li#yuhead-username a{font-weight:bold;}#yuhead-hd li#yuhead-username span.yuhead-hi{font-weight:normal;float:left;* float:none;}#yuhead-hd li#yuhead-username{whitespace:no-wrap;}#yuhead-hd li#yuhead-username ul li a{font-weight:normal;}#yuhead-hd #yuhead-mepanel-cont #yuhead-mepanel #yuhead-me-signin{font-weight:bold;}#yuhead-hd #yuhead-promo{float:left;width:29.5%;text-align:center;}#yuhead-hd #yuhead-promo div.yucs-trending-anim{min-width:200px;margin:0 auto;text-align:left;float:right;}#yuhead-hd #yuhead-promo a{color:#1f4ca5;font-weight:bold;}#yuhead-hd #yuhead-promo a:hover{color:#1f4ca5;font-weight:bold;}#yuhead-hd #yuhead-promo #yuhead-promo-i{display:inline;}
#yuhead-hd #yuhead-promo #yuhead-promo-i .yuhead-promo-label{color:#1f4ca5;font-weight:bold;}#yuhead-hd #yuhead-promo #yuhead-promo-i a{color:#1f4ca5;}#yuhead-hd #yuhead-promo #yuhead-promo-i a:hover{color:#1f4ca5;}#yuhead-hd #yuhead-promo #yuhead-promo-i #yuhead-promo-menu{display:none;}#yuhead-hd #yuhead-com-links-cont{float:right;width:35%;*overflow-x:hidden;}#yuhead-hd #yuhead-com-links-cont #yuhead-com-links{float:right;margin-top:-2px;padding-top:2px;margin-right:-9px;}#yuhead-hd #yuhead-com-links-cont #yuhead-com-links li{* float:left;display:inline-block;padding:0 9px;border-right:1px solid #ccc;margin-right:-1px;}#yuhead-hd #yuhead-com-links-cont #yuhead-com-links li#yuhead-com-home{border-right:none;}#yuhead-hd #yuhead-com-links-cont #yuhead-com-links li ul li{display:block;float:none;_width:0;* border-right:none;}#yuhead-hd #yuhead-com-links-cont #yuhead-com-links .yuhead-ico-home a{padding-right:10px;}#yuhead-hd #yuhead-com-links-cont #yuhead-com-links a.yuhead-ico-mail,#yuhead-hd #yuhead-com-links-cont #yuhead-com-links a span.yuhead-ico-home{display:block;padding-bottom:1px;_display:inline-block;}#yuhead-hd #yuhead-right{float:right;width:56.8%;max-width:727px;}#yuhead-bd{padding:0 10px 12px;}.yuhead-logo{float:left;width:360px;margin-right:40px;text-align:left;}.yuhead-logo h2 a{color:#333;text-indent:-999em;overflow:hidden;}.yuhead-logo h2 div.yuhead-comarketing a{display:inline;text-indent:0;width:0 auto;}.yuhead-logo h2 div.yuhead-comarketing{text-align:right;white-space:nowrap;}#yUnivHead #yuhead-hd ul li.yucs-menu{position:relative;z-index:10000;}#yUnivHead #yuhead-hd ul li.yucs-menu ul{* clear:both;top:13px;font-size:108%;padding:8px 0;}#yUnivHead #yuhead-hd ul li.yucs-menu ul.yucs-menu-left{left:0;}#yUnivHead #yuhead-hd ul li.yucs-menu ul.yucs-menu-right{right:8px;}#yUnivHead #yuhead-hd ul li.yucs-menu ul.yucs-menu-left .debug-item em{display:block;margin:-1.2em 0 0 15em;font-style:normal;text-align:right;}#yUnivHead #yuhead-hd ul li.yucs-menu ul.yucs-menu-right .debug-item em{display:block;margin:-1.2em 0 0 15em;font-style:normal;text-align:right;}#yUnivHead #yuhead-hd ul li.yucs-menu ul li{clear:both;float:none;border:0;padding:0;margin:0;}#yUnivHead #yuhead-hd #yuhead-mepanel-cont #yuhead-mepanel li.yucs-menu ul li{* float:none!important;}#yUnivHead #yuhead-hd ul li.yucs-menu ul{position:absolute;background:#f5f5f5;border:1px solid #777;white-space:nowrap;z-index:1000;-moz-border-radius:3px;-webkit-border-radius:3px;border-radius:3px;-moz-box-shadow:0 5px 10px rgba(0,0,0,0.25);-webkit-box-shadow:0 5px 10px rgba(0,0,0,0.25);box-shadow:0 5px 10px rgba(0,0,0,0.25);}#yUnivHead #yuhead-hd ul li.yucs-menu ul li{float:none;color:#454545;padding:3px 16px!important;line-height:1.3em;}#yUnivHead #yuhead-hd ul li.yucs-menu ul li a{color:#454545;}#yUnivHead #yuhead-hd ul li.active{background-position:6px -1035px;}#yUnivHead #yuhead-hd ul li.yucs-menu ul li.disabled{cursor:pointer;}#yUnivHead #yuhead-hd ul li.yucs-menu ul li.disabled a{color:#999;cursor:pointer;}#yUnivHead #yuhead-hd ul li.yucs-menu ul li.disabled a:hover{text-decoration:none;cursor:default;}#yUnivHead #yuhead-hd ul li.yucs-menu ul li.last-item{min-width:13em;* width:17em;}#yUnivHead #yuhead-hd ul li.yucs-menu ul li.last-child{border-top:1px solid #ccc;width:100%;_width:17em;padding:8px 0 0!important;text-indent:18px;margin-right:19px;_margin-right:0;margin-top:8px;}#yUnivHead #yuhead-hd ul li.yucs-menu ul li.last-child span,#yUnivHead #yuhead-hd ul li.yucs-menu ul li.yuhead-user-login span{display:block;color:#454545;clear:both;cursor:pointer;font-weight:bold;padding:3px 0;}#yUnivHead #yuhead-hd ul li.yucs-menu span.yucs-menu-access{text-decoration:none;display:inline-block;width:7px;padding:0;text-indent:-999em;overflow:hidden;height:15px;vertical-align:middle;}#yUnivHead #yuhead-hd ul li.yucs-menu a.yucs-menu-access{display:inline-block;height:15px;overflow:hidden;padding:0;text-decoration:none;text-indent:-999em;vertical-align:middle;width:7px;}div.sa-tray{z-index:9999;}#yUnivHead #yuhead-pbar{color:#fff;font-size:93%;padding:3px 3px 6px;border-bottom:1px solid #328ca5;background-color:#33a1c8;background-image:-moz-linear-gradient(top,#3494b2,#48c9ed 90%);background-image:-webkit-gradient(linear,left top,left bottom,from(#3494b2),color-stop(0.9,#48c9ed));background-image:linear-gradient(top,#3494b2,#48c9ed);}#yUnivHead #yuhead-pbar div.yuhead-pbar-links a{color:#fff;padding-right:7px;padding-left:7px;border-right:1px solid #75d03d;vertical-align:middle;}#yUnivHead #yuhead-pbar div.yuhead-pbar-links a.last{border-right:none;}#yUnivHead #yuhead-pbar div.yuhead-pbar-links{float:none;* float:left;display:inline;}#yUnivHead #yuhead-pbar img{float:right;vertical-align:middle;padding-right:6px;border:none;}#yUnivHead #yuhead-promo .yucs-sethp .yucs-sethp-panel a,#yUnivHead #yuhead-promo .yucs-sethp .yucs-sethp-panel a:hover{color:#1F4CA5!important;}#yUnivHead #yuhead-promo .yucs-sethp .yucs-sethp-panel{color:#676767;}#yuhead-hd #yuhead-mepanel-cont #yuhead-mepanel li ul li{float:none;border-left:medium none;margin-left:0;}#yUnivHead #yuhead-hd ul li.yucs-menu ul li:hover,#yUnivHead #yuhead-hd ul li.yucs-menu ul li.li-selected{background-color:#e0e0e0;}#yUnivHead #yuhead-hd ul li.yucs-menu ul#yuhead-useroptions li.last-child:hover{background-color:#f6f6f6;}#yUnivHead #yuhead-hd ul li.yucs-menu ul#yuhead-useroptions li.last-child span:hover{background-color:#e0e0e0;}#yUnivHead #yuhead-hd ul li.yucs-menu ul span.separator{display:block;border-bottom:1px solid #ccc;padding-bottom:8px;margin-bottom:9px;}#yuhead-hd #yuhead-com-links-cont #yuhead-com-links li ul#yuhead-useroptions li.last-child{border-right:#777;margin-top:0;padding:6px 0 3px!important;}#yUnivHead #yuhead-hd #yuhead-att-panel li{border-left:0;border-right:1px solid #777;padding:3px 18px!important;}.yuhead-logo h2{background-repeat:no-repeat;}.yuhead-logo h2.small{background-position:0 -240px;}.yuhead-logo div.yuhead-comarketing a{display:inline;position:relative;}.yuhead-logo a{display:block;position:absolute;}.yuhead-logo div.yuhead-comarketing{font-size:93%;white-space:nowrap;text-align:right;}img.yucs-avatar{border:1px solid #cacaca!important;padding:1px;width:16px;height:16px;_display:block;_position:relative;}span.yucs-avatar{display:inline-block;margin-top:-2px;margin-right:5px;float:left;width:20px;height:20px;}span.yucs-opi em{float:left;text-indent:-999em;}span.yucs-opi{float:left;*float:none;}.yucs-opi{display:inline-block;width:20px;height:12px;background:url(http://l.yimg.com/a/lib/uh/20/uh-sprite-2-15.png) no-repeat scroll 0 -100% transparent;_background:url(http://l.yimg.com/a/lib/uh/20/uh-sprite-2-15.gif) no-repeat scroll 0 -100% transparent;border:none;vertical-align:middle;margin-top:1px;}img.yucs-opi{height:15px!important;}.yucs-opi.invisible{background-position:2px -606px;visibility:visible;}.yucs-opi.available{background-position:2px -792px;}.yucs-opi.busy{background-position:2px -667px;}.yucs-opi.offline{background-position:2px -606px;}.yucs-opi.idle{background-position:2px -732px;visibility:visible;}#yUnivHead #yuhead-hd .yucs-notifications a.ynotif-control{*cursor:pointer;}#yUnivHead #yuhead-hd .yucs-notifications a.ynotif-control:focus{text-decoration:none;}#yUnivHead #yuhead-hd .yucs-notifications a.busy{background:url(http://l.yimg.com/us.yimg.com/i/nt/ic/ut/bsc/busyarr_1.gif) no-repeat;}#yUnivHead #yuhead-hd li.yucs-notifications .ynotif-ico-bell{padding-left:0;}li.yucs-notifications .ynotif-ico-bell{margin-top:-1px;*margin-top:0;vertical-align:top;background-position:3px -292px;display:inline-block;float:left;height:18px;_height:15px;width:22px;border:1px solid rgba(0,0,0,0);*padding-bottom:1px;border-bottom:0;}#yUnivHead #yuhead-hd li.yucs-notifications .ynotif-ico-bell.enabled{border:1px solid #aaa;border:1px solid rgba(0,0,0,.35);background-position:3px -290px;margin-top:-3px;border-bottom:0;*margin-right:-1px;*padding-bottom:2px;_padding-bottom:3px;position:relative;z-index:1001;border-radius:3px 3px 0 0;-moz-border-radius:3px 3px 0 0;-webkit-border-radius:3px 3px 0 0;-webkit-box-shadow:0 0 0 0 rgba(0,0,0,0.25);-moz-box-shadow:0 0 0 0 rgba(0,0,0,0.25);box-shadow:0 0 0 0 rgba(0,0,0,0.25);background-color:#fff;}#yUnivHead #yuhead-hd .yucs-notifications .invisible{visibility:hidden;-webkit-transition:opacity .25s linear,visibility .25s linear;-moz-transition:opacity .25s linear,visibility .25s linear;-ms-transition:opacity .25s linear,visibility .25s linear;-o-transition:opacity .25s linear,visibility .25s linear;transition:opacity .25s linear,visibility .25s linear;opacity:0;}#yUnivHead #yuhead-hd .yucs-notifications .ynotif-notif-count-con{_display:inline-block;display:block;float:left;vertical-align:top;*margin-top:0;}#yUnivHead #yuhead-hd .yucs-notifications .ynotif-notif-count{background-color:#e02727;color:#fff;padding:0 5px;-webkit-border-radius:6px;-moz-border-radius:6px;border-radius:6px;}#yUnivHead #yuhead-hd li.yucs-notifications .ynotif-ico-bell:hover{text-decoration:none!important;}#yUnivHead #yuhead-hd li.yucs-notifications ul.ynotif-no-menu{white-space:normal;padding:10px!important;}#yUnivHead #yuhead-hd li.yucs-notifications ul.ynotif-no-menu span{white-space:normal;}#yUnivHead #yuhead-hd li.yucs-notifications ul.ynotif-no-menu a{font-weight:bold;float:none;}#yUnivHead #yuhead-hd li.yucs-notifications span.ynotif-unavail{padding-left:26px;background-image:url(http://l.yimg.com/us.yimg.com/i/nt/ic/ut/bsc/warn16_1.gif);background-repeat:no-repeat;display:block;}#yUnivHead #yuhead-hd #yuhead-com-links-cont #yuhead-com-links li.yucs-notifications .yucs-notif-loading{background:url("http://mail.yimg.com/ok/u/assets/img/spinner-24x24-anim.gif") no-repeat scroll 50% 6px transparent;padding:10px 0;text-indent:-9999px;}li.yucs-notifications{z-index:10000;position:relative;}#yUnivHead #yuhead-hd li.yucs-notifications.forceZIndex{z-index:10000;}#yUnivHead #yuhead-hd .yucs-notif-panel{width:220px;_width:220px;outline:none;background-color:#fff;padding-top:0;left:-10px;top:13px;*top:15px;z-index:1000;position:absolute;-webkit-box-shadow:0 5px 10px rgba(0,0,0,0.25);-moz-box-shadow:0 5px 10px rgba(0,0,0,0.25);box-shadow:0 5px 10px rgba(0,0,0,0.25);border:1px solid #aaa;border:1px solid rgba(0,0,0,0.35);border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;}#yUnivHead #yuhead-hd ul.yucs-notif-items-panel{overflow-y:auto;overflow-x:hidden;max-height:360px;*max-height:360px;}#yUnivHead #yuhead-hd #yuhead-com-links-cont #yuhead-com-links ul.yucs-notif-items-panel .yucs-notif-util{background-color:#fff;font-weight:bold;padding:10px 10px 10px 20px;}#yUnivHead #yuhead-hd .yucs-notif-title-bar{padding:5px;border-bottom:1px solid #ccc;}#yUnivHead #yuhead-hd .yucs-notif-title-bar .yucs-notif-panel-title{float:left;font-weight:bold;color:#000;}#yUnivHead #yuhead-hd .yucs-notif-title-bar .yucs-notif-panel-settings{text-indent:-999em;overflow:hidden;float:right;width:16px;height:16px;background-position:0 -1444px;margin-right:-4px;}#yUnivHead #yuhead-hd .yucs-notif-title-bar .yucs-notif-tools{overflow:hidden;float:right;margin-top:0;color:#454545;}#yUnivHead #yuhead-hd #yuhead-com-links-cont #yuhead-com-links ul.yucs-notif-items-panel li:first-child{border:none;}#yUnivHead #yuhead-hd #yuhead-com-links-cont #yuhead-com-links ul.yucs-notif-items-panel li:last-child{padding-bottom:15px;}#yUnivHead #yuhead-hd #yuhead-com-links-cont #yuhead-com-links ul.yucs-notif-items-panel li{list-style:none;clear:both;border-top:1px solid #ccc;padding:5px;font-size:95%;background-color:#f9f9f9;_width:auto!important;}#yUnivHead #yuhead-hd #yuhead-com-links-cont #yuhead-com-links ul.yucs-notif-items-panel li.yucs-new-notif{background-color:#fff;}#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li.yucs-notif-flash{background-color:#fffae4!important;}#yUnivHead #yuhead-hd #yuhead-com-links-cont #yuhead-com-links ul.yucs-notif-items-panel .yucs-get-items,#yUnivHead #yuhead-hd #yuhead-com-links-cont #yuhead-com-links ul.yucs-notif-items-panel .yucs-signedout-cta-message{border-top:1px solid #ccc;background-color:#f9f9f9;font-weight:normal;}#yUnivHead #yuhead-hd #yuhead-com-links-cont #yuhead-com-links ul.yucs-notif-items-panel .yucs-try-items,#yUnivHead #yuhead-hd #yuhead-com-links-cont #yuhead-com-links ul.yucs-notif-items-panel .yucs-signin-btn{background-color:#f9f9f9;padding-top:0;}#yUnivHead #yuhead-hd ul.yucs-notif-items-panel .yucs-try-items a.yucs-has-focus{text-decoration:underline;}#yUnivHead #yuhead-hd ul.yucs-notif-items-panel a.yucs-notif-util-action{border:1px solid #ccc;background-position:0 -1309px;background-repeat:repeat-x;-moz-border-radius:3px;-webkit-border-radius:3px;border-radius:3px;text-decoration:none;color:#1f4ca5;display:inline-block;padding:3px;font-weight:normal;}#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li .dot{float:left;width:10px;height:10px;visibility:hidden;}#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li .yucs-notif-bd{overflow:hidden;word-wrap:break-word;margin-left:15px;}#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li .yucs-notif-ft{margin-left:15px;}
#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li.yucs-new-notif .dot{background-position:0 -1764px;visibility:visible;}#yUnivHead #yuhead-hd ul.yucs-notif-items-panel div .yucs-notif-cta-con,#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li .yucs-notif-cta-con{margin:5px 0 0;}#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li a.yucs-notif-cta-btn{border:1px solid #ccc;background-position:0 -1309px;background-repeat:repeat-x;-moz-border-radius:3px;-webkit-border-radius:3px;border-radius:3px;}#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li a.yucs-notif-cta-btn,#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li a.yucs-notif-cta-link{display:inline-block;padding:3px;margin-right:5px;}#yUnivHead .yucs-notif-panel .sp{background-image:url('http://l.yimg.com/a/lib/uh/20/uh-sprite-2-15.png');_background-image:url('http://l.yimg.com/a/lib/uh/20/uh-sprite-2-15.gif');background-repeat:no-repeat;}#yUnivHead #yuhead-hd ul.yucs-notif-items-panel{color:#454545;}#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li a{display:inline;text-decoration:none;color:#1f4ca5;*cursor:pointer;}#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li .yucs-notif-ft a{display:block;float:right;}#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li.yucs-notif-by-time .ynotif-timestamp{color:#AAA;display:block;float:left;width:140px;padding-top:5px;font-size:85%;}#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li.yucs-notif-by-time .icon{float:right;border:none;}#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li:hover,#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li.yucs-new-notif:hover,#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li.yucs-has-focus{background-color:#e0e0e0!important;outline:none;}#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li a.yucs-has-focus{text-decoration:underline;}#yUnivHead #yuhead-hd .yucs-notif-title-bar .yucs-has-focus{outline:1px dotted #676767!important;text-decoration:none;}#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li .yucs-notif-cta-con a.yucs-has-focus,#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li .yucs-notif-cta-con a.yucs-has-focus,#yUnivHead #yuhead-hd ul.yucs-notif-items-panel li .yucs-notif-ft a.yucs-has-focus{text-decoration:none;outline:1px dotted;}#yuhead-bd #yuhead-search{float:right;width:56.8%;max-width:727px;}#yuhead-bd #yuhead-search #yuhead-sform-cont{float:right;width:100%;border:1px solid;_overflow:hidden;_padding-bottom:1px;}#yuhead-bd #yuhead-search #yuhead-sform-cont form input{color:#000;}#yuhead-bd #yuhead-search #yuhead-sform-cont form label span{float:left;text-indent:-999em;_text-indent:0;overflow:hidden;height:0;width:0;}#yuhead-bd #yuhead-search #yuhead-sform-cont form .yucs-form-input{width:100%;padding:3px;_padding:2px 0 0 3px;}#yuhead-bd #yuhead-search #yuhead-sform-cont form .yucs-search-hint-color{color:#a9a9a9;}#yuhead-bd #yuhead-search #yuhead-sform-cont form .yucs-form-btn{padding:3px 3px 3px 23px;_padding:2px 2px 0 23px;}#yuhead-bd #yuhead-search #yuhead-sform-cont form input{border-color:#8E8E90 #D9D9DA #D9D9DA #8E8E90;outline:none;background-color:#fff;}#yuhead-bd #yuhead-search #yuhead-sform-cont form .yucs-search-field{width:100%;border-width:1px;vertical-align:top;height:18px;_height:19px;padding-top:2px;padding-bottom:2px;* padding-top:4px;_padding-bottom:0;border-style:solid;margin-right:3px;}#yuhead-bd #yuhead-search #yuhead-sform-cont form button{border:0;margin:0;background:none;font-weight:bold;font-size:100%;padding:4px 15px 3px;* padding:3px 4px;cursor:pointer;font-family:arial;line-height:15px;max-height:23px;}#yuhead-bd #yuhead-search #yuhead-sform-cont{border-color:#afafaf;background-color:#dfdfe0;background-image:-moz-linear-gradient(top,#f1f1f4,#cacaca);background-image:-webkit-gradient(linear,left top,left bottom,from(#f1f1f4),to(#cacaca));background-image:linear-gradient(top,#f1f1f4,#cacaca);}#yuhead-bd #yuhead-search #yuhead-sform-cont form .yucs-btn-wrap{display:inline-block;* display:inline;margin-right:2px;* margin-right:3px;}#yuhead-bd #yuhead-search #yuhead-sform-cont form button:focus,#yuhead-bd #yuhead-search #yuhead-sform-cont form button:active,#yuhead-bd #yuhead-search #yuhead-sform-cont form button::-moz-focus-inner{border:none;-ms-filter:"progid:DXImageTransform.Microsoft.Shadow(Strength=5,Direction=135,Color='#0085C6')";-moz-box-shadow:0 0 5px #0085C6;-webkit-box-shadow:0 0 5px #0085C6;box-shadow:0 0 5px #0085C6;outline:1px dotted transparent;}#yUnivHead #yuhead-hd #yuhead-mepanel-cont{width:43%!important;}li#yuhead-username ul li a img{border:none;vertical-align:middle;padding-right:8px;width:10px;height:10px;}li#yuhead-username ul li a{padding-left:3px;}#yUnivHead .yucs-trending-anim .yucs-trending-anim-fade a{position:relative;}#yUnivHead{height:120px;position:static;z-index:0;min-width:1014px;}#yUnivHead #yuhead-hd ul li.yucs-menu ul{z-index:0;}#yUnivHead .yucs-sethp .pnt{display:none;}#yUnivHead .yucs-trending-anim .yucs-trending-anim-fade{background:transparent;}#yuhead-hd #yuhead-promo div.yucs-trending-anim{float:none;}#yuhead-hd #yuhead-promo{text-align:left;}#yUnivHead #yuhead-bd #yuhead-search{max-width:544px;}#yUnivHead #yuhead-hd #yuhead-right{max-width:544px;}#yuhead-hd #yuhead-com-links-cont{width:310px;}#yuhead-hd #yuhead-promo{width:234px;}#yuhead-bd #yuhead-search #yuhead-sform-cont form button{font-size:13px;overflow:hidden;}#yUnivHead #yuhead-hd ul li.yucs-menu{z-index:1000;}#yUnivHead #yuhead-hd ul li.yucs-menu ul{z-index:2;}li.yucs-notifications{z-index:2;}#yUnivHead li.yucs-notifications .ynotif-ico-bell{background-position:3px -978px;}#yUnivHead.yucs-en-nz .yuhead-logo h2,#yUnivhead.yucs-en-NZ .yuhead-logo h2{margin-top:-3px;}#yUnivHead #yuhead-bd #yuhead-search #yuhead-sform-cont form button{-moz-border-radius:4px;-webkit-border-radius:4px;border-radius:4px;}#yUnivHead #yuhead-bd #yuhead-search #yuhead-sform-cont form .yucs-sprop-btn{*margin-right:-3px;background-color:#f8d44c;background-image:-moz-linear-gradient(top,#FFF4D6,#F7B739);background-image:-webkit-gradient(linear,left top,left bottom,from(#FFF4D6),to(#F7B739));background-image:linear-gradient(top,#FFF4D6,#F7B739);border:1px solid #878787;}#yUnivHead #yuhead-bd #yuhead-search #yuhead-sform-cont form .yucs-sweb-btn{*margin-right:-3px;background-color:#cecece;background-image:-moz-linear-gradient(top,#f7f7f7,#bfbfbf);background-image:-webkit-gradient(linear,left top,left bottom,from(#f7f7f7),to(#bfbfbf));background-image:linear-gradient(top,#f7f7f7,#bfbfbf);border:1px solid #878787;}#yUnivHead #yuhead-bd #yuhead-search #yuhead-sform-cont form .yucs-sweb-btn:hover,#yUnivHead #yuhead-bd #yuhead-search #yuhead-sform-cont form .yucs-sweb-btn:focus{background-color:#949292;background-image:-moz-linear-gradient(top,#f7f7f7,#949292);background-image:-webkit-gradient(linear,left top,left bottom,from(#f7f7f7),to(#949292));background-image:linear-gradient(top,#f7f7f7,#949292);}#yUnivHead #yuhead-bd #yuhead-search #yuhead-sform-cont form .yucs-sprop-btn:hover,#yUnivHead #yuhead-bd #yuhead-search #yuhead-sform-cont form .yucs-sprop-btn:focus{background-color:#E9A436;background-image:-moz-linear-gradient(top,#FFF4D6,#E9A436);background-image:-webkit-gradient(linear,left top,left bottom,from(#FFF4D6),to(#E9A436));background-image:linear-gradient(top,#FFF4D6,#E9A436);}body.rtl #yuhead-hd #yuhead-mepanel-cont{*position:absolute;*right:0;*z-index:10;}body.rtl #yuhead-hd #yuhead-mepanel-cont #yuhead-mepanel li#yuhead-username span.yucs-avatar{*vertical-align:bottom;*float:none;}body.rtl #yuhead-hd #yuhead-mepanel-cont #yuhead-mepanel li#yuhead-username span.yucs-opi{*float:none;}body{margin:0;padding:0;font-family:Arial,Helvetica,sans-serif;font-size:12px;color:#454545}h1,h2,h3,h4,h5,h6,{margin:10px 0;padding:0}p{margin:15px 0;padding:0}table{padding:0}h3{font-size:14px}a{text-decoration:none;color:#234786;outline:0}a:hover{text-decoration:none;color:#3a65bb;outline:0}input[type="text"]:focus,textarea:focus,div:focus,li:focus{outline:0 none}a:focus{outline:0;text-decoration:underline}::-moz-focus-inner{border:0;outline:0}tbody{width:100%}input,textarea{font-family:Arial,Helvetica,sans-serif;font-size:12px;color:#454545}img{border:0}ul{margin:0;padding:0;list-style:none}dt,dd{margin:0}small{font-size:90%}#toolbar{position:relative;min-width:800px;border-bottom:1px solid #d5d5d5;background-color:#e0e0e0}#toolbar div.switcher,#toolbar div.commontasks,#toolbar div.options{float:left;margin:8px 0 0 15px;padding:0}#toolbar div.search{float:left;margin:0;position:relative;vertical-align:middle;width:230px}#toolbar div.switcher{min-width:172px}#toolbar select,#toolbar input{margin:0;vertical-align:middle}#toolbar>.search{float:left;margin:0;width:230px;vertical-align:middle;position:relative}#search-contacts{padding:0 0 0 20px;width:194px;height:18px;border:1px solid #CCC;-webkit-border-radius:3px;-moz-border-radius:3px;border-radius:3px;background:url("/ok/u/assets/sprite/default/16x16/inbox-search-contacts-ltr-47050.png") no-repeat scroll 0 -389px #FFF;font-size:11px;line-height:11px}#search-clear-button{display:none;position:absolute;top:2px;right:15px;width:16px;height:16px;background:url("/ok/u/assets/sprite/default/16x16/inbox-search-contacts-ltr-47050.png") no-repeat scroll 0 -510px #FFF;text-align:center;cursor:pointer}iframe#abIframeTab{margin-left:-1px}.content .inner{margin:25px 24px 22px 23px}#dock{position:fixed;bottom:0;width:100%;height:3px;border-color:#3c0338;background-color:#4c1548;background-image:-moz-linear-gradient(#60205a,#4c1548);background-image:-webkit-gradient(linear,0 top,0 bottom,from(#60205a),to(#4c1548));border-bottom:1px solid;z-index:15;font-size:1px}.selected,.selected a:focus,.selected a:hover,.selected .rht,.yui3-acwidget-selected{background-color:#954a8f!important}.selected,.selected a,.selected span,.yui3-acwidget-selected{color:#FFF!important}.col-a{overflow:hidden;padding:14px 14px 0 17px}.col-b{position:absolute;padding:14px 6px 0 17px;top:0;right:2px}.col-a>div,.col-b>div{margin-bottom:25px}.wide-col{min-width:450px}.wide-col .col-a{max-width:880px}.wide-col .col-b{left:56%;width:300px}div.textwrapper{margin-right:2px;padding:3px 0}div.textwrapper textarea{display:block;padding:2px 0;width:100%;height:100px;border:0;resize:none;border:1px solid #BBB}div.textshorty textarea{height:36px}.rht{position:absolute;top:0;right:0}.lht{position:absolute;top:0;left:0}.inline-items li{display:inline-block;margin-right:1px;margin-bottom:6px;position:relative}.uc{text-transform:uppercase}h2.insider,h2.welcome,h2.list-title{margin:25px 0 4px;padding:0 0 3px;border-bottom:2px solid;font-size:16px}h2.insider{margin-top:0;font-size:12px;clear:left}h2.list-title{margin-top:20px;margin-bottom:20px;font-weight:normal}h2.legend,dt.legend{border-top:1px solid #DDD;border-bottom:1px solid #FFF;font-weight:bold}div.inner h2.legend{margin:30px 0 18px}h2.legend span.label,dt.legend span.label{float:left;margin:-8px 5px 5px;padding:0 5px;background-color:#FFF;font-size:11px;line-height:15px;white-space:nowrap}h2.legend span.rht{margin:-11px 5px 0 0;background-color:#f5f5f5}h6.last-update{float:right;margin:-16px 0 0;padding:0;font-size:11px;font-weight:normal;line-height:13px;color:#999}h6.date-deleted{margin:-12px 0 16px 0;padding:0;font-size:10px;font-weight:normal;line-height:13px;color:#999}p.loading{padding:16px 0 16px 52px;background:transparent url("/ok/u/assets/img/spinner-32x32-anim.gif") no-repeat scroll 50% 6px;text-indent:-9999px}.success{height:16px;margin-bottom:15px;padding-left:24px;background:transparent url("/ok/u/assets/sprite/default/16x16/common-leftrail-ltr-47050.png") no-repeat scroll 0 -840px}.error{color:#cf0505!important}ul.error{margin-bottom:16px;padding:3px 10px;border:1px solid #e3c6c2;background-color:#ffdcd7}ul.error li{margin:3px 0 5px 15px;padding:0;list-style-type:disc}.opi