Over 1 million tech questions and answers.

Banners in Firefox window, unwanted programs, extra tabs opening in firefox.....

Q: Banners in Firefox window, unwanted programs, extra tabs opening in firefox.....

Acer Aspire 5750-6636
Windows 7 64bit Service Pack 1
Intel Core i3-2310M (2.1GHz, 3MB L3 cache)
 
(Addition.txt would not attach so I pasted it at the end.)
 
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-06-2015
Ran by Owner (administrator) on OWNER-PC on 08-06-2015 11:24:36
Running from C:\Users\Owner\Downloads
Loaded Profiles: Owner (Available Profiles: Owner)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP Officejet Pro 8610\Bin\ScanToPCActivationApp.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP Officejet Pro 8610\Bin\HPNetworkCommunicatorCom.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Ninja Soft Inc.) C:\Program Files (x86)\Ninja Loader\NinjaMaintainer.exe
(Ninja Soft Inc.) C:\Program Files (x86)\Ninja Loader\NinjaMaintainer.exe
(Ninja Soft Inc.) C:\Program Files (x86)\Ninja Loader\NinjaMaintainer.exe
(CLICK YES BELOW LP) C:\Program Files (x86)\Ninja Loader\Ninja Loader.exe
(Cinema PlusV08.06) C:\Program Files (x86)\CinemaPlus-3.2cV08.06-ntf\d409385c-785e-4d4d-9aed-71c9f81e0b79-10.exe
(Cinema PlusV08.06) C:\Program Files (x86)\CinemaPlus-3.2cV08.06\d409385c-785e-4d4d-9aed-71c9f81e0b79-1-6.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(The Chromium Authors) C:\Users\Owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\Owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\Owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\Owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\Owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\Owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\Owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\Owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\Owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\Owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\Owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\Owner\AppData\Local\Ninja Loader\Discover\Discover.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2280232 2014-02-17] (Synaptics Incorporated)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2011-02-18] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2014-02-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [884440 2015-05-28] (BlueStack Systems, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2586465260-67891513-3247288464-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8322328 2015-05-08] (Piriform Ltd)
HKU\S-1-5-21-2586465260-67891513-3247288464-1000\...\Run: [MAgent] => C:\Users\Owner\AppData\Roaming\Mail.Ru\Agent\magent.exe [38253600 2015-05-30] (Mail.Ru)
HKU\S-1-5-21-2586465260-67891513-3247288464-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4471536 2015-05-21] (Disc Soft Ltd)
HKU\S-1-5-21-2586465260-67891513-3247288464-1000\...\Run: [HP Officejet Pro 8610 (NET)] => C:\Program Files\HP\HP Officejet Pro 8610\Bin\ScanToPCActivationApp.exe [3487240 2014-07-21] (Hewlett-Packard Development Company, LP)
HKU\S-1-5-21-2586465260-67891513-3247288464-1000\...\Run: [NinjaLoader] => C:\Program Files (x86)\Ninja Loader\Ninja Loader.exe [1573480 2015-05-29] (CLICK YES BELOW LP)
HKU\S-1-5-21-2586465260-67891513-3247288464-1000\...\MountPoints2: E - E:\VerizonSWUpgradeAssistantLauncher.exe
HKU\S-1-5-21-2586465260-67891513-3247288464-1000\...\MountPoints2: {2309a8cb-982e-11e3-917a-806e6f6e6963} - "D:\Diablo III Setup.exe"
HKU\S-1-5-21-2586465260-67891513-3247288464-1000\...\MountPoints2: {6f4958ca-0cc0-11e5-a08c-b870f4720eb8} - E:\AutoRun.exe
HKU\S-1-5-21-2586465260-67891513-3247288464-1000\...\MountPoints2: {7b9015d9-7bbe-11e4-a862-b870f4720eb8} - E:\VerizonSWUpgradeAssistantLauncher.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2014-08-28]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2586465260-67891513-3247288464-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2586465260-67891513-3247288464-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2586465260-67891513-3247288464-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKU\S-1-5-21-2586465260-67891513-3247288464-1000 -> {86148631-72D6-419B-9EE1-4BEBE77B6E71} URL = https://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=667671&p={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-03-10] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-04-14] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-04-14] (Microsoft Corporation)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-04] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-04-14] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-04] (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\z96v4ubc.default-1415487348170
FF DefaultSearchEngine: Yahoo!
FF DefaultSearchEngine.US: Google
FF Homepage: https://www.google.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_188.dll [2015-06-08] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-06-08] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-06] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-04] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-04] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-02-21] (Microsoft Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-06-08] (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-06-08] (globalUpdate)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\z96v4ubc.default-1415487348170\user.js [2015-06-07]
FF Extension: CinemaPlus-3.2cV08.06 - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\z96v4ubc.default-1415487348170\Extensions\[email protected] [2015-06-08]
FF HKU\S-1-5-21-2586465260-67891513-3247288464-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
FF HKU\S-1-5-21-2586465260-67891513-3247288464-1000\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Ninja Loader\FireFox
FF Extension: NinjaLoader - C:\Program Files (x86)\Ninja Loader\FireFox [2015-06-08]
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [cmlhbjpgeogifjnmlajdaealbdlfonah] - https://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [433880 2015-05-28] (BlueStack Systems, Inc.)
S3 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [413400 2015-05-28] (BlueStack Systems, Inc.)
S3 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [806616 2015-05-28] (BlueStack Systems, Inc.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2736824 2015-04-07] (Microsoft Corporation)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1272560 2015-05-21] (Disc Soft Ltd)
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-06-08] (globalUpdate) [File not signed] <==== ATTENTION
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-06-08] (globalUpdate) [File not signed] <==== ATTENTION
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 NinjaLoaderService; C:\Program Files (x86)\Ninja Loader\NinjaMaintainer.exe [59496 2015-05-21] (Ninja Soft Inc.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AX88772; C:\Windows\System32\DRIVERS\ax88772.sys [73216 2010-11-01] (ASIX Electronics Corp.)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [145112 2015-05-28] (BlueStack Systems)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-06-06] (Disc Soft Ltd)
R1 {21181538-7fbb-4069-b287-194adafdb095}Gw64; C:\Windows\System32\drivers\{21181538-7fbb-4069-b287-194adafdb095}Gw64.sys [48784 2015-06-06] (StdLib)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-08 11:24 - 2015-06-08 11:25 - 00015827 _____ C:\Users\Owner\Downloads\FRST.txt
2015-06-08 11:23 - 2015-06-08 11:23 - 02108928 _____ (Farbar) C:\Users\Owner\Downloads\FRST64.exe
