Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: sound goes out, yadaying running, Downloader.Tiny.BB, Help!!!  (Read 30433 times)

0 Members and 1 Guest are viewing this topic.

Dr Jay

  • Malware Removal Specialist


  • Specialist
  • Moderator emeritus
  • Thanked: 119
  • Experience: Guru
  • OS: Windows 10
Re: sound goes out, yadaying running, Downloader.Tiny.BB, Help!!!
« Reply #30 on: August 01, 2010, 01:58:02 PM »
Please download DrWeb-CureIt and save it to your Desktop. Do NOT perform a scan yet

  • Double-click on drweb-cureit.exe to start the program.
    An Express Scan of your PC notice will appear.
  • Under Start the Express Scan Now, Click OK to start the scan.
    This is a short scan that will scan the files currently running in memory.
    If something is found, click the Yes button when it asks you if you want to cure it.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the Scan tab and UNcheck Heuristic analysis
  • Back at the main window, click Custom Scan, then Select drives (a red dot will show which drives have been chosen).
  • Then click the Start/Stop Scanning button (green arrow on the right, and the scan will start.
  • When finished, a message will be displayed at the bottom advising if any viruses were found.
  • Click Yes to all if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can see the icon next to the files found.

If so, click it, then click the next icon right below and select Move incurable.
(This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
  • Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
  • Save the DrWeb.csv report to your Desktop.
  • Exit Dr.Web Cureit when you have finished.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)
~Dr Jay

Mr.Hopeless

    Topic Starter


    Rookie

    Re: sound goes out, yadaying running, Downloader.Tiny.BB, Help!!!
    « Reply #31 on: August 02, 2010, 05:54:49 AM »
    Wow.  This got a lot of stuff...

    1196745071jtun_firstexpirationpif.x00\Program Files\Common Files\PIF_B8E1\pifCrawl.exe;C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\1196745071jtun_firstexpirationpif.x00;Trojan.Swizzor.based;;
    1196745071jtun_firstexpirationpif.x00;C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads;Archive contains infected objects;Moved.;
    005F6B55.tmp;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.DownLoader.3204;Deleted.;
    0A532F1A.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.DownLoader.793;Deleted.;
    10FF3461.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Adware.AdBlaster;Incurable.Deleted.;
    278E22DA.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Adware.AdBlaster;Incurable.Deleted.;
    441A342D.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Adware.Virtumonde;Incurable.Deleted.;
    46DC7909.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Adware.Virtumonde;Incurable.Deleted.;
    48D12855.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.Virtumod;Deleted.;
    49D62471.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Adware.Winad;Incurable.Deleted.;
    4D5725C8.EXE;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Adware.AdBlaster;Incurable.Deleted.;
    4D5A4FC5.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Adware.AdBlaster;Incurable.Deleted.;
    6A115978.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Adware.AdBlaster;Incurable.Deleted.;
    6A12297F.bat;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Joke.Opros;Incurable.Deleted.;
    79AC3926.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.DownLoader.793;Deleted.;
    7BD2172F.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Adware.AdBlaster;Incurable.Deleted.;
    7F5368CC.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.DownLoader.1959;Deleted.;
    7F5712C9.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Adware.Winad;Incurable.Deleted.;
    7F5712C9.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Adware.Winad;Incurable.Deleted.;
    7F5712C9.fr9;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Adware.Winad;Incurable.Deleted.;
    Salary Survey.bat;C:\Documents and Settings\Brett\Desktop\Old Computer Stuff\Misc\Humor;Joke.Opros;Incurable.Deleted.;
    ASAP Utilities 310 setup.exe\{app}\format.asap;C:\Documents and Settings\Brett\My Documents\Temp\ASAP Utilities 310 setup.exe;W97M.Iseng;;
    ASAP Utilities 310 setup.exe;C:\Documents and Settings\Brett\My Documents\Temp;Container contains infected objects;Moved.;
    VundoFix.exe\process.exe;C:\Documents and Settings\Brett\My Documents\Temp\VundoFix.exe;Tool.Killproc.3;;
    VundoFix.exe;C:\Documents and Settings\Brett\My Documents\Temp;Container contains infected objects;Moved.;
    pifCrawl.exe;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08};Trojan.Swizzor.based;Deleted.;
    VundoFix.exe\process.exe;C:\Program Files\Computer Defense\VundoFix\VundoFix.exe;Tool.Killproc.3;;
    VundoFix.exe;C:\Program Files\Computer Defense\VundoFix;Container contains infected objects;Moved.;
    process.exe;C:\Program Files\Computer Defense\VundoFix\VundoFix;Tool.Killproc.3;Incurable.Deleted.;
    A0001440.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP14;Trojan.DownLoader.793;Deleted.;
    A0001441.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP14;Trojan.Virtumod;Deleted.;
    A0001442.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP14;Trojan.DownLoader.793;Deleted.;
    A0001443.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP14;Trojan.DownLoader.1959;Deleted.;
    A0001444.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP14;Trojan.Swizzor.based;Deleted.;
    A0001445.exe\process.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP14\A0001445.exe;Tool.Killproc.3;;
    A0001445.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP14;Container contains infected objects;Moved.;