a{padding-left:20px!important;color:#454545;line-height:15px}.photo{float:left;margin:11px 7px 14px 11px;padding:1px;border:1px solid #CCC;background-color:#FFF}.photo img{display:block}.offscreen{position:absolute!important;padding:0!important;border:0!important;height:1px!important;width:1px!important;overflow:hidden;clip:rect(1px 1px 1px 1px);clip:rect(1px,1px,1px,1px)}.divider{padding:0 3px;font-weight:normal;color:#DDD}.box-iso .divider{padding:0 3px;font-weight:normal;color:#AAA}.offset{position:absolute;top:0;right:10px}.borderless{border:0}.timestamp{padding-right:22px;font-size:11px;color:#888;line-height:16px}.ghosted{color:#AAA}.hint{color:#999}.more,.down{padding-right:14px;background:transparent url("/ok/u/assets/sprite/default/16x16/launch-ltr-55366.png") no-repeat 100% -360px;font-size:11px}.down{background-position:100% -390px}.bold{font-weight:bold}.nobold{font-weight:normal}.invisible{visibility:hidden}.visible{visibility:visible}.underlined{padding-bottom:10px!important;border-bottom:1px solid #d5d5d5}.none{font-style:italic;color:#888}.counter{clear:none;margin:2px 5px;padding:1px 12px;-moz-border-radius:10px;-webkit-border-radius:10px;border-radius:10px;background-color:#666;font-size:12px;font-weight:bold;color:#FFF;line-height:14px}.sms-overflow{background-color:#F00!important}.unselectable{-moz-user-select:-moz-none;-khtml-user-select:none;-webkit-user-select:none;-o-user-select:none;user-select:none}.hidden{display:none!important}.yui3-resize-handle{position:absolute;width:16px;height:16px;background:transparent url("/ok/u/assets/sprite/default/16x16/convo-ctrls-yui-ltr.png") no-repeat scroll 0 0}.yui3-resize-handle-br{bottom:1px;right:-1px;background-position:0 -52px;cursor:se-resize}.yui3-widget-hidden{display:none}.yui3-widget-content{overflow:hidden}.yui3-widget-content-expanded{-moz-box-sizing:border-box;-webkit-box-sizing:border-box;-ms-box-sizing:border-box;box-sizing:border-box;height:100%}
.yui3-widget-tmp-forcesize{overflow:hidden!important}.yui3-widget-stacked .yui3-widget-shim{opacity:0;filter:alpha(opacity=0);position:absolute;border:0;top:0;left:0;padding:0;margin:0;z-index:-1;width:100%;height:100%;_width:0;_height:0}.yui3-overlay{position:absolute}.yui3-overlay-hidden{visibility:hidden}.yui3-widget-tmp-forcesize .yui3-overlay-content{overflow:hidden!important}#tgtSKY{width:160px;height:618px}#tgtMNW{height:45px}div.optionMenu,div.colorPickerMenu{display:none;padding:0;border:solid 1px #777;-moz-border-radius:3px;-webkit-border-radius:3px;border-radius:3px;-moz-box-shadow:0 5px 10px rgba(0,0,0,0.25);-webkit-box-shadow:0 5px 10px rgba(0,0,0,0.25);box-shadow:0 5px 10px rgba(0,0,0,0.25);background-color:#f5f5f5;z-index:1;outline:0}div.optionMenu ul,div#menu-tab-overflow div ul{clear:both;padding:9px 0;border-top:1px solid #CCC;*zoom:1}div.optionMenu ul:first-child{border-top:0}div.optionMenu li a{display:block;overflow:hidden;padding:3px 18px;color:#454545;cursor:pointer}div.optionMenu span{float:left}div.nagbar{position:relative;margin-bottom:10px;overflow:hidden;border:1px solid #DDD;border-radius:5px;-moz-border-radius:5px;-webkit-border-radius:5px;background-color:#f5f5f5;background-image:-webkit-gradient(linear,0 top,0 bottom,from(#FFF),to(#EEE));background-image:-moz-linear-gradient(#FFF,#EEE);-webkit-box-shadow:inset 0 0 2px #FFF;-moz-box-shadow:inset 0 0 2px #FFF}div.nagbar.nagbar-lg{max-width:516px;min-width:342px;height:auto}div.nagbar .icn{float:left;width:48px;height:48px;margin:11px}div.nagbar .icn.contact-card{background:url("/ok/u/assets/sprite/default/48x48/inbox-search-contacts-43806.png") no-repeat scroll 50% -420px transparent}div.nagbar h2{color:#582454}div.nagbar p{margin:-15px 10px 15px 0}#preloadsprite{width:20px!important}.l-split{overflow:hidden}.l-split-left{float:left}.l-split-right{float:right}#yUnivHead{background:-moz-linear-gradient(#3c0338,#60205a);background:-webkit-gradient(linear,0 top,0 bottom,from(#3c0338),to(#60205a));background-color:#4c1548}#yuhead-hd #yuhead-mepanel-cont #yuhead-mepanel li.yuhead-me,#yuhead-hd #yuhead-com-links-cont #yuhead-com-links li.yuhead-com-link-item,#yuhead-hd #yuhead-com-links-cont #yuhead-com-links li.yucs-notifications{border-color:#b79db5}#yuhead-bd #yuhead-search #yuhead-sform-cont{position:relative;border-color:#4c1548;background-color:#835980;background-image:-moz-linear-gradient(#b79db5,#835980);background-image:-webkit-gradient(linear,0 top,0 bottom,from(#b79db5),to(#835980));z-index:1}#yUnivHead #yuhead-bd #yuhead-search #yuhead-sform-cont form .yucs-sweb-btn{color:#fff;text-shadow:1px 1px 1px rgba(0,0,0,0.75);border-color:#4c1548;background-color:#60205a;background-image:-webkit-gradient(linear,0 top,0 bottom,from(#954a8f),to(#60205a));background-image:-moz-linear-gradient(#954a8f,#60205a);filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#954A8F,endColorstr=#60205A))}#yUnivHead #yuhead-bd #yuhead-search #yuhead-sform-cont form .yucs-sweb-btn:hover,#yUnivHead #yuhead-bd #yuhead-search #yuhead-sform-cont form .yucs-sweb-btn:focus{background-color:#3c0338;background-image:-moz-linear-gradient(#954a8f,#3c0338);background-image:-webkit-gradient(linear,0 top,0 bottom,from(#954a8f),to(#3c0338));filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#954A8F,endColorstr=#3C0338))}#yUnivHead .yuhead-bullet-down{background-position:100% -119px}#yUnivHead .yuhead-ico-mail{background-position:0 -915px}#yUnivHead .yuhead-ico-home{background-position:0 -854px}#yUnivHead .yuhead-ico-bell,#yUnivHead .ynotif-ico-bell{background-position:0 -978px}#yUnivHead,#yUnivHead a,#yUnivHead a:hover,.yuhead-logo h2 a{color:#fff}#yuhead-hd{padding:12px 16px 12px 10px}#yuhead-bd{padding:0 14px 12px}#yUnivHead #yuhead-promo .yucs-promo-label,#yUnivHead #yuhead-promo a,#yUnivHead #yuhead-promo a:hover{color:#fff}.yucs-fh{background:0}.nav-bar{position:fixed;top:90px;left:0;right:0;width:100%;height:30px;z-index:0;background-color:#3c0338}.nav-bar .tabs{padding-left:16px;padding-right:160px;left:0;right:0}.tabclose{cursor:pointer}.tabs{position:absolute;bottom:0;font-size:11px}.tabs ul{margin:0;padding:0;list-style:none;position:absolute;bottom:0;max-height:38px}.tablist:focus{outline:0}.tabs li{position:relative;top:5px;float:left;margin-left:-1px;max-width:170px;height:34px;border:1px solid;border-color:#b79db5;background-color:#60205a;background-image:-webkit-gradient(linear,0 top,0 bottom,from(#954a8f),to(#60205a));background-image:-moz-linear-gradient(#954a8f,#60205a);filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#954A8F,endColorstr=#60205A));font-weight:bold;z-index:0}.tabs li a:hover,.tabs li a:focus{background-color:#3c0338;background-image:-moz-linear-gradient(#954a8f,#3c0338);background-image:-webkit-gradient(linear,0 top,0 bottom,from(#954a8f),to(#3c0338));text-decoration:none}.tabs .active a:focus{text-decoration:underline}.tabs li a{display:block;padding:10px 0 7px 14px;color:#FFF;text-shadow:rgba(0,0,0,.25) 1px 1px 1px;-webkit-font-smoothing:antialiased}.tabs li b{display:block;overflow:hidden;margin-right:20px;white-space:nowrap;font-weight:bold;text-overflow:ellipsis;cursor:pointer}.tabs li i{font-weight:normal;font-style:normal}.tabs .unremovable b{margin-right:0;text-align:center}.tabs .unremovable a{padding-right:14px}.tabs .active,.tabs .active>a:hover,.tabs .active>a:focus,.tabs .yui3-tab-selected{display:block;top:1px;border-bottom:0;-moz-border-radius:5px 5px 0 0;-webkit-border-top-left-radius:5px;-webkit-border-top-right-radius:5px;border-radius:5px 5px 0 0;-webkit-background-clip:padding-box;border-color:#FFF;background-color:#e0e0e0;background-image:-moz-linear-gradient(#FFF,#e0e0e0);background-image:-webkit-gradient(linear,0 top,0 bottom,from(#FFF),to(#e0e0e0));filter:none;z-index:1}.tabs .active>a,.tabs .yui3-tab-selected>a{padding-top:14px;color:#454545;text-shadow:1px 1px 1px rgba(255,255,255,0.75)}.tabs li>span{visibility:hidden;position:absolute;top:10px;right:2px;width:15px;height:15px;cursor:pointer;text-indent:-9999px}.tabs li:hover>span{visibility:visible;background:url("/ok/u/assets/sprite/default/16x16/common-leftrail-ltr-47050.png") no-repeat scroll 0 -362px transparent}.tabs .active:hover>span{top:14px;background-position:0 -332px}.tabs .tab-overflow a span{margin:-10px 0 0 -14px;height:24px;width:20px;display:block;background:url("/ok/u/assets/sprite/default/16x16/common-leftrail-ltr-47050.png") no-repeat scroll 50% -263px transparent}.tabs .compose span{display:none}.btn{display:-moz-inline-box;display:inline-block;position:relative;padding:0;height:auto;border:1px