2015-06-08 11:10 - 2015-06-08 11:10 - 00000000 ____D C:\Users\Owner\.cache
2015-06-08 10:05 - 2015-06-08 11:10 - 00003138 _____ C:\Windows\Tasks\d409385c-785e-4d4d-9aed-71c9f81e0b79-1-6.job
2015-06-08 10:05 - 2015-06-08 11:10 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-06-08 10:05 - 2015-06-08 10:10 - 00000974 _____ C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2015-06-08 10:05 - 2015-06-08 10:10 - 00000970 _____ C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-06-08 10:05 - 2015-06-08 10:05 - 00007524 _____ C:\Windows\System32\Tasks\d409385c-785e-4d4d-9aed-71c9f81e0b79-4
2015-06-08 10:05 - 2015-06-08 10:05 - 00006168 _____ C:\Windows\System32\Tasks\d409385c-785e-4d4d-9aed-71c9f81e0b79-1-7
2015-06-08 10:05 - 2015-06-08 10:05 - 00006166 _____ C:\Windows\System32\Tasks\d409385c-785e-4d4d-9aed-71c9f81e0b79-1-6
2015-06-08 10:05 - 2015-06-08 10:05 - 00005476 _____ C:\Windows\System32\Tasks\d409385c-785e-4d4d-9aed-71c9f81e0b79-5
2015-06-08 10:05 - 2015-06-08 10:05 - 00004494 _____ C:\Windows\Tasks\d409385c-785e-4d4d-9aed-71c9f81e0b79-4.job
2015-06-08 10:05 - 2015-06-08 10:05 - 00004028 _____ C:\Windows\System32\Tasks\NMttF0Xg0cgJc72
2015-06-08 10:05 - 2015-06-08 10:05 - 00003972 _____ C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
2015-06-08 10:05 - 2015-06-08 10:05 - 00003718 _____ C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
2015-06-08 10:05 - 2015-06-08 10:05 - 00003138 _____ C:\Windows\Tasks\d409385c-785e-4d4d-9aed-71c9f81e0b79-1-7.job
2015-06-08 10:05 - 2015-06-08 10:05 - 00002446 _____ C:\Windows\Tasks\d409385c-785e-4d4d-9aed-71c9f81e0b79-5_user.job
2015-06-08 10:05 - 2015-06-08 10:05 - 00002446 _____ C:\Windows\Tasks\d409385c-785e-4d4d-9aed-71c9f81e0b79-5.job
2015-06-08 10:05 - 2015-06-08 10:05 - 00001002 _____ C:\Windows\Tasks\NMttF0Xg0cgJc72.job
2015-06-08 10:05 - 2015-06-08 10:05 - 00000000 ____D C:\Users\Owner\AppData\Local\globalUpdate
2015-06-08 10:05 - 2015-06-08 10:05 - 00000000 ____D C:\Program Files (x86)\globalUpdate
2015-06-08 10:04 - 2015-06-08 11:10 - 00002120 _____ C:\Windows\Tasks\d409385c-785e-4d4d-9aed-71c9f81e0b79-10_user.job
2015-06-08 10:04 - 2015-06-08 10:06 - 00000000 ____D C:\Users\Owner\AppData\Local\Ninja Loader
2015-06-08 10:04 - 2015-06-08 10:05 - 00000000 ____D C:\Program Files (x86)\CinemaPlus-3.2cV08.06
2015-06-08 10:04 - 2015-06-08 10:04 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ninja Loader
2015-06-08 10:04 - 2015-06-08 10:04 - 00000000 ____D C:\Program Files (x86)\Ninja Loader
2015-06-08 10:04 - 2015-06-08 10:04 - 00000000 ____D C:\Program Files (x86)\CinemaPlus-3.2cV08.06-ntf
2015-06-07 23:05 - 2015-06-07 23:05 - 00001500 _____ C:\Users\Public\Desktop\LibreOffice 4.4.lnk
2015-06-07 23:05 - 2015-06-07 23:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.4
2015-06-07 23:04 - 2015-06-07 23:05 - 00000000 ____D C:\Program Files (x86)\LibreOffice 4
2015-06-07 22:14 - 2015-06-07 22:14 - 00002200 _____ C:\Users\Public\Desktop\HP Officejet Pro 8610.lnk
2015-06-07 22:14 - 2015-06-07 22:14 - 00001152 _____ C:\Users\Public\Desktop\Shop for Supplies - HP Officejet Pro 8610.lnk
2015-06-07 22:14 - 2015-06-07 22:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2015-06-07 22:14 - 2014-07-21 16:31 - 00763912 ____N (Hewlett-Packard Development Company, LP) C:\Windows\system32\HPDiscoPM7112.dll
2015-06-07 22:13 - 2015-06-07 22:13 - 00000057 _____ C:\ProgramData\Ament.ini
2015-06-07 22:13 - 2015-06-07 22:13 - 00000000 ____D C:\ProgramData\HP
2015-06-07 22:13 - 2015-06-07 22:13 - 00000000 ____D C:\Program Files\HP
2015-06-07 22:10 - 2015-06-07 22:14 - 00000000 ____D C:\Users\Owner\AppData\Local\HP
2015-06-07 21:51 - 2015-06-07 21:51 - 00000000 ____D C:\Users\Owner\AppData\Local\Hewlett-Packard
2015-06-07 21:50 - 2015-06-07 22:14 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard
2015-06-07 21:50 - 2015-06-07 22:13 - 00000000 ____D C:\Program Files (x86)\Hp
2015-06-07 21:50 - 2015-06-07 21:50 - 05197824 _____ C:\Users\Owner\Downloads\HPSupportSolutionsFramework-11.51.0049.msi
2015-06-07 21:43 - 2015-06-07 23:50 - 00000000 ____D C:\Users\Owner\Documents\Inna's Resume
2015-06-07 20:30 - 2015-06-07 20:30 - 00000000 ____D C:\Users\Owner\AppData\Roaming\LibreOffice
2015-06-07 20:06 - 2015-06-07 20:06 - 00000000 ____D C:\Users\Owner\Documents\Diablo III
2015-06-07 20:05 - 2015-06-07 20:05 - 00000000 ____D C:\Program Files (x86)\Setup Support for Consumer Input
2015-06-07 19:56 - 2015-06-07 19:56 - 03071032 _____ (Blizzard Entertainment) C:\Users\Owner\Downloads\Diablo-III-Setup-enUS.exe
2015-06-07 19:27 - 2015-06-07 19:27 - 00000000 ____D C:\Users\Owner\Documents\Lists
2015-06-07 19:12 - 2015-06-08 09:42 - 00009122 _____ C:\Windows\PFRO.log
2015-06-07 19:12 - 2015-06-07 19:12 - 00000258 __RSH C:\ProgramData\ntuser.pol
2015-06-07 18:46 - 2015-06-07 19:35 - 00000000 ____D C:\Users\Owner\Desktop\Games
2015-06-07 14:30 - 2015-06-07 14:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III
2015-06-07 13:25 - 2015-06-07 20:06 - 00000000 ____D C:\Program Files (x86)\Diablo III
2015-06-07 13:23 - 2015-06-07 19:57 - 00000000 ____D C:\Users\Owner\AppData\Local\Battle.net
2015-06-07 13:23 - 2015-06-07 13:24 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Battle.net
2015-06-07 13:23 - 2015-06-07 13:23 - 00000000 ____D C:\Users\Owner\AppData\Local\Blizzard Entertainment
2015-06-07 13:23 - 2015-06-07 13:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2015-06-07 13:23 - 2015-06-07 13:23 - 00000000 ____D C:\ProgramData\Blizzard Entertainment
2015-06-07 13:23 - 2015-06-07 13:23 - 00000000 ____D C:\Program Files (x86)\Battle.net
2015-06-07 13:22 - 2015-06-07 13:22 - 00000000 ____D C:\ProgramData\Battle.net
2015-06-07 00:32 - 2015-06-07 00:32 - 00000000 ____D C:\Program Files (x86)\Koei
2015-06-07 00:31 - 2015-06-07 00:31 - 00000000 ____D C:\Users\Owner\Documents\Koei
2015-06-07 00:31 - 2015-06-07 00:31 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Koei
2015-06-07 00:17 - 2015-06-07 00:17 - 00000000 ____D C:\Users\Owner\AppData\Local\Disc_Soft_Ltd
2015-06-07 00:05 - 2015-06-06 16:45 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{21181538-7fbb-4069-b287-194adafdb095}Gw64.sys
2015-06-07 00:03 - 2015-06-08 09:42 - 00000330 _____ C:\Windows\Tasks\KZUWXNBQI1.job
2015-06-07 00:03 - 2015-06-07 19:12 - 00000000 ____D C:\Program Files (x86)\Swift Record
2015-06-07 00:03 - 2015-06-07 00:03 - 00003558 _____ C:\Windows\System32\Tasks\YBSNKXI
2015-06-07 00:03 - 2015-06-07 00:03 - 00002852 _____ C:\Windows\System32\Tasks\KZUWXNBQI1
2015-06-07 00:03 - 2015-06-07 00:03 - 00000000 ____D C:\ProgramData\6b818a33a2964c51a9c56ff33ef8d8c7
2015-06-07 00:03 - 2015-06-07 00:03 - 00000000 ____D C:\ProgramData\28341ff220e0446c9fff27c4493d622e
2015-06-06 23:57 - 2015-06-06 23:57 - 00030264 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtlitescsibus.sys
2015-06-06 23:57 - 2015-06-06 23:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2015-06-06 23:57 - 2015-06-06 23:57 - 00000000 ____D C:\Program Files\DAEMON Tools Lite
2015-06-06 23:13 - 2015-06-06 23:13 - 00000000 ____D C:\Users\Owner\AppData\Roaming\fltk.org
2015-06-06 22:54 - 2015-06-08 09:42 - 00000280 _____ C:\Windows\setupact.log
2015-06-06 22:54 - 2015-06-06 22:54 - 00000000 _____ C:\Windows\setuperr.log
2015-06-06 22:39 - 2015-06-06 22:39 - 00000000 ____D C:\ProgramData\SystemRequirementsLab
2015-06-06 22:39 - 2015-06-06 22:39 - 00000000 ____D C:\Program Files (x86)\SystemRequirementsLab
2015-06-06 17:19 - 2015-06-06 17:19 - 00002172 _____ C:\Users\Owner\AppData\Local\recently-used.xbel
2015-06-06 16:59 - 2015-06-06 17:05 - 00000000 ____D C:\Users\Owner\AppData\Local\gtk-2.0