    Dr Jay

    • Malware Removal Specialist


    • Specialist
    • Moderator emeritus
    • Thanked: 119
    • Experience: Guru
    • OS: Windows 10
    Re: sound goes out, yadaying running, Downloader.Tiny.BB, Help!!!
    « Reply #32 on: August 02, 2010, 03:27:49 PM »
    Infections found in ComboFix Quarantine and System Restore

    Virus and malware scanners detect infections found in ComboFix quarantine (C:\Qoobox\) and System Restore (C:\System Volume Information\). However, these infections are harmless, unless if certain conditions occur.

    For ComboFix quarantine:
    • ComboFix should be uninstalled. Otherwise, if a threat were to be restored or executed from the quarantine, the computer would become reinfected.
    For System Restore:
    • A new Restore Point should be created and System Restore should be reset after the infection has been removed.
    • If you do not reset System Restore, and go to Restore your computer to an earlier time, it can reinfect your computer.
    We will be cleaning all of it up.



    Save these instructions so you can have access to them while in Safe Mode.

    Please click here to download AVP Tool by Kaspersky.
    • Save it to your desktop.
    • Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
    • Double click the setup file to run it.
    • Click Next to continue.
    • Accept the License agreement and click on next.
    • It will, by default, install it to your desktop folder. Click Next.
    • It will then open a box There will be a tab that says Automatic scan.
    • Under Automatic scan make sure these are checked.
      • Hidden Startup Objects
      • System Memory
      • Disk Boot Sectors.
      • My Computer.
      • Also any other drives (Removable that you may have)[/color]
      Leave the rest of the settings as they appear as default.
      • Then click on Scan at the to right hand Corner.
      • It will automatically Neutralize any objects found.
      • If some objects are left un-neutralized then click the button that says Neutralize all
      • If it says it cannot be neutralized then choose the delete option when prompted.
      • After that is done click on the reports button at the bottom and save it to file name it Kas.
      • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

        Note: This tool will self uninstall when you close it so please save the log before closing it.
      ~Dr Jay

      Mr.Hopeless

        Topic Starter


        Rookie

        Re: sound goes out, yadaying running, Downloader.Tiny.BB, Help!!!
        « Reply #33 on: August 02, 2010, 10:00:17 PM »
        I was unable to save the report since, in Safe Mode, I couldn't change the Display settings and, unfortunately, the button for creating the report was cut off below the end of the monitor and the top of the window kept snapping to the top of the monitor no matter what I did to try to move it up.  Here are the actions (I had to type this out, so I hope it's accurate):

        Detected: HEUR:Trojan.Win32.Generic  C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1134765A.exe/CryptFF/UPX

        Detected: HEUR:Trojan.Win32.Generic  C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\112E2261.exe/CryptFF/UPX

        Detected: HEUR:Trojan.Win32.Generic  C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1134765A.exe/CryptFF

        Detected: HEUR:Trojan.Win32.Generic  C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\112E2261.exe/CryptFF/UPX

        Deleted: HEUR:Trojan.Win32.Generic  C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1134765A.exe

        Detected: HEUR:Trojan.Win32.Generic  C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\112E2261.exe

        Detected: Trojan-Spy.HTML.Bankfraud.p  C:\Documents and Settings\All Users\Application Data\Symante\Norton AntiVirusQuarantine\357F57F3.exe/CryptFF

        Detected: not-a-virus:AdWare.Win32.AdBlaster.b  C:\Documents and Settings\All Users\Application Data\Symante\Norton AntiVirusQuarantine\4d5A4FC5.dll/CryptFF