solid #ddd;border-left:0;background-color:#f7f7f7;background-image:-webkit-gradient(linear,0 top,0 bottom,from(#FFF),to(#e6e6e6));background-image:-moz-linear-gradient(#FFF,#e6e6e6);filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#FFFFFF,endColorstr=#E6E6E6));cursor:pointer;vertical-align:middle;-webkit-text-stroke:1px transparent;line-height:13px}.btn input,.btn a{display:block;padding:4px 11px 3px;margin:0;border:0;background-color:transparent;color:#454545;font-family:Arial,Helvetica,sans-serif;cursor:pointer}.btn>input[type="button"]{-webkit-user-select:none}.btn input:hover,.btn a:hover{color:#454545;text-decoration:none;background-color:#EEE}.btn a:hover{background-image:-webkit-gradient(linear,0 top,0 bottom,from(#FFF),to(#cbcbcb));background-image:-moz-linear-gradient(#FFF,#cbcbcb)}.btn input{overflow:visible}.btn i{font-style:normal}.small input{width:20px;height:16px}.btn input:focus,.btn a:focus,.btn a:active,.btn input:active,.message-header .flag a:focus,.message-header .flag a:active,.file-attach li:focus,.attachment-button-form span.focused,.pod:focus{text-decoration:none;outline:1px dotted #333;outline:1px dotted rgba(0,0,0,0);-webkit-box-shadow:0 0 5px #0085c6;-moz-box-shadow:0 0 5px #0085c6;box-shadow:0 0 5px #0085c6}::moz-inner-focus{border:0;outline:0}.left{border-left:1px solid #ddd}div.left,span.left,span.left a{-moz-border-radius-topleft:4px;-moz-border-radius-bottomleft:4px;-webkit-border-bottom-left-radius:4px;-webkit-border-top-left-radius:4px;-webkit-background-clip:padding-box;border-bottom-left-radius:4px;border-top-left-radius:4px}div.right,span.right,span.right a{-moz-border-radius-topright:4px;-moz-border-radius-bottomright:4px;-webkit-border-bottom-right-radius:4px;-webkit-border-top-right-radius:4px;-webkit-background-clip:padding-box;border-bottom-right-radius:4px;border-top-right-radius:4px}span.disabled{color:#8999b9;opacity:.60;filter:alpha(opacity=60)!important;cursor:default}span.disabled a:hover{background-color:#f7f7f7;background-image:-webkit-gradient(linear,0 top,0 bottom,from(#FFF),to(#e6e6e6));background-image:-moz-linear-gradient(#FFF,#e6e6e6);filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#FFFFFF,endColorstr=#E6E6E6)) progid:DXImageTransform.Microsoft.DropShadow(Color='white',OffX=0,OffY=0)}span.disabled a,span.disabled input{cursor:default}.btn.menu.pressed{background-color:#f7f7f7;background-image:-webkit-gradient(linear,0 top,0 bottom,from(#cbcbcb),to(#FFF));background-image:-moz-linear-gradient(#cbcbcb,#FFF);color:#454545;z-index:2}.small a{margin:0;padding:2px 8px 3px;font-size:12px;line-height:12px}.small input{padding:1px}span.default{border-color:#e8ac47}span.default a{background-color:#fbd27e;background-image:-webkit-gradient(linear,0 top,0 bottom,from(#fff4d6),to(#f7b739));background-image:-moz-linear-gradient(#fff4d6,#f7b739);filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#FFF4D6,endColorstr=#F7B739) progid:DXImageTransform.Microsoft.DropShadow(Color='white',OffX=0,OffY=0);color:#333}span.default a:hover{background-color:#f2c46c;background-image:-webkit-gradient(linear,0 top,0 bottom,from(#fff4d6),to(#e9a436));background-image:-moz-linear-gradient(#fff4d6,#e9a436);filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#FFF4D6,endColorstr=#E9A436) progid:DXImageTransform.Microsoft.DropShadow(Color='white',OffX=0,OffY=0)}span.default,span.default>input{font-weight:bold}span.default.disabled a:hover{background-color:#fbd27e;background-image:-webkit-gradient(linear,0 top,0 bottom,from(#fff4d6),to(#f7b739));background-image:-moz-linear-gradient(#fff4d6,#f7b739);filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#FFF4D6,endColorstr=#F7B739) progid:DXImageTransform.Microsoft.DropShadow(Color='white',OffX=0,OffY=0)}span.btn a.icon{padding:0}.btn .icon i{display:block;padding:3px 10px;width:1px;background:url("/ok/u/assets/sprite/default/16x16/launch-ltr-55366.png") no-repeat 50% -100%;text-indent:-9999px}.shaded .btn .icon i{padding:3px 15px}input.icon{padding-left:7px;padding-right:7px;background:url("/ok/u/assets/sprite/default/16x16/launch-ltr-55366.png") no-repeat 50% -100%;text-indent:-9999px}.btn input.icon{*padding-left:30px}.shaded .lg .icon i{padding:3px 19px}.btn .next i{background:url("/ok/u/assets/sprite/default/16x16/common-leftrail-ltr-47050.png") no-repeat scroll 50% -448px}.btn .prev i{background:url("/ok/u/assets/sprite/default/16x16/common-leftrail-ltr-47050.png") no-repeat scroll 50% -478px}.btn .icon b{position:absolute;right:4px;top:5px}.btn>.icon-text{padding:0}.btn>.icon-text>i{display:block;margin-left:3px;padding:2px 8px 3px 18px}span.menu b{display:inline-block;width:12px;height:12px;background:url("/ok/u/assets/sprite/default/16x16/launch-ltr-55366.png") no-repeat 0 -392px;text-indent:-9999px;vertical-align:middle}span.split-menu a{padding:4px 5px 3px 0}.shaded .btn{margin:0;height:20px;border:1px solid;border-color:#c8c8c8 #414141 #9d9c9c #666666;border-width:0 1px;background-color:#343434;background-image:-moz-linear-gradient(#494949,#1f1f1f);background-image:-webkit-gradient(linear,0 top,0 bottom,from(#4a4a4a),to(#1f1f1f));filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#4a4a4a,endColorstr=#1f1f1f));-webkit-box-shadow:0 1px 0 #AAA;-moz-box-shadow:0 1px 0 #AAA;text-shadow:rgba(0,0,0,0.25) 0 1px 1px 0}.shaded .btn a{font-size:11px;font-weight:bold;color:#FFF;text-shadow:rgba(0,0,0,.50) 1px 1px 1px}.shaded .btn a:hover{background-color:#4e4e4e;background-image:-moz-linear-gradient(#919191,#4e4e4e);background-image:-webkit-gradient(linear,0 top,0 bottom,from(#919191),to(#4e4e4e));filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#919191,endColorstr=#4e4e4e))}.shaded .disabled{filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#4a4a4a4a,endColorstr=#333333)),alpha(opacity=75)}.shaded .btn.disabled a:hover{background-color:#343434;background-image:-moz-linear-gradient(#494949,#1f1f1f);background-image:-webkit-gradient(linear,0 top,0 bottom,from(#4a4a4a),to(#1f1f1f));filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#4a4a4a,endColorstr=#1f1f1f))}
.shaded .left{border-left:none}.shaded .right{margin-right:7px;border-right:0}.shaded .menu b{background-position:0 -931px}button.lg{width:102px}button.md{width:72px}button.sm{width:52px}.btn input.check-mail,.btn input.check-updates,.btn input.check-notifications{background-position:50% -268px}.btn input.trash,.btn .trash i{background-position:50% -299px}.btn input.add,.btn .add i{background-position:50% -330px}.btn input.edit{background-position:50% -418px}.btn input.remove,.btn .remove{background:url("/ok/u/assets/sprite/default/16x16/common-leftrail-ltr-47050.png") no-repeat scroll 50% -30px transparent!important}.btn input.conn{background-position:50% -1229px}.btn.small input.loading{background:transparent url("/ok/u/assets/img/spinner-12x12-anim-19370.gif") no-repeat scroll 50% 2px!important}.btn input.down{background-position:50% -1499px}.btn input.up{background-position:50% -1529px}.rte-pane .icon i{background-image:url("/ok/u/assets/sprite/default/16x16/rich-text-editor-ltr-47050.png");background-repeat:no-repeat;background-position:50% -100%}.btn .bold i{background-position:60% -149px}.btn .italic i{background-position:50% -179px}.btn .underline i{background-position:50% -208px}.btn .color i{background-position:60% -239px}.btn .highlight i{background-position:40% -268px}.btn .align-l i{background-position:40% -298px}.btn .indent i{background-position:30% -387px}.btn .bulletlist i{background-position:30% -418px}.btn .spell i{background-position:50% -479px}.btn .link i{background-position:50% -537px}.btn .change_ltr i{background-position:50% -658px}.btn .change_rtl i{background-position:50% -628px}.btn .search-contacts{background:transparent url("/ok/u/assets/sprite/default/16x16/inbox-search-contacts-ltr-47050.png") no-repeat scroll 50% -118px}.lozenge,.search-nav li .refine a:hover{max-width:380px;border-color:#afbfcf;background-color:#d2e0ee;background-image:-moz-linear-gradient(#e9f4ff,#d2e0ee);background-image:-webkit-gradient(linear,0 top,0 bottom,from(#e9f4ff),to(#d2e0ee));filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#E9F4FF,endColorstr=#D2E0EE));z-index:1}.lozenge a{white-space:nowrap;overflow:hidden;text-overflow:ellipsis}.lozengeadd a{background:transparent url("/ok/u/assets/sprite/default/16x16/inbox-search-contacts-ltr-47050.png") no-repeat scroll 50% -271px}.lozengeContainer.pressed .lozengeadd a{background:transparent