2015-06-06 16:58 - 2015-06-06 16:58 - 00000000 ____D C:\Users\Owner\.thumbnails
2015-06-06 16:52 - 2015-06-06 17:19 - 00000000 ____D C:\Users\Owner\.gimp-2.8
2015-06-06 16:52 - 2015-06-06 16:52 - 00000000 ____D C:\Users\Owner\AppData\Local\gegl-0.2
2015-06-06 16:52 - 2015-06-06 16:52 - 00000000 ____D C:\Users\Owner\AppData\Local\Bluestacks
2015-06-06 16:52 - 2015-06-06 16:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
2015-06-06 16:52 - 2015-06-06 16:52 - 00000000 ____D C:\ProgramData\BlueStacks
2015-06-06 16:52 - 2015-06-06 16:52 - 00000000 ____D C:\Program Files (x86)\BlueStacks
2015-06-06 15:57 - 2015-06-06 16:00 - 00000894 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2015-06-06 15:56 - 2015-06-06 15:57 - 00000000 ____D C:\Program Files\GIMP 2
2015-06-06 11:59 - 2015-06-06 11:59 - 14155832 _____ (BlueStack Systems Inc.) C:\Users\Owner\Downloads\BlueStacks-ThinInstaller.exe
2015-06-04 16:53 - 2015-06-04 16:53 - 00003130 _____ C:\Windows\System32\Tasks\{88B2B859-08D4-45F6-9335-28827E2FDD6C}
2015-06-01 20:13 - 2015-06-08 02:11 - 00000000 ____D C:\Users\Owner\AppData\Roaming\CDisplayEx
2015-06-01 20:13 - 2015-06-01 20:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDisplayEx
2015-06-01 20:13 - 2015-06-01 20:13 - 00000000 ____D C:\Program Files\CDisplayEx
2015-06-01 20:09 - 2015-06-02 21:08 - 00000000 ____D C:\Users\Owner\Downloads\ARRRR
2015-06-01 18:45 - 2015-06-01 18:45 - 00000000 ____D C:\Users\Owner\AppData\Local\GWX
2015-05-31 23:15 - 2015-06-02 20:53 - 00000000 ____D C:\Users\Owner\Downloads\Seeding Torrents
2015-05-31 23:12 - 2015-06-02 20:57 - 00000000 ____D C:\Users\Owner\Downloads\Completed
2015-05-30 22:51 - 2015-05-30 22:51 - 00002012 _____ C:\Users\Owner\Desktop\Mail.Ru Agent.lnk
2015-05-30 22:51 - 2015-05-30 22:51 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mail.Ru
2015-05-30 22:51 - 2015-05-30 22:51 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Mail.Ru
2015-05-30 21:47 - 2015-06-01 21:42 - 00000025 _____ C:\Users\Owner\Desktop\Find.txt
2015-05-29 20:50 - 2015-05-29 20:50 - 00000000 ____D C:\Users\Owner\.android
2015-05-29 20:08 - 2015-06-02 13:30 - 00001054 _____ C:\Users\Owner\Desktop\New Text Document.txt
2015-05-29 11:10 - 2015-05-29 11:19 - 00000000 ____D C:\AdwCleaner
2015-05-29 10:54 - 2015-05-29 10:54 - 00001199 _____ C:\Users\Owner\Desktop\Downloads - Shortcut.lnk
2015-05-29 01:40 - 2015-05-29 01:46 - 00000000 ____D C:\Users\Owner\Downloads\Dolores.Claiborne.1995.WS.DVDRip.x264-REKoDE
2015-05-28 02:33 - 2015-06-08 11:24 - 00000000 ____D C:\FRST
2015-05-28 00:12 - 2015-05-28 00:12 - 00002790 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-05-28 00:12 - 2015-05-28 00:12 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-05-28 00:12 - 2015-05-28 00:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-05-28 00:12 - 2015-05-28 00:12 - 00000000 ____D C:\Program Files\CCleaner
2015-05-27 18:30 - 2015-05-27 18:30 - 00000000 __SHD C:\Users\Owner\AppData\Local\EmieBrowserModeList
2015-05-27 03:11 - 2015-06-06 20:37 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2015-05-17 20:48 - 2015-06-02 13:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-05-13 06:54 - 2015-05-01 09:17 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 06:54 - 2015-05-01 09:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-12 15:26 - 2015-05-04 21:29 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-12 15:26 - 2015-05-04 21:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-05-12 15:26 - 2015-04-21 22:28 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-05-12 15:26 - 2015-04-21 21:48 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-05-12 15:26 - 2015-04-21 13:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-05-12 15:26 - 2015-04-21 13:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-05-12 15:26 - 2015-04-21 12:51 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-05-12 15:26 - 2015-04-21 12:50 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-12 15:26 - 2015-04-21 12:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-05-12 15:26 - 2015-04-21 12:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-12 15:26 - 2015-04-21 12:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-05-12 15:26 - 2015-04-21 12:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-05-12 15:26 - 2015-04-21 12:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-05-12 15:26 - 2015-04-21 12:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-05-12 15:26 - 2015-04-21 12:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-05-12 15:26 - 2015-04-21 12:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-05-12 15:26 - 2015-04-21 12:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-05-12 15:26 - 2015-04-21 12:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-05-12 15:26 - 2015-04-21 12:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-05-12 15:26 - 2015-04-21 12:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-05-12 15:26 - 2015-04-21 12:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-05-12 15:26 - 2015-04-21 12:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-05-12 15:26 - 2015-04-21 12:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-05-12 15:26 - 2015-04-21 12:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-12 15:26 - 2015-04-21 12:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-05-12 15:26 - 2015-04-21 12:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-05-12 15:26 - 2015-04-21 12:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-05-12 15:26 - 2015-04-21 12:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-05-12 15:26 - 2015-04-21 11:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-05-12 15:26 - 2015-04-21 11:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-05-12 15:26 - 2015-04-21 11:57 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-05-12 15:26 - 2015-04-21 11:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-12 15:26 - 2015-04-21 11:49 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-05-12 15:26 - 2015-04-21 11:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-05-12 15:26 - 2015-04-21 11:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-12 15:26 - 2015-04-21 11:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-05-12 15:26 - 2015-04-21 11:39 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-05-12 15:26 - 2015-04-21 11:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-05-12 15:26 - 2015-04-21 11:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-05-12 15:26 - 2015-04-21 11:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-05-12 15:26 - 2015-04-21 11:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-05-12 15:26 - 2015-04-21 11:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-05-12 15:26 - 2015-04-21 11:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-05-12 15:26 - 2015-04-21 11:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-05-12 15:26 - 2015-04-21 11:15 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-12 15:26 - 2015-04-21 11:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-05-12 15:26 - 2015-04-21 11:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-05-12 15:26 - 2015-04-21 10:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-05-12 15:26 - 2015-04-21 10:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-05-12 15:26 - 2015-04-17 23:10 - 00460800 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-05-12 15:26 - 2015-04-17 22:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2015-05-12 15:25 - 2015-04-27 15:28 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-05-12 15:25 - 2015-04-27 15:28 