        Deleted: Trojan-Spy.HTML.Bankfraud.p  C:\Documents and Settings\All Users\Application Data\Symante\Norton AntiVirusQuarantine\357F57F3.htm

        Detected: not-a-virus:AdWare.Win32.AdBlaster.b  C:\Documents and Settings\All Users\Application Data\Symante\Norton AntiVirusQuarantine\4D5D79C1.dll/CryptFF

        Deleted: not-a-virus:AdWare.Win32.AdBlaster.b  C:\Documents and Settings\All Users\Application Data\Symante\Norton AntiVirusQuarantine\4D5D4FC5.dll/CryptFF

        Detected: not-a-virus:AdWare.Win32.AdBlaster.b  C:\Documents and Settings\All Users\Application Data\Symante\Norton AntiVirusQuarantine\5D0C1A7E.dll/CryptFF

        Deleted: not-a-virus:AdWare.Win32.AdBlaster.b  C:\Documents and Settings\All Users\Application Data\Symante\Nortn AntiVirusQuarantine\4D5D79C1.dll

        Deleted: not-a-virus:AdWare.Win32.AdBlaster.b  C:\Documents and Settings\All Users\Application Data\Symante\Norton AntiVirusQuarantine\5D0C1A7E.dll

        Detected: not-a-virus:AdWare.Win32.AdBlaster.b  C:\Documents and Settings\All Users\Application Data\Symante\Norton AntiVirusQuarantine\6A115978.dll/CryptFF

        Deleted: not-a-virus:AdWare.Win32.AdBlaster.b  C:\Documents and Settings\All Users\Application Data\Symante\Nortn AntiVirusQuarantine\6A115978.dll

        Detected: Trojan-Spy.Win32.SpyAnyTime.c  C:\Documents and Settings\Brett\My Documents\Temp\SANYTIMEsoftwarespy.zip/Spy Anytime PC Spy 2.3/setup.exe/data0001

        Deleted: Trojan-Spy.Win32.SpyAnyTime.c  C:\Documents and Settings\Brett\My Documents\Temp\SANYTIMEsoftwarespy.zip/Spy Anytime PC Spy 2.3/setup.exe

        Detected: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001448.exe/CryptFF

        Detected: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001449.exe/CryptFF

        Detected: Trojan.Win32.Crypt.o  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001450.exe/CryptFF

        Deleted: Trojan.Win32.Crypt.o  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001450.exe

        Deleted: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001448.exe

        Deleted: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001449.exe

        Detected: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001453.EXE/CryptFF

        Detected: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001452.exe/CryptFF

        Detected: Trojan.Win32.Crypt.o  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001451.dll/CryptFF

        Deleted: Trojan.Win32.Crypt.o  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001451.dll

        Detected: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001454.exe/CryptFF

        Deleted: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001453.EXE

        Detected: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001455.exe/CryptFF

        Deleted: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001452.exe

        Deleted: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001454.exe

        Deleted: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001455.exe

        Detected: not-a-virus:Adware.Win32.WinAD.ak  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001458.dll/CryptFF/UPX

        Detected: not-a-virus:Adware.Win32.WinAD.ak  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001459.exe/CryptFF/UPX

        Detected: not-a-virus:Adware.Win32.WinAD.ak  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001457.exe/CryptFF

        Deleted: not-a-virus:Adware.Win32.WinAD.ak  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001458.dll

        Deleted: not-a-virus:Adware.Win32.WinAD.ak  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001459.exe

        Detected: HEUR.Trojan.Win32.Generic  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001516.exe/CryptFF/UPX

        Detected: HEUR.Trojan.Win32.Generic  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001517.exe/CryptFF/UPX

        Detected: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001518.dll/CryptFF

        Detected: HEUR.Trojan.Win32.Generic  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001516.exe/CryptFF

        Deleted: HEUR.Trojan.Win32.Generic  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001516.exe

        Deleted: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001518.dll

        Detected: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001520.dll/CryptFF

        Detected: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001519.dll/CryptFF

        Detected: HEUR.Trojan.Win32.Generic  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001517.exe/CryptFF

        Deleted: HEUR.Trojan.Win32.Generic  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001517.exe

        Detected: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001521.dll/CryptFF

        Deleted: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001521.dll/CryptFF

        Deleted: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001520.dll/CryptFF

        Deleted: not-a-virus:AdWare.Win32.AdBlaster.b  C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0001519.dll/CryptFF