url("/ok/u/assets/sprite/default/16x16/inbox-search-contacts-ltr-47050.png") no-repeat scroll 50% -1321px}.lozenge a:hover,.lozengeremove a:hover,.lozengeretry a:hover{background-color:#b1c2d3;background-image:-moz-linear-gradient(#d6e4f1,#b1c2d3);background-image:-webkit-gradient(linear,0 top,0 bottom,from(#d6e4f1),to(#b1c2d3))}.lozengeadd a:hover{background-color:#b1c2d3;background:url("/ok/u/assets/sprite/default/16x16/inbox-search-contacts-ltr-47050.png") no-repeat scroll 50% -271px,-moz-linear-gradient(#d6e4f1,#b1c2d3) repeat scroll 0 0 #b1c2d3;background:url("/ok/u/assets/sprite/default/16x16/inbox-search-contacts-ltr-47050.png") no-repeat scroll 50% -271px,-webkit-gradient(linear,0 top,0 bottom,from(#d6e4f1),to(#b1c2d3)) repeat scroll 0 0 #b1c2d3}.lozengeContainer.pressed .lozengeadd a:hover{background:transparent url("/ok/u/assets/sprite/default/16x16/inbox-search-contacts-ltr-47050.png") no-repeat scroll 50% -1321px}.lozengeremove,.lozengeretry{border-color:#afbfcf;background-color:#c2cfdc;background-image:-moz-linear-gradient(#deebf8,#c2cfdc);background-image:-webkit-gradient(linear,0 top,0 bottom,from(#deebf8),to(#c2cfdc));filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#deebf8,endColorstr=#c2cfdc))}span.lozengeerror{background-color:#f91d1d;background-image:-moz-linear-gradient(#f9afaf,#f91d1d);background-image:-webkit-gradient(linear,0 top,0 bottom,from(#f9afaf),to(#f91d1d));filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#F9AFAF,endColorstr=#F91D1D));border-color:#d98888 #DF3939 #df3939}.lozengeerror-remove{background-color:#cd2020;background-image:-moz-linear-gradient(#f19292,#cd2020);background-image:-webkit-gradient(linear,0 top,0 bottom,from(#f19292),to(#cd2020));filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#F19292,endColorstr=#CD2020));border-color:#d98888 #DF3939 #df3939}.lozengeerror a:hover,.lozengeerror-remove a:hover{background-color:#e11a1a;background-image:-moz-linear-gradient(#f99999,#e11a1a);background-image:-webkit-gradient(linear,0 top,0 bottom,from(#f99999),to(#e11a1a));filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#F99999,endColorstr=#E11A1A));border-color:#d98888 #DF3939 #df3939}.items-nav li .lozengeremove a,.items-nav li .lozengeretry a{margin:0;padding-left:14px!important}.lozengeremove b{position:absolute;height:18px;width:20px;left:0;top:0;background:transparent url("/ok/u/assets/sprite/default/16x16/inbox-search-contacts-ltr-47050.png") no-repeat scroll 50% -510px!important}.lozengeerror a{color:#FFF!important}.lozengeerror b,.lozengeerror-remove b{top:0;left:0;background:url("/ok/u/assets/sprite/default/16x16/common-leftrail-ltr-47050.png") no-repeat scroll 50% -359px transparent!important}.lozengeretry b{position:absolute;height:16px;width:16px;left:0;top:0;background:transparent url("/ok/u/assets/sprite/default/16x16/inbox-search-contacts-ltr-47050.png") no-repeat scroll 50% -1380px!important}.search-nav .lozengeremove b,.search-nav .lozengeremove b{top:2px;left:2px}.lozengeContainer.pressed a{-moz-box-shadow:none;-webkit-box-shadow:none;outline:0;box-shadow:none}#btn-new a,#btn-reply a,#btn-conv-reply a,span.attach-btn-menu a{padding:4px 11px 3px 5px}#btn-spell-langs a{padding:4px 6px 3px 0}#btn-ml-preview i,#btn-ml-prev i{margin:0 6px 0 10px;background-position:0 -1347px}#btn-delete i,#btn-rpy i,#btn-reply-all i,#btn-forward i,#btn-spam i,#btn-thread i,#btn-print i{background:url("/ok/u/assets/sprite/default/16x16/launch-ltr-threading-59273.png") no-repeat 50% -100%}#btn-delete i{background-position:50% -1556px}#btn-rpy i{background-position:50% -1466px}#btn-reply-all i{background-position:50% -1496px}#btn-forward i{background-position:50% -1526px}#btn-spam i{background-position:50% -1586px}#btn-thread i{background-position:50% -1617px}#btn-print i{background-position:50% -1646px}#btn-actions i,#btn-conv-actions i,#btn-msg-actions i{margin:0 6px 0 10px;background-position:0 -1407px}#btn-move i{margin:0 6px 0 10px;background-position:0 -1377px}
#pagetoolbar .btn .icon b{right:9px}.btn.pressed,.btn.pressed a:hover{border-color:#c0c0c0;background-color:#cacaca;background-image:-webkit-gradient(linear,0 top,0 bottom,from(#c0c0c0),to(#e0e0e0));background-image:-moz-linear-gradient(#c0c0c0,#e0e0e0);filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#C0C0C0,endColorstr=#E0E0E0))}.btn.pressed a,.lozenge.pressed a,.lozengeContainer.pressed .lozenge a{color:#FFF}.ac-input .focus span,.message-header .pressed span,.lozenge.pressed,.hdr-info .lozenge.pressed a:hover,.lozengeContainer.pressed a:hover{border-color:#888;background-color:#666;background-image:-moz-linear-gradient(#333,#666);background-image:-webkit-gradient(linear,0 top,0 bottom,from(#333),to(#666));filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#333333,endColorstr=#666666))}.shaded .btn.pressed,.shaded .btn.pressed a:hover{border-color:#858585 #373737 #9a9a9a #5D5D5D;background-color:#000;background-image:-moz-linear-gradient(#000,#262626);background-image:-webkit-gradient(linear,0 top,0 bottom,from(#000),to(#262626));filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#000000,endColorstr=#262626))}.shaded .btn.pressed a{color:#FFF}.items{position:relative;clear:both;margin:0 0 10px;padding:0}.items>ul>li>a{overflow:hidden;text-overflow:ellipsis;white-space:nowrap}.items h2{margin:0 5px 0 12px}.items h2 span.label{background-color:#f5f5f5!important}.items ul,.items ol{position:relative;clear:left;margin:0;margin-bottom:8px;padding:0;list-style:none}.items li{position:relative;clear:both;margin:1px;padding:0;overflow:hidden;background-color:#f5f5f5}.items li>a:hover,.items li>a:focus,.items li>a:hover .rht,.items li>a:focus .rht,.items li.popping,.items li.popping .rht{background-color:#e0e0e0;text-decoration:none}.items li.yui3-dd-drop-over{background-color:#e0e0e0}li.cntxtmenu a,li.cntxtmenu .rht{background-color:#e0e0e0}.items .rht{margin:0 4px 0 0;padding:2px 0 0 5px;line-height:16px;font-size:11px;color:#454545;background-color:#f5f5f5}.items li i{font-style:normal;display:block;overflow:hidden;text-overflow:ellipsis;white-space:nowrap}.items-nav{margin-bottom:14px}.items-first{margin-bottom:8px}.items-nav li>a,.items-list li>a{color:#454545}.items-nav div,.items-list div{margin:5px 10px;padding:0}.items div.nav-ft{position:relative;margin-top:15px;padding:3px 0;font-weight:bold}.items-list li>a{display:block;margin:0 10px;padding:3px 0}.items-coun li>a{padding-right:10px}.items-nav h2 span.label{margin-left:16px}.items-nav li>a{display:block;margin:0;padding:3px 5px}.items-nav li i{margin:0 30px 0 7px;padding:1px 0 1px 20px;text-align:left;background:transparent url("/ok/u/assets/sprite/default/16x16/launch-ltr-55366.png") no-repeat 0 -100%}.items-nav-nogutter li i{margin-right:0}.items-nav .sm li>a{margin-left:5px;padding-left:22px}.items-nav-msgr-contacts li a em,#menu-uh-account .opi a{padding-left:20px;background:transparent url("/ok/u/assets/sprite/default/16x16/opis-mode-ltr.png") no-repeat 0 -100%}.items-nav-msgr-contacts li a em{padding-top:3px;font-style:normal}.items-nav li{padding:0}.items-nav li a div{margin:0;color:#888}.items-nav li.stealth{opacity:.6;-ms-filter:"alpha(opacity=50)";filter:alpha(opacity=50)}.items-nav li img{float:left;margin:-1px 0 0;padding:1px;border:1px solid #DDD;background-color:#FFF}.items-nav .sm li img,.items-nav .sm li span.vitality,.items-nav .med li span.vitality{display:none}.items-nav .lg li span{display:block;margin-top:-1px;padding:0 0 3px 20px;overflow:hidden;font-size:11px;color:#888;text-overflow:ellipsis;white-space:nowrap}.items-nav li span.unread-count{position:relative;top:2px;padding-right:3px}.items-nav li.in span.unread-count{top:1px}.items-nav-applications li i{background-position:0 0;background-repeat:no-repeat;background-image:none}.collapsed h2 span.label,.expanded h2 span.label{margin-left:0!important;padding-left:21px!important;overflow:hidden;max-width:67%;background:url("/ok/u/assets/sprite/default/16x16/launch-ltr-55366.png") no-repeat;-webkit-user-select:none;cursor:pointer}.expanded h2 span.label{background-position:0 -390px}.collapsed h2 span.label{margin-bottom:0;background-position:0 -360px}.collapsed ul{display:none}.collapsed>*{display:none}.collapsed>:first-child{display:block;margin-bottom:20px}.items .has-unread{font-weight:bold}.items .has-unread a i{margin-right:18px;text-overflow:ellipsis}.items .has-unread .x-gap i{margin-right:43px}li.trash a,li.trash span,li.spam a,li.spam span{font-weight:normal}li.in i{background-position:0 -89px}li.chats i{background-position:0 -1198px}li.drafts