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-05-12 15:25 - 2015-04-27 15:28 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-05-12 15:25 - 2015-04-27 15:26 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 01254400 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-05-12 15:25 - 2015-04-27 15:23 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-05-12 15:25 - 2015-04-27 15:22 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-05-12 15:25 - 2015-04-27 15:22 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-05-12 15:25 - 2015-04-27 15:22 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-05-12 15:25 - 2015-04-27 15:22 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-05-12 15:25 - 2015-04-27 15:22 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-05-12 15:25 - 2015-04-27 15:22 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-05-12 15:25 - 2015-04-27 15:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-05-12 15:25 - 2015-04-27 15:22 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-05-12 15:25 - 2015-04-27 15:22 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-05-12 15:25 - 2015-04-27 15:21 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-05-12 15:25 - 2015-04-27 15:18 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-05-12 15:25 - 2015-04-27 15:18 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 15:11 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-05-12 15:25 - 2015-04-27 15:11 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-05-12 15:25 - 2015-04-27 15:08 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-05-12 15:25 - 2015-04-27 15:05 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-05-12 15:25 - 2015-04-27 15:05 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-05-12 15:25 - 2015-04-27 15:05 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-05-12 15:25 - 2015-04-27 15:05 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-05-12 15:25 - 2015-04-27 15:05 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll
2015-05-12 15:25 - 2015-04-27 15:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-05-12 15:25 - 2015-04-27 15:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-05-12 15:25 - 2015-04-27 15:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-05-12 15:25 - 2015-04-27 15:05 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-05-12 15:25 - 2015-04-27 15:04 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2015-05-12 15:25 - 2015-04-27 15:04 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-05-12 15:25 - 2015-04-27 15:04 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe
2015-05-12 15:25 - 2015-04-27 15:04 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe
2015-05-12 15:25 - 2015-04-27 15:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe
2015-05-12 15:25 - 2015-04-27 15:04 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe
2015-05-12 15:25 - 2015-04-27 15:04 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-05-12 15:25 - 2015-04-27 15:04 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-05-12 15:25 - 2015-04-27 15:03 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-05-12 15:25 - 2015-04-27 15:03 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-05-12 15:25 - 2015-04-27 15:03 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-05-12 15:25 - 2015-04-27 15:03 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-05-12 15:25 - 2015-04-27 15:03 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe
2015-05-12 15:25 - 2015-04-27 15:03 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-05-12 15:25 - 2015-04-27 15:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-05-12 15:25 - 2015-04-27 15:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 14:06 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-05-12 15:25 - 2015-04-27 13:57 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-05-12 15:25 - 2015-04-27 13:57 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-05-12 15:25 - 2015-04-27 13:55 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 13:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 13:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-05-12 15:25 - 2015-04-27 13:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-05-12 15:25 - 2015-04-21 13:14 - 24971776 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-12 15:25 - 2015-04-21 12:50 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-12 15:25 - 2015-04-21 12:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-05-12 15:25 - 2015-04-21 12:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-12 15:25 - 2015-04-21 12:35 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-12 15:25 - 2015-04-21 12:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-05-12 15:25 - 2015-04-21 12:31 - 06025728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-12 15:25 - 2015-04-21 12:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-05-12 15:25 - 2015-04-21 12:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-05-12 15:25 - 2015-04-21 12:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-12 15:25 - 2015-04-21 11:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-05-12 15:25 - 2015-04-21 11:40 - 14401536 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-12 15:25 - 2015-04-21 11:27 - 02352128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-12 15:25 - 2015-04-12 23:28 - 00328704 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-12 15:24 - 2015-04-19 23:17 - 01647104 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-12 15:24 - 2015-04-19 23:17 - 01179136 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-12 15:24 - 2015-04-19 22:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-05-12 15:24 - 2015-04-19 22:11 - 03204608 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-12 15:24 - 2015-04-07 23:29 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-05-12 15:24 - 2015-04-07 23:29 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-05-12 15:24 - 2015-04-07 23:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-05-12 15:24 - 2015-03-04 00:41 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-05-12 15:24 - 2015-03-04 00:41 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-05-12 15:24 - 2015-03-04 00:41 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-05-12 15:24 - 2015-03-04 00:41 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-05-12 15:24 - 2015-03-04 00:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
2015-05-12 15:24 - 2015-03-04 00:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2015-05-12 15:24 - 2015-03-04 00:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-05-12 15:24 - 2015-02-18 03:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2015-05-12 15:24 - 2015-02-18 03:04 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2015-05-12 15:24 - 2015-01-28 23:19 - 02543104 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-05-12 15:24 - 2015-01-28 23:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-08 11:20 - 2009-07-14 00:45 - 00029120 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-08 11:20 - 2009-07-14 00:45 - 00029120 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-08 11:10 - 2014-02-17 20:00 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-08 11:10 - 2014-02-14 17:12 - 00000000 ____D C:\Users\Owner
2015-06-08 10:00 - 2014-02-14 17:12 - 01444090 _____ C:\Windows\WindowsUpdate.log
2015-06-08 09:47 - 2014-02-14 21:07 - 00003926 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{DE1642F8-AF94-4418-B8B6-FF4AA1184D50}