        Detected: not-a-virus:AdWare.Win32.Sahat.ao  C:\WINDOWS\system32\70tovmto.ini

        Detected: not-a-virus:AdWare.Win32.Sahat.ao  C:\WINDOWS\system32\gah95on6.ini

        Deleted: not-a-virus:AdWare.Win32.Sahat.ao  C:\WINDOWS\system32\70tovmto.ini

        Deleted: not-a-virus:AdWare.Win32.Sahat.ao  C:\WINDOWS\system32\gah95on6.ini

        Dr Jay

        • Malware Removal Specialist


        • Specialist
        • Moderator emeritus
        • Thanked: 119
        • Experience: Guru
        • OS: Windows 10
        Re: sound goes out, yadaying running, Downloader.Tiny.BB, Help!!!
        « Reply #34 on: August 04, 2010, 12:40:17 PM »
        Download SuperAntiSpyware
        • Load SuperAntiSpyware and click the Check for updates button.
        • Once the update is finished click the Scan your computer button.
        • Check Perform Complete Scan and then next.
        • SuperAntiSpyware will now scan your computer and when its finished it will list all the infections it has found.
        • Make sure that they all have a check next to them and press next.
        • Click finish and you will be taken back to the main interface.
        • Click Preferences and then click the statistics/logs tab. Click the dated log and press view log and a text file will appear.
        • Copy and paste the log onto the forum.
        ~Dr Jay

        Mr.Hopeless

          Topic Starter


          Rookie

          Re: sound goes out, yadaying running, Downloader.Tiny.BB, Help!!!
          « Reply #35 on: August 05, 2010, 09:22:47 PM »
          SUPERAntiSpyware Scan Log
          http://www.superantispyware.com

          Generated 08/05/2010 at 01:46 PM

          Application Version : 4.41.1000

          Core Rules Database Version : 5322
          Trace Rules Database Version: 3134

          Scan type       : Complete Scan
          Total Scan Time : 00:46:51

          Memory items scanned      : 529
          Memory threats detected   : 0
          Registry items scanned    : 7287
          Registry threats detected : 0
          File items scanned        : 28943
          File threats detected     : 266