i{background-position:0 -119px}li.sent i{background-position:0 -149px}li.spam i{background-position:0 -179px}li.trash i{background-position:0 -209px}li.folder i{background-position:0 -240px;text-align:left}li.contacts i{background-position:0 -1140px}li.emails-contacts i{background-position:0 -1440px}li.attachments i{background-position:0 -1500px}li.photos i{background-position:0 -1500px}li.updates i{background-position:0 -1290px}li.flagged i{background-position:0 -32px!important}li.replied i{background-position:0 -208px!important}li.forwarded i{background-position:0 -241px!important}li.unread i{background-position:0 -901px!important}li.email i{background-position:0 0!important}li.im i{background-position:0 -28px!important}li.sms i{background-position:0 -90px!important}li.group i{background-position:0 -58px!important}li.voice i{background-position:0 -120px!important}li.video i{background-position:0 -150px!important}li.phone i{background-position:0 -180px!important}li.calendar i{background-position:0 -1170px}li.notes i{background-position:0 -30px}li.flickr i{background-position:0 -270px}li.answers i{background-position:0 -302px}li.large-attachments i{background-position:0 -392px}li.automatic-organizer i{background-position:0 -330px}li.photo-editor i{background-position:0 -452px}li.evite i{background-position:0 -360px}li.paypal i{background-position:0 -482px}li.ping-invitations i{background-position:0 -422px}.items-nav-applications .calendar a{background-position:0 1px}.ymsg-available a,.ymsg-available span,.ymsg-available em,b.ymsg-available{background-position:0 3px!important}.ymsg-away a,.ymsg-away span,.ymsg-away em,b.ymsg-away{background-position:0 -27px!important}.ymsg-busy a,.ymsg-busy span,.ymsg-busy em,b.ymsg-busy{background-position:0 -57px!important}.ymsg-offline a,.ymsg-offline span,.ymsg-offline em,b.ymsg-offline{background-position:0 -88px!important}.ymsg-invisible a,.ymsg-invisible span,.ymsg-invisible em{background-position:0 -88px!important}.icn .yim-conv span{background-image:none;padding-left:0}.ymsg-mobile a,.ymsg-mobile span,.ymsg-mobile em,b.ymsg-mobile{background-position:0 -238px!important}.ymsg-quiet a,.ymsg-quiet span,.ymsg-quiet em,b.ymsg-quiet{background-position:0 -148px!important}.ymsg-video a,.ymsg-video span,.ymsg-video em,b.ymsg-video{background-position:0 -178px!important}.ymsg-voice a,.ymsg-voice span,.ymsg-voice em,b.ymsg-voice{background-position:0 -208px!important}b.ymsg-phone{background-position:0 -418px!important}input.renamer{position:absolute;top:-999px;left:-999px;width:auto;height:14px;border:1px solid #DDD;outline:0;z-index:10}ul.bullet{list-style-type:disc}
ul.bullet li{margin:5px 15px}.entries li{position:relative;margin:0;padding:8px 0 5px 48px;overflow:hidden}.entries li.no-indent{padding-left:0}.entries div{margin-bottom:11px}.entries div div{margin-bottom:0}.entries .photo{position:absolute;top:9px;left:0;margin:0;padding:0;border:0 none}.entries .photo img{padding:1px;width:32px;height:32px;border:1px solid #ccc}.entries h3{margin:0;font-size:12px}.entries .action{font-size:11px}.more-entries{text-align:right}.updates.entries li{border-bottom:1px solid #DDD}.updates.entries li.last{border:0}.updates li{position:relative;clear:left;border-bottom:1px solid #DDD}.updates .timestamp{position:absolute;top:8px;right:0}.updates .update-entry{margin:0 110px 10px 0}.updates .author{font-weight:bold}.replies{margin:10px 0;padding:0 10px;border:1px solid #DDD;-moz-border-radius:5px;-webkit-border-radius:5px;border-radius:5px;background-color:#f5f5f5;list-style:none}.replies li{margin:0;padding-top:10px;overflow:hidden;border-top:1px solid #FFF!important;border-bottom:none!important}.replies .action{padding:10px 0;border-bottom:1px solid #DDD}.replies .overline{border-top:1px solid #FFF}.replies .response{padding:7px 0}.replies .timestamp{padding-left:24px}.replies textarea{padding:3px}.story{margin:0!important;overflow:hidden}.story .photo{float:left;margin:0 10px 10px 0!important;max-width:150px}.story img{max-height:150px;max-width:150px}.story h4{margin-top:0;margin-bottom:0}.story h4 a{font-weight:bold}.story h4 span{font-weight:normal}.story h5{margin-top:0;font-size:11px;font-weight:normal}.story-feature{background-color:#fff}.story-feature h4{margin-bottom:10px}.story .dateline{text-transform:uppercase}.show{margin:0 0 8px 0;padding:0;overflow:hidden;font-size:11px;list-style:none}.show li{float:left;padding:3px 0}.show li a{display:block;padding:3px 9px;border-left:1px solid #d5d5d5;font-weight:bold}.show .first a{padding-left:0;border:0}.show .active{background:url("/ok/u/assets/sprite/default/16x16/launch-ltr-55366.png") no-repeat scroll 50% -375px transparent}.show .active a{color:#454545}.show .last{float:right}.messages{margin:2px 0}.messages li{margin:0;padding:0}.messages li a{padding:0 5px 0 23px;background:transparent url("/ok/u/assets/sprite/default/16x16/launch-ltr-55366.png") no-repeat 0 -450px;line-height:18px}.partner-yahoo{background:transparent url("/ok/u/assets/sprite/default/16x16/partner-logos-ltr.png") no-repeat scroll 100% -60px}.partner-facebook{background:transparent url("/ok/u/assets/sprite/default/16x16/partner-logos-ltr.png") no-repeat scroll 100% -180px}.partner-twitter{background:transparent url("/ok/u/assets/sprite/default/16x16/partner-logos-ltr.png") no-repeat scroll 100% -210px}div.card-sm .partner-yahoo,div.card-md .partner-yahoo{background:transparent url("/ok/u/assets/sprite/default/16x16/partner-logos-ltr.png") no-repeat scroll 0 -60px}div.card-sm .partner-facebook,div.card-md .partner-facebook{background:transparent url("/ok/u/assets/sprite/default/16x16/partner-logos-ltr.png") no-repeat scroll 0 -180px}div.card-sm .partner-twitter,div.card-md .partner-twitter{background:transparent url("/ok/u/assets/sprite/default/16x16/partner-logos-ltr.png") no-repeat scroll 0 -210px}.items-nav-contacts li a i{background:transparent url("/ok/u/assets/sprite/default/16x16/common-leftrail-ltr-47050.png") no-repeat 0 -1140px}.items-nav-contacts .legend{margin:-3px 5px 2px 12px}.contacts-smart a i{background-position:0 -1290px;line-height:14px}li.no-custom-lists{padding-left:10px;color:#666}li.contacts-short a i{background:transparent url("/ok/u/assets/sprite/default/16x16/inbox-search-contacts-ltr-47050.png") no-repeat 0 -661px!important}li.contacts-suggested a i{background:transparent url("/ok/u/assets/sprite/default/16x16/inbox-search-contacts-ltr-47050.png") no-repeat 0 -1351px!important}.contacts-lists a i,.contacts-lists div.lists-bg{background:transparent url("/ok/u/assets/sprite/default/16x16/inbox-search-contacts-ltr-47050.png") no-repeat 0 -690px!important}.contacts-lists div.lists-bg{display:none;padding:0 0 0 19px;margin-left:8px;background-position:0 -691px}.lists-bg input{color:#3e3e3e!important;border:1px solid #d9d9d9;margin:-2px 0;height:16px;width:95px}.items-contacts{padding:12px 0}.items-contacts li{position:relative;clear:left;padding:5px 0 8px 16px}.items-contacts li input{position:absolute;top:5px;left:4px;margin:0}.items-contacts li img{display:block;float:left;margin:0 2px 0 6px;padding:1px;border:1px solid #DDD}.items-contacts li span{display:block;margin:0 0 0 46px;line-height:14px;cursor:default}.items-contacts li span a{display:block;font-size:11px}.nophoto li span{margin-left:8px}.services{margin-bottom:25px}.services li{clear:left;margin:10px 0;padding-bottom:10px;overflow:hidden;border-bottom:1px solid #d5d5d5}.services .icon-lg,li.contacts-lists a,.external li a{background:url("/ok/u/assets/sprite/default/48x48/import-logos-ltr.png") no-repeat scroll 50% -100%}.services .global,.services .clean,.services .compose,.services .create-list,.services .delete,.services .address,.services .sync{background:url("/ok/u/assets/sprite/default/48x48/inbox-search-contacts-ltr.png") no-repeat scroll 50% -100%}.services .icon-lg{float:left;margin-top:10px;width:48px;height:48px;border:0}.services p{margin-left:60px!important}.services .global{background-position:0 -559px}.services .clean{b
Title: Re: resource:///components/nsSessionStore.js:402
Post by: SuperDave on February 29, 2012, 05:33:43 PM
Quote
Any advice on what to do?
Sorry. I really know very little about this problem.
Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on March 01, 2012, 02:51:51 AM
Many thanks for all this help. What happened is ESET was taking more than 11 hours and it said it had done 31% when it seemed to suddenly finish but it said stopped by user. I am not aware of having done anything to stop it. Should I run it again