2015-06-08 09:47 - 2009-07-14 01:13 - 00781570 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-08 09:45 - 2015-03-05 22:12 - 00000000 ____D C:\Users\Owner\AppData\Local\Adobe
2015-06-08 09:45 - 2014-02-17 20:00 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-06-08 09:45 - 2014-02-17 20:00 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-08 09:45 - 2014-02-17 20:00 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-06-08 09:42 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-08 09:42 - 2009-07-14 00:45 - 00486888 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-08 01:50 - 2014-02-14 17:42 - 00127320 _____ C:\Users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT
2015-06-07 19:58 - 2014-04-01 20:41 - 00000000 ____D C:\Users\Owner\AppData\Roaming\uTorrent
2015-06-07 14:42 - 2009-07-13 22:34 - 00000505 _____ C:\Windows\win.ini
2015-06-07 02:05 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\system32\GroupPolicy
2015-06-07 00:36 - 2014-02-14 20:58 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-06-07 00:30 - 2014-04-01 20:34 - 00000000 ____D C:\Users\Owner\AppData\Roaming\DAEMON Tools Lite
2015-06-06 16:52 - 2009-07-13 23:20 - 00000000 __RHD C:\Users\Public\Libraries
2015-06-04 16:55 - 2014-02-17 20:09 - 00000000 ____D C:\ProgramData\Oracle
2015-06-04 16:55 - 2014-02-17 20:08 - 00000000 ____D C:\Program Files (x86)\Java
2015-06-04 16:54 - 2014-02-17 20:09 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-06-02 20:53 - 2014-04-01 20:57 - 00000000 ____D C:\Users\Owner\Desktop\Torrents
2015-06-02 13:32 - 2014-11-08 19:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-31 00:17 - 2014-04-01 20:56 - 00000000 ____D C:\Users\Owner\Desktop\ARRRRR
2015-05-30 22:51 - 2014-02-19 23:28 - 00001834 _____ C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Mail.Ru Agent.lnk
2015-05-29 11:19 - 2014-02-14 17:12 - 00000989 _____ C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-05-22 15:05 - 2014-02-21 01:29 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-05-21 15:18 - 2015-04-05 12:08 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-05-21 15:18 - 2015-04-05 12:08 - 00000000 ___SD C:\Windows\system32\GWX
2015-05-16 00:07 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\rescache
2015-05-14 00:45 - 2014-03-14 20:43 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-05-14 00:45 - 2014-03-14 20:43 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-05-14 00:43 - 2011-04-12 04:28 - 00000000 ____D C:\Program Files\Windows Journal
2015-05-14 00:43 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
2015-05-13 15:22 - 2014-02-17 19:05 - 00000000 ____D C:\Windows\system32\MRT
2015-05-13 06:56 - 2014-02-17 19:05 - 140425016 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-05-13 06:54 - 2014-03-14 20:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-05-12 18:39 - 2014-02-17 20:03 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
==================== Files in the root of some directories =======
2015-04-14 12:28 - 2015-04-14 12:28 - 0004387 _____ () C:\Users\Owner\AppData\Roaming\NMttF0Xg0cgJc72
2015-04-20 10:05 - 2015-04-20 10:05 - 1246720 _____ () C:\Users\Owner\AppData\Roaming\NMttF0Xg0cgJc72.exe
2014-09-04 08:40 - 2014-11-08 18:08 - 0000104 _____ () C:\Users\Owner\AppData\Roaming\WB.CFG
2015-06-06 17:19 - 2015-06-06 17:19 - 0002172 _____ () C:\Users\Owner\AppData\Local\recently-used.xbel
2015-06-07 22:13 - 2015-06-07 22:13 - 0000057 _____ () C:\ProgramData\Ament.ini
Some files in TEMP:
====================
C:\Users\Owner\AppData\Local\Temp\bitool.dll
C:\Users\Owner\AppData\Local\Temp\compete.exe
C:\Users\Owner\AppData\Local\Temp\cw.exe
C:\Users\Owner\AppData\Local\Temp\SRLDetectionLibrary2230249390790519917.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-06-03 17:05
==================== End of log ============================
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:07-06-2015
Ran by Owner at 2015-06-08 11:25:49
Running from C:\Users\Owner\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2586465260-67891513-3247288464-500 - Administrator - Disabled)
Guest (S-1-5-21-2586465260-67891513-3247288464-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2586465260-67891513-3247288464-1002 - Limited - Enabled)
Owner (S-1-5-21-2586465260-67891513-3247288464-1000 - Administrator - Enabled) => C:\Users\Owner
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-2586465260-67891513-3247288464-1000\...\uTorrent) (Version: 3.4.1.30740 - BitTorrent Inc.)
Acer System Information (HKLM-x32\...\{72199E33-4F2A-4B7F-8E25-95DDDD50A678}) (Version: 1.0.0 - Acer)
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.11) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\...\{21FC2093-6E43-460B-B9B0-5F5AA35BBB0F}) (Version: 3.0 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{FE86CB0C-FCB3-4358-B4B0-B0A41E33B3DD}) (Version: 7.1.0.32 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Atheros Driver Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Atheros)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
BlueStacks App Player (HKLM-x32\...\BlueStacks App Player) (Version: 0.9.27.5408 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM-x32\...\{C1F53C9F-C560-4292-9237-12786FE6BF62}) (Version: 0.9.27.5408 - BlueStack Systems, Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom Card Reader Driver Installer (HKLM\...\{4710662C-8204-4334-A977-B1AC9E547819}) (Version: 14.6.1.2 - Broadcom Corporation)
Broadcom NetLink Controller (HKLM\...\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 14.8.4.1 - Broadcom Corporation)
CCleaner (HKLM\...\CCleaner) (Version: 5.06 - Piriform)
CDisplayEx 1.10.29 (HKLM\...\CDisplayEx_is1) (Version:  - Progdigy Software S.A.R.L.)
CinemaPlus-3.2cV08.06 (HKLM-x32\...\CinemaPlus-3.2cV08.06) (Version: 1.36.01.22 - Cinema PlusV08.06) <==== ATTENTION
Combined Community Codec Pack 2014-01-17 (HKLM-x32\...\Combined Community Codec Pack_is1) (Version: 2014.01.17.0 - CCCP Project)
Consumer Input (HKLM-x32\...\Setup Support for Consumer Input) (Version: 1.0 - Software Service Inc.) <==== ATTENTION
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.0.0.0054 - Disc Soft Ltd)
Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
globalupdate Helper (x32 Version: 1.3.25.0 - globalupdate Inc.) Hidden <==== ATTENTION
GUC2100 (HKLM-x32\...\{CAAF899F-D15F-480F-AF10-22B1431A5E9F}) (Version: 1.00.0000 - )
HP Officejet Pro 8610 Basic Device Software (HKLM\...\{39DA3F40-0B9E-4002-8E01-108FEC9EFE43}) (Version: 32.3.198.49673 - Hewlett-Packard Co.)
HP Support Solutions Framework (HKLM-x32\...\{FC3C2B77-6800-48C6-A15D-9D1031130C16}) (Version: 11.51.0049 - Hewlett-Packard Company)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2342 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation)
iTunes (HKLM\...\{96B53CA8-5ABB-49D8-96F1-F6C0D73A76C6}) (Version: 11.1.4.62 - Apple Inc.)
Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
LibreOffice 4.4.3.2 (HKLM-x32\...\{A651A592-2F6C-4D66-AEA8-9BFE4B61BCB3}) (Version: 4.4.3.2 - The Document Foundation)
Mail.Ru Agent 6.4 (build 8614) (HKU\S-1-5-21-2586465260-67891513-3247288464-1000\...\MRA) (Version: 6.4.8614.0 - Mail.Ru) <==== ATTENTION
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 15.0.4719.1002 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-2586465260-67891513-3247288464-1000\...\SkyDriveSetup.exe) (Version: 17.0.2015.0811 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 38.0.5 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 38.0.5 (x86 en-US)) (Version: 38.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.0.3 - Mozilla)
Ninja Loader (HKLM-x32\...\Ninja Loader) (Version: 174.0.0.545 - C