          Adware.Tracking Cookie
             *Blocked Russian URL* [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .overture.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .overture.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .doubleclick.net [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .247realmedia.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .tribalfusion.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .atdmt.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .atdmt.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .kontera.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .bs.serving-sys.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .serving-sys.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .serving-sys.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .serving-sys.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .serving-sys.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .serving-sys.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .serving-sys.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .serving-sys.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .kontera.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .kontera.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .media6degrees.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .media6degrees.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .media6degrees.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .collective-media.net [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .apmebf.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .fastclick.net [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .fastclick.net [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .mediaplex.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .ads.pointroll.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .pointroll.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .pointroll.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .ads.pointroll.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .ads.pointroll.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .ads.pointroll.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .ads.pointroll.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .ads.pointroll.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .ads.pointroll.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .avgtechnologies.112.2o7.net [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .liveperson.net [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .liveperson.net [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .media6degrees.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .kaspersky.122.2o7.net [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .interclick.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .specificclick.net [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .specificclick.net [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .fastclick.net [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .interclick.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .interclick.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .invitemedia.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .invitemedia.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .invitemedia.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .revsci.net [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .revsci.net [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .cyberdefender.122.2o7.net [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .mediaplex.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .a1.interclick.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .revsci.net [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .revsci.net [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .ehg-eset.hitbox.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .hitbox.com [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .collective-media.net [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .collective-media.net [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             *Blocked Russian URL* [ C:\Documents and Settings\Brett\Application Data\Mozilla\Firefox\Profiles\jsow3vw5.default\cookies.sqlite ]
             .adbureau.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .adinterax.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .s.clickability.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .s.clickability.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             server.cpmstar.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .redorbit.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .interclick.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .interclick.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .yieldmanager.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .nextag.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .nextag.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .at.atwola.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .specificclick.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .specificclick.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .edge.ru4.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .edge.ru4.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .specificclick.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .specificmedia.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             cdn4.specificclick.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             cdn4.specificclick.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .specificclick.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .ads.pointroll.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .ads.pointroll.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .ads.pointroll.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .ads.pointroll.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .ads.pointroll.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .ads.pointroll.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .ads.pointroll.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .richmedia.yahoo.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .imrworldwide.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .imrworldwide.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             citi.bridgetrack.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             citi.bridgetrack.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             citi.bridgetrack.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .collective-media.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .newbalance.112.2o7.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .interclick.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .invitemedia.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .invitemedia.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .invitemedia.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .invitemedia.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .invitemedia.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             server.iad.liveperson.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             server.iad.liveperson.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             citi.bridgetrack.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             citi.bridgetrack.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             citi.bridgetrack.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .iacas.adbureau.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .iacas.adbureau.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .iacas.adbureau.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             ads.lucidmedia.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .michaelcfina.122.2o7.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .roiservice.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .adlegend.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .media6degrees.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .media6degrees.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .media6degrees.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .media6degrees.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .media6degrees.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .neoedge.adbureau.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .care2.112.2o7.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             ads.gamesbannernet.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             ads.gamesbannernet.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             ads.gamesbannernet.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .bizrate.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             media.mtvnservices.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .viacom.adbureau.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .viacom.adbureau.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .viacom.adbureau.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .adserver.adtechus.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             rotator.adjuggler.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             rotator.adjuggler.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             sales.liveperson.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             sales.liveperson.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             sales.liveperson.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .adinterax.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .adinterax.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .borders.112.2o7.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .azjmp.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .microsoftwindows.112.2o7.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .chitika.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .ads.pointroll.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .sixteenthstreetsynagogue.org [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .e-2dj6wjlyekcpodp.stats.esomniture.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .e-2dj6wjny-1gc5ec.stats.esomniture.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .e-2dj6wjkoknajgko.stats.esomniture.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .qnsr.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .qnsr.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .specificclick.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             cdn4.specificclick.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .specificclick.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .videoegg.adbureau.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .afe.specificclick.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             stat.onestat.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             stat.onestat.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .a1.interclick.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .specificclick.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .cbs.112.2o7.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .lockedonmedia.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .eyewonder.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             sales.liveperson.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             www.skicountryantiques.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .kiplinger.112.2o7.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .healthgrades.112.2o7.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             cdn4.specificclick.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             webstats.aetna.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .invitemedia.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .legolas-media.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             adserver.webads.co.il [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             cdn4.specificclick.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             cdn4.specificclick.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .media6degrees.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .dmtracker.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .avgtechnologies.112.2o7.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             dc.tremormedia.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .socialmedia.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .invitemedia.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .invitemedia.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             stats.amnh.org [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .media6degrees.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .hotelscom.122.2o7.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .server.cpmstar.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .network.realmedia.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .server.cpmstar.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .invitemedia.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .chicagosuntimes.122.2o7.net [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .kontera.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             secure.sussexdirectories.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .sussexdirectories.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .sussexdirectories.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .secure3.sussexdirectories.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .secure3.sussexdirectories.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .at.atwola.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .insightexpressai.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             www.googleadservices.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .nextag.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .nextag.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .nextag.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .nextag.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .at.atwola.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .nextag.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             .nextag.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             www.clickmanage.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]
             www.clickmanage.com [ C:\Documents and Settings\Deborah\Application Data\Mozilla\Firefox\Profiles\r183vqyk.default\cookies.sqlite ]

          Adware.Vundo/Variant-X32[Header]
             C:\PROGRAM FILES\GIFCONSTRUCTIONSETPROFESSIONAL\GCSGIF32.DLL
             C:\PROGRAM FILES\GIFCONSTRUCTIONSETPROFESSIONAL\GCSJPG32.DLL
             C:\PROGRAM FILES\GIFCONSTRUCTIONSETPROFESSIONAL\GCSPCX32.DLL
             C:\PROGRAM FILES\GIFCONSTRUCTIONSETPROFESSIONAL\GCSPNG32.DLL
             C:\PROGRAM FILES\GIFCONSTRUCTIONSETPROFESSIONAL\GCSTGA32.DLL

          Adware.Unknown Origin
             C:\WINDOWS\SYSTEM32\IESH12052004.CFG

          Dr Jay

          • Malware Removal Specialist


          • Specialist
          • Moderator emeritus
          • Thanked: 119
          • Experience: Guru
          • OS: Windows 10
          Re: sound goes out, yadaying running, Downloader.Tiny.BB, Help!!!
          « Reply #36 on: August 06, 2010, 11:08:55 PM »
          We'll do another scan here, to check for anymore malware.

          Please download the latest version of Kaspersky GetSystemInfo (GSI) from Kaspersky and save it to your Desktop.

          Note: please close all other applications running on your system.