I copy and paste below the logs in case you need them and/or are helpful for your to tell me whether to rerun it or not

The First of them


C:\Program Files (x86)\Bandoo\Plugins\MSN\msnplugin.dll   a variant of Win32/Adware.Bandoo.AA application   cleaned by deleting - quarantined
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\qlipso-qlipso-silent-us.exe   a variant of Win32/Toolbar.Zugo application   deleted - quarantined
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\qlps-qlipso-sntb.exe   Win32/Toolbar.Zugo application   deleted - quarantined
C:\Users\marina\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JPDCB8CW\index[1].htm   HTML/Refresh.AU trojan   cleaned by deleting - quarantined
C:\Users\marina\AppData\Roaming\Mozilla\Firefox\Profiles\2y9b2iki.default\extensions\[email protected]\chrome
\content\overlay.js   Win32/Adware.GamePlayLabs application   cleaned by deleting - quarantined

The other


ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=fd4075455707dc41b5e12f71c4ce925b
# end=stopped
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-03-01 09:30:03
# local_time=2012-03-01 09:30:03 (+0000, GMT Standard Time)
# country="United Kingdom"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=3584 16777215 100 0 0 0 0 0
# compatibility_mode=5893 16776574 100 94 17579729 83017256 0 0
# compatibility_mode=8192 67108863 100 0 25680060 25680060 0 0
# scanned=294997
# found=5
# cleaned=5
# scan_time=41997
C:\Program Files (x86)\Bandoo\Plugins\MSN\msnplugin.dll   a variant of Win32/Adware.Bandoo.
AA application (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\qlipso-qlipso-silent-us.exe   
a variant of Win32/Toolbar.Zugo application (deleted - quarantined)   00000000000000000
000000000000000   C
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\qlps-qlipso-sntb.exe   Win32/Toolbar.
Zugo application (deleted - quarantined)   00000000000000000000000000000000   C
C:\Users\marina\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.
IE5\JPDCB8CW\index[1].htm   HTML/Refresh.AU trojan (cleaned by deleting - quarantined)   00000
000000000000000000000000000   C
C:\Users\marina\AppData\Roaming\Mozilla\Firefox\Profiles\2y9b2iki.default\extensions\[email protected]\chrome\c
ontent\overlay.js   Win32/Adware.GamePlayLabs application (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
Title: Re: resource:///components/nsSessionStore.js:402
Post by: SuperDave on March 01, 2012, 11:59:22 AM
That looks good. Other than the other problems you mentioned before, how's your computer working now?
Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on March 01, 2012, 03:47:00 PM
I think it is faster although it is not great either.

I am rerunning the ESAT scan and after 4,5 hours it has scanned 29% and has found one threat

I will wait for you to give me the OK in terms of spywares and then will try to fix the script and CPU issue.

Many thanks!
Title: Re: resource:///components/nsSessionStore.js:402
Post by: SuperDave on March 01, 2012, 07:10:45 PM
You're welcome. Now we should do some cleanup.

To uninstall ComboFix

(http://i424.photobucket.com/albums/pp322/digistar/Combofix_uninstall_image.jpg)

(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

*****************************************************
To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
******************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer (http://oldtimer.geekstogo.com/TFC.exe) to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
*****************************************************
Use the Secunia Software Inspector (http://secunia.com/software_inspector) to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update (http://windowsupdate.microsoft.com/) and get all critical updates.

----------

I suggest using WOT - Web of Trust (http://www.mywot.com/). WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster (http://www.javacoolsoftware.com/spywareblaster.html)- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer (http://www.bleepingcomputer.com/forums/tutorial49.html) from Spyware and Malware
* If you don't know what ActiveX controls are, see here (http://www.webopedia.com/TERM/A/ActiveX_control.html)

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. (http://www.safer-networking.org/en/spybotsd/index.html) Guide: Use Spybot's Immunize Feature (http://www.bleepingcomputer.com/tutorials/tutorial43.html#immunize) to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ (http://www.safer-networking.org/en/faq/index.html)

Check out Keeping Yourself Safe On The Web  (http://evilfantasy.wordpress.com/2008/05/20/keeping-yourself-safe-on-the-web/) for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware (http://evilfantasy.wordpress.com/2008/05/24/slow-computer-it-may-not-be-malware/) for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on March 02, 2012, 12:49:55 AM
I rerun the ESET and found one more threat

C:\Users\marina\AppData\Local\GamePlayLabs Plugin\gplplugin.xpi   Win32/Adware.GamePlayLabs application   deleted - quarantined
Title: Re: resource:///components/nsSessionStore.js:402
Post by: Anna_Pyr on March 02, 2012, 01:01:29 AM
You're welcome. Now we should do some cleanup.

To uninstall ComboFix

    Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
    In the field, type in ComboFix /uninstall

(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

    Then, phttp://www.computerhope.com/ress Enter, or click OK.
    This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.

I am afraid I   have already put it in the dust bin (and emptied the bin) and I do not   seem to be able to uninstall it using the instructions above (I have   windows  7 , no vista, in case this makes any difference). Any   suggestion? Other than this I will do everything else you suggested and many thanks again!
Title: Re: resource:///components/nsSessionStore.js:402
Post by: SuperDave on March 02, 2012, 01:01:44 PM
Quote
I am afraid I   have already put it in the dust bin (and emptied the bin) and I do not   seem to be able to uninstall it using the instructions above (I have   windows  7 , no vista, in case this makes any difference). Any   suggestion? Other than this I will do everything else you suggested and many thanks again!
That's ok. We just need to set a new, clean Restore Point.

To set a new Restore Point.

Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection.  If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode.
Click the Start button , click Control Panel, click System and Maintenance, and then click System.
In the left pane, click System Protection.  If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK.
This will give you a new, clean Restore Point.