RELEVANCY SCORE 200
Preferred Solution: Banners in Firefox window, unwanted programs, extra tabs opening in firefox.....

I recommend downloading and running DAP. It can help sort out any driver and firmware related issues on your system

It's worked out well for many of us in the past.

You can download it direct from this link http://downloaddap.org. (This link will open the download page of DAP so you can save a copy to your computer.)

A: Banners in Firefox window, unwanted programs, extra tabs opening in firefox.....

Hello! Welcome to BleepingComputer Forums!
My name is Georgi and and I will be helping you with your computer problems.
Before we begin, please note the following:
I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
The logs can take some time to research, so please be patient with me.
Stay with the topic until I tell you that your system is clean. Missing symptoms does not mean that everything is okay.
Instructions that I give are for your system only!
Please do not run any tools until requested ! The reason for this is so I know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.
Please perform all steps in the order received. If you can't understand something don't hesitate to ask.
Again I would like to remind you to make no further changes to your computer unless I direct you to do so. I will not help you if you do not follow my instructions.
 
Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop. Don't kill any malicious processes at your own.Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
Double-click to run it. When the tool opens click Yes to disclaimer.
Make sure that Addition.txt is checked before you press the Scan button.
Press Scan button.
It will make 2 logs (FRST.txt and Addition.txt) in the same directory the tool is run. Please copy and paste them to your reply.
 
 
Regards,
Georgi

Read other 20 answers
RELEVANCY SCORE 110

Hello. I am experiencing the following problems:

1) When i click on links returned by Google searches, I am frequently redirected to web pages which are in no way connected to the link I clicked on and are generally some ad for a product or service,

2) Unwanted new tabs are frequently opening spontaneously (i.e., with no input from me) in Firefox 3.5.9 (which I'm using instead of 3.6.x because it's incredibly slow, crash-prone, and uses stunning amounts of memory) and these tabs generally contain an ad for some product or service, and

3) Microsoft Update will not function.

So that you'll know, I'm running Windows XP Pro and have run avast! Free Antivirus (version 5.0.545), Spybot Search & Destroy (version 1.6.2.46), and Malwarebytes' Anti-Malware (version 1.46), all of which I keep up to date, and none of them have discovered any problems. Also, I was infected this past weekend with whatever virus/malware causes all kinds of popups telling you that every program you attempt to run is infected and turns your desktop green, but was able to use your instructions here together with Malwarebytes' Anti-Malware to apparently get rid of it. That said, it may be helpful to know that before this infection, none of the problems enumerated above were occurring.

Naturally, I would appreciate any assistance that anyone with expertise in resolving these issues may be able to offer. Many thanks in advance...

A:Google Redirects, Unwanted Tabs Opening in Firefox, MS Update Will Not Work...

Is no one going to help me here? This topic has been viewed 29 times and not one person has replied. Am I doing something wrong? If so, please advise. If not, please help.

Thank you.

Read other 2 answers
RELEVANCY SCORE 104.8

Hi,
Since this is my first post please pardon me for posting in wrong section, if I did.
 
From last few days I am noticing strange problems in firefox
On each boot, when I open Mozilla Firefox, few tabs and windows (around 3-4) automatically gets open.
They contain the following address
https://photos-a.xx.fbcdn.net/hphotos-prn1/hellocdn.html?v=1

I have searched a bit and found out its a some kind of malware (AFAIK).
But i don't know the root cause of this problem and how eliminate it.
 
Any help to remove this malware is much appreciated
Screen shot of automatically opened tab:http://s21.postimg.org/qr1flzjzb/screenshot_188.png
 
Regards
Abhisheak
 

A:Multiple tabs and window opening automatically in firefox: photos-a.xx.fbcdn.net

Welcome aboard
 
Is Firefox the only browser affected?

Read other 5 answers
RELEVANCY SCORE 92.8

While running Firefox, lately a new tab has been popping up, unwanted. Here is the link that opens:

hxxp://www.w€g'Ú7®$´b-îá4…z.com/

It doesn't lead anywhere. It happens whenever I go to a new page/site. Sometimes 1 pops up, other times 2-4 come up, all the same URL.

I have multiple anti malware programs installed, but nothing has caught this.

Help?

A:Unwanted tabs popping up in Firefox

Welcome aboard Download Security Check from HERE, and save it to your Desktop. * Double-click SecurityCheck.exe * Follow the onscreen instructions inside of the black box. * A Notepad document should open automatically called checkup.txt; please post the contents of that document.=============================================================================Please download MiniToolBox and run it.Checkmark following boxes:Report IE Proxy SettingsReport FF Proxy SettingsList content of HostsList IP configurationList last 10 Event Viewer logList Users, Partitions and Memory sizeClick Go and post the result.=============================================================================Download Malwarebytes' Anti-Malware (aka MBAM): http://www.malwarebytes.org/products/malwarebytes_free to your desktop. * Double-click mbam-setup.exe and follow the prompts to install the program. * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. * If an update is found, it will download and install the latest version. * Once the program has loaded, select Perform quick scan, then click Scan. * When the scan is complete, click OK, then Show Results to view the results. * Be sure that everything is checked, and click Remove Selected. * When completed, a log will open in Notepad. * Post the log back here.Be sure to restart the computer.The log can also be found here:C... Read more

Read other 33 answers
RELEVANCY SCORE 90.8

I launch Firefox, and almost immediately am interrupted by ten or so new tabs unexpectedly opening, with paid-for ad sites like news7daily.tv, and a few raunchy sites. Later I get random redirects, too, after closing all the tabs.

Last week I installed and ran malwarebytes' anti-malware software, because I was seeing similar unwanted behavior (redirects, pop-ups, continually checking "allow third party cookies".) I killed a couple processes (xxx.exe) and deleted a program whose name I have forgotten, but which another discussion forum identified as malicious. I thought it was fixed, but the issues cropped back up after a few days. I did not have Windows firewall on, I discovered today, which is unfortunate, as it might have saved me a lot of trouble.

Thanks in advance for your help!

-Sid

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_27
Run by Owner at 19:43:47 on 2012-01-05
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1277.66 [GMT -6:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
sv... Read more

A:Ad malware opens dozens of unwanted tabs in Firefox

Hello and Welcome to the forums! My name is Gringo and I'll be glad to help you with your computer problems. Somethings to remember while we are working together.Do not run any other tool untill instructed to do so!please Do not Attach logs or put in code boxes.Tell me about any problems that have occurred during the fix.Tell me of any other symptoms you may be having as these can help also.Do not run anything while running a fix.Do not run any other tool untill instructed to do so!Click on the Watch Topic Button and select Immediate Notification and click on proceed, this will help you to get notified faster when I have replied and make the cleaning process faster.Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.Run Combofix:You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<Combofix may need to reboot your computer more than once to do its job this is normal.You can download Combofix from one of these links.Link 1Link 2Link 3 1. Close any open browsers or any other programs that are open.2. Close/disable all anti virus and anti malware programs so they do not interfere with the r... Read more

Read other 3 answers
RELEVANCY SCORE 90.4

i am getting tabs such as 
http://--load-component-extension%3Dc/Program%20Files/Google/Chrome/Application/Extensions/chrome/man
when i start up chrome  that only started after i managed to get rid of some extension coupon malware(i thought)
it brings up 4 blank tabs with names like that and they do nothing as far as i know, how can i fix these.