          Double click GetSystemInfo.exe to open it. It will display an agreement. Click on I Agree to continue.

          Click the Settings button.



          Set the slider to Maximum.



          IMPORTANT! Then, click Customize - choose Driver / Ports tab and uncheck Scan Ports.




          On the General tab, make sure all of the boxes are checked.




          On the Misc tab, make sure all the checkboxes are checked.

          Then, click OK on the windows that you launched.



          Click Create Report to run it.


          It will begin scanning.

          It will create a zip folder called GetSystemInfo_XXXXXXXXXXXXXX.zip on your Desktop.

          It should automatically upload it to http://www.getsysteminfo.com. If it does not, then please submit it manually by going to the site and doing the upload process.

          It will redirect to a page, where it will provide a sharing URL for specialists. Copy and paste the url of the GSI Parser report in your next reply.
          ~Dr Jay


          Dr Jay

          • Malware Removal Specialist


          • Specialist
          • Moderator emeritus
          • Thanked: 119
          • Experience: Guru
          • OS: Windows 10
          Re: sound goes out, yadaying running, Downloader.Tiny.BB, Help!!!
          « Reply #38 on: August 07, 2010, 08:09:22 PM »
          Are there any other signs of infection?

          Shall we clean up or continue searching?
          ~Dr Jay

          Gahmieh

          • Guest
          Re: sound goes out, yadaying running, Downloader.Tiny.BB, Help!!!
          « Reply #39 on: August 08, 2010, 03:38:51 AM »
          Please open Notepad and enter in the following:Then, click File > Save as...
          Save as remove.bat to the same location as remover.exe.
          Choose Save as type... All Files.
          Click Save.

          Then, exit Notepad.

          Double-click on remove.bat.

          Please re-run remover.exe and post a new log in your next reply.

          Sorry, I know, it's not my topic, but I read it here and because I have also some problems with my sound on my laptop, I tried this. But after doing exactly like you have described it, my laptop does not boot. Is there a solution?

          Mr.Hopeless

            Topic Starter


            Rookie

            Re: sound goes out, yadaying running, Downloader.Tiny.BB, Help!!!
            « Reply #40 on: August 08, 2010, 04:45:49 PM »
            Right now the sound is working again and the ticking noise seems to have abated...  We could go for the clean up now unless you think I should use that computer again for the next few days to see if anything else comes up.  (I've been borrowing a laptop for the past month or so...)

            Dr Jay

            • Malware Removal Specialist


            • Specialist
            • Moderator emeritus
            • Thanked: 119
            • Experience: Guru
            • OS: Windows 10
            Re: sound goes out, yadaying running, Downloader.Tiny.BB, Help!!!
            « Reply #41 on: August 09, 2010, 11:18:25 PM »
            Why not give it a few days, and let me know if anything shows up. :)
            ~Dr Jay

            Mr.Hopeless

              Topic Starter


              Rookie

              Re: sound goes out, yadaying running, Downloader.Tiny.BB, Help!!!
              « Reply #42 on: August 30, 2010, 11:06:44 AM »
              Okay, so after a using the computer a bunch of times, the sound is still working and the only thing I'm seeing that gets me nervous is this message still pops up, and I'm not sure what it's related to:
              Quote
              WMI has changed since the last time you used it. This could happen if you have updated it recently.  Click Detail to see more information.  Do you want to allow it to access the network?
              The executable has changed since the last time you used: C:\WINDOWS\system32\wbem\wmiprvse.exe
              My computer also seems to be sluggish.  It may be because I've been borrowing my wife's faster laptop a lot lately, but it just seems slow and that also gets me nervous.  Maybe I need to remove some of the software we've added?

              Dr Jay

              • Malware Removal Specialist


              • Specialist
              • Moderator emeritus
              • Thanked: 119
              • Experience: Guru
              • OS: Windows 10
              ~Dr Jay

              elchocolato

              • Guest
              Re: sound goes out, yadaying running, Downloader.Tiny.BB, Help!!!
              « Reply #44 on: September 03, 2010, 10:50:45 PM »
              Hey guys, for those of you who are having this problem but this solution isn't working for you (or is too long and you are lazy):
              There is a program called ProcessGuard, which allows you to deny a program to ever run. You can use it to just block iexplore.exe from ever running. This blocks the symptoms, so its nice as a quick fix, but keep in mind you still have the disease! I have just done this, it is also nice because it allows you to remain functional while actually fixing it as well without the iexplore's to worry about.