A:getting unwanted extra tabs that are not in the tabs list on startup

Hi there,my name is Marius and I will assist you with your malware related problems.Before we move on, please read the following points carefully.First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.Perform everything in the correct order. Sometimes one step requires the previous one.If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem.Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me.Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.Important: To help me reviewing your logs, please post them in code boxes. You can create them by clicking on the <>-symbol on top of the reply window.    HijackThis is not the preferred initial scanning tool in this forum. With today's malware, a more comprehensive set of logs i... Read more

Read other 48 answers
RELEVANCY SCORE 89.2

Is there anyway of getting Firefox to open with say, 3 tabs open with certain things already in them, like Hotmail and Techspot and stuff... instead of just having them in "bookmark tabs".... Can I do that? I don't think there is any option is the "settings" part.
 

A:Firefox Opening With Tabs?

I don't know offhand, but you could try searching addons.mozilla.org, their extensions/add-ons site, for an extension that customizes your tabs like that.
 

Read other 3 answers
RELEVANCY SCORE 89.2

HelloThis started with a nasty virus called antimalware doctor in my task bar downloaded through a torrent.... Also, google would redirect and new tabs would open.It seems the majority of it has gone using spybot and malware bytes but new tabs STILL are opening in firefox.Scans follow - two attachments dds and gmerUPDATE: Google still redirects.DDS (Ver_10-03-17.01) - NTFSx86 Run by Me at 18:49:30.18 on 20/08/2010Internet Explorer: 8.0.6001.18702Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.2046.1382 [GMT 1:00]FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}============== Running Processes ===============C:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\WINDOWS\System32\svchost.exe -k netsvcsC:\WINDOWS\system32\svchost.exe -k WudfServiceGroupC:\Program Files\Intel\Wireless\Bin\S24EvMon.exesvchost.exesvchost.exeC:\WINDOWS\system32\ZoneLabs\vsmon.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exesvchost.exeC:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exesvchost.exeC:\Program Files\Intel\Wireless\Bin\EvtEng.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEC:\WINDOWS\System32\svchost.exe -k HPZ12C:\WINDOW... Read more

A:Firefox opening new tabs!

Hello, Large Banana.OK, you were definitely infected. A few questions before we get started:1. Do you have an antivirus installed? The DDS log didn't show it, but I'm not sure if you disabled it before running hte DDS Log.2. Do you only have issues in Firefox, or are they also present in Internet Explorer?P2P Warning and RequestThe log shows that you have been using so called peer-to-peer or file-sharing programmes (in your case uTorrent). These programmes allow to share files between users as the name(s) suggest. In today's world the cyber crime has come a long way and any means is used to infect personal computers to make use of their stored data or machine power for further propagation of their malware files. A popular means is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it.It is therefore possible to be infected by downloading manipulated files via peer-to-peer tools and thus suggested to be used with intense care. I recommend that you uninstall this program. That is optional, however. If you decide to not uninstall, please refrain from using it until I let you know your computer is clean.Registry Cleaner WarningI also see that you have a Ccleaner installed. It is a great tool that I use. However, be careful of the registry cleaning functionality (versus file cleaning), Here at BC, we do not recommend using registry cleaners as they don't speed up your computer and they can do mor... Read more

Read other 23 answers
RELEVANCY SCORE 89.2

I've seen this posted a lot but i dont want to try anything on my own.....If someone could please help me, i would greatly appreciate it

My computer is infected with a virus, series of trojans that cause IE/Firefox to open new windows/tabs.

I have Windows XP
Spybot Search and Destroy
AVG
Ad-Aware Personal Edition

AVD detected two trojans yesterday but it didn't fix the problem. As someone else posted, most of the time i'm getting a pop-up for the www.sagipsul website. Could someone please help me? I'm a quick learner! Thanks

A:FIREFOX KEEPS OPENING NEW TABS/POP-UPS

Please download MalwareBytes Anti-Malware to your desktop.Ensure that your computer is connected to the internet and your software firewall is disabled until instructed to re-enable it.Double click on the mbam-setup.exe to begin the installation process.When the installation begins, please do not change any of the settings and follow the prompts.Please make sure that when you finish the installation, these options remain checked; *Update MalwareBytes' Anti-Malware *Launch MalwareBytes' Anti-MalwareYou may now click finish...When MBAM launches, you will be prompted to update before running a scan. If an update is found, MBAM will automatically download and apply the updates and you can then click 'OK' button to close the box and continue. You may now re-enable your firewallPlease ensure that while you are on the scanner tab the 'Perform Quick Scan' option is selected, then click the 'Scan' button.If you are asked which drives to scan, please leave all of them ticked, and click 'Start Scan'.The scan will now begin and you will see ?Scan in progress? at the top; It may take a while to complete so please be patient.When the scan completes, you will see ?The scan completed successfully. Click 'Show Results' to display all objects found?Click the 'OK' button to close the box and continue with the removal process.Back on the main scanner screen, click 'Show Results' to see a list of any found Malware.Ensure that all it... Read more

Read other 7 answers
RELEVANCY SCORE 88.4

I started using Firefox and I am looking to keep the open windows to a minimum because on many sites as I'm kind of concentrating on the top menu bar and the open windows, meanwhile on the task bar i can see the FF icon's outline stacking of other windows open but not until i hover over with mouse do i realize all these windows have spun out to the far right and was when one of them was playing over the current video clip i had playing.

Is there a configuration method to tone down the number of links or whatever derives from the current window or video, etc...that interrupts and bleeds over into the current windows desired to be open?

Read other answers
RELEVANCY SCORE 88.4

Hi all,

Anyone have any thoughts? Keep getting redirected to different sites.

I've ran updated Malywarebytes, Spybot S&D and even AdAware but cannot strip it out.

Using processexplorer to search through I cannot find anything too strange.

Anyone see anything strange in the HijackThis Log attached? Any help would be great!

Thanks
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\Symant... Read more

A:Firefox redirecting and opening up new tabs...

Hello, teriblet.My name is aommaster and I will be helping you with your log.I apologize for the delay in response we get overwhelmed at times but we are trying our best to keep up.If you have since resolved the original problem you were having, I would appreciate you letting us know. If not please perform the following below so I can have a look at the current condition of your machine.ThanksShould you still require assistance, please take note of the points below:Please track this topic by either adding it to your favourites or clicking the Options button at the top of this thread and then Track this topic.Please disable word-wrap before posting logs. This can be done by clicking Format and un-ticking the word-wrap feature in notepad. The logs that you post should be copied and pasted directly into the reply. Only attach them if requested or if they do not fit into the post.If you do not reply within 5 days, I will have to close your topic. Should you not be able to meet this, please notify me so that I will leave the topic open.Please do not install, update, or run any programs for the duration of the fix.If you do not understand the instructions I provide, please don't hesitate to ask. That's what I'm here for Please continue to reply to this topic until I give you the all clean. Just because there are no symptoms of infection doesn't mean that the computer is clean.If you are running Vista or Windows 7, please run all the fixes as an administrator. This ... Read more

Read other 3 answers
RELEVANCY SCORE 88.4

Hey guys.I'll be brief, i'm being a little interrupted right now so I have to skim over the problem as quick as I can! Sorry!(Also, since this is my first post; I'm David. Nice to meet you all. (: )Firstly, a little about me and my computer. I'm very, very OCD about keeping my computer organized, clean and error free. That said, I usually format every 2-3 months and can get my computer back to how I like it in about 3-4 hours. I work as a technician at a small computer repair shop, and viruses are easily our number 1 problem there.I'm very experienced with removing them through a myriad of programs that are the standard from what i've seen on the site. My usual toolbox would be Combofix > Smitfraudfix > MalwareBytes > Avast > Hijack This > CCleaner. Of course that won't clean everything and more work would be required for harder to remove ones, etc.tl;dr and extension; I'm more than capable when it comes to computers, viruses, and the like. I don't require a 'simple-version' of instructions. :DNow, my problem. I've tried searching on the forum for similar problems but Firefox, Google, viruses, tabs and other words ive used are just way too general! I promise I tried. .__.;Basically here's what's happened. After formatting my computer a matter of days ago, I installed Firefox, my usual addons, my usual about:config edits, everything. Like I said before, I have an obsession with organization so i... Read more

A:Firefox Opening Tabs, Adverts, etc.

I CAN'T WAIT TO BOMB THIS VIRUS!

It's been annoying the shizzle out of me all morning long. But rest assured I will always find out what the hell is going on.

C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll

here's your likely murder. Use Security Task Manager or other type program to isolate it and soft delete it. Don't worry about that folder's parent, I believe it just latched itself in there to be annoying. Just delete the Search Helper folder and you should be good.

Read other 5 answers
RELEVANCY SCORE 88.4

My computer has decided to become a pain in my rear end lately. I have had so many things happen to me it's just ridiculous, and there's only one I can't seem to get rid of. It's something that keeps opening new tabs to random websites on my browser. Also, I have noticed that this malware likes to interfere with some of the pages I want to visit (such as your website) and others. Another thing that I think has to do with it is that I cannot successfully install and run Google Chrome, because it will sit there for 20 minutes and never load a page, or it will tell me that it crashed and that will be the end of it.I am worried that I am going to need to reformat but before I do I need to see if there is any other solutions.I am aware that this website has previously dealt with this same issue, and therefore i felt the obligation to send you this problem as well. I have ran everything that was recommended to me, and bought the internet security version of Avast Antivirus even. Also, I have run Spybot S&D and Malwarebytes. I just now recently did a system restore, hoping that in some strange universe it might actually get rid of this thing wreaking havoc on my brain.Though, there is a difference between me and the last guy you helped. I do not know what I should post here to help you out, I am rather new to all the tech things for computers though I will say I am far above average in users. I just don't want to have to call my father on this one, seeing as ... Read more

A:Firefox/IE8 Opening Random Tabs

What did those malware tools find? Can you post those logs here?

Read other 22 answers
RELEVANCY SCORE 88.4

Hey GuysI really do need your help,i am currently using , Avg free, Spybot s&d , And malware bytes My firefox keeps opening new windows with 4 tabs opening up everytime here is whats the each tabs have in the url bar;file:///C:/Documents%20and%20Settings/Matt/http://???t?/hxxp://yS%C2%A4%C2%B6%1An8%C3%90%10%11%E2%80%A1m%15%40%01Xg5%C3%B5%C2%A3%C3%A5W%C3%95%0E%C3%95%E2%80%94%C2%A8%C3%92%C3%9C%C2%8D%E2%80%B9+%C2%[email protected] tq3a}-jra04cm9dn1i/;%1F%C3%B6%C2%B8&%C3%B2%C2%B0%E2%80%94U%C3%8E%11%14UD:%E2%80%93%C3%AE%C3%A1%C3%B4%C3%94v%C3%B6%C3%8F%E2%80%B0%%C3%B3%C3%95%CB%9C#q+%C2%BA5w%C3%90%27%C3%BC%[email protected]%C3%AF%E2%80%A0%04%C3%94%C3%88%C3%86%13%02%C3%93Ws%C2%BE%E2%80%94S%C3%8DjL%C3%9C%C3%84%%C2%BA-f%C2%BAr%C6%928%1F%C3%98\%C3%83%E2%84%A2:hxxp://g?_,???c?~?q???????????????up?????????[n?e?4????6%????`~7$ok????????{u???????????5{q????a??/@%C3%8BE%200%C3%9D%C3%A3QB%E2%80%94%C3%BDA!M%C3%8A%C3%BCA%C3%A3%C2%B34%C3%85%C3%B7%C3%A7%C2%B5%E2%80%94?%1E%9F%FC%CD%BA%F5R2%D6%99%F9Tj%ABq%EFq]%F1%C1%99%F6%02%AF%0CqH%B7%ED%20P%0E%89,f.%B8%A0%C5W.%07%18M%F7%8B%AE%90

i dont really have much experience with computer viruses, so i really need help , Heres my hijack this scan log

Matt

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:02:25, on 04/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Runnin... Read more

A:My FireFox Keeps Opening More and More tabs and windows

Hello Matthew94 Welcome to the BC HijackThis Log and Analysis forum. I will be assisting you in cleaning up your system.I ask that you refrain from running tools other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.In the upper right hand corner of the topic you will see a button called Options. If you click on this in the drop-down menu you can choose Track this topic. By doing this and then choosing Immediate E-Mail notification and then clicking on Proceed you will be advised when we respond the your topic and facilitate the cleaning of your machine.After 5 days if a topic is not replied to we assume it has been abandoned and it is closed.I need for you to perform the following:Download DDS and save it to your desktop from here or here.Disable any script blocker, and then double click dds.scr to run the tool. When done, DDS will open two (2) logs: DDS.txt Attach.txtSave both reports to your desktop then post the DDS.txt in the reply window and attach the otherDownload GMER Rootkit Scanner from here to your desktop. Double click the exe file. If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO, then use the following settings for a more complete scan.

Click the image to enlarge it
In the right panel, you will see several boxes that have bee... Read more

Read other 11 answers
RELEVANCY SCORE 88.4

Hey guys, I have a quite a bit of a problem here. I recently installed Windows 7 (about 1 month), and now Firefox decides to randomly visit urls, like monstershopmarket or something. The wierd thig is that I think they are taking things i type into Google and using them in other sites that pop up. I tried changing my web browser, but nothing helped. Im somewhat of a noob when it comes to security because I never had serious problems like this. Also, this doesnt occur in any other comp in my house, so its probably not my router. And I really want to stray away from reinstalling a brand new copy. Please help guys.

-cyborg129

A:Random Tabs opening on Firefox

Hey Budapest, I happen to have a similar problem and so far I have followed your advice. Would mind tackling both of our problems at once? Or would that be too much of a problem. I have a topic open fro my problem, but I have yet to receive responses. Here is my GMER log.GMER 1.0.15.15281 - http://www.gmer.netRootkit scan 2010-04-19 21:23:48Windows 6.1.7600 Running: h271miwc.exe; Driver: C:\Users\OWNER~1\AppData\Local\Temp\ufkiiuow.sys---- Kernel code sections - GMER 1.0.15 ----.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82A4F579 1 Byte [06].text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82A73F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}? System32\Drivers\spgy.sys The system cannot find the path specified. !.text USBPORT.SYS!DllUnload 8DE4CCA0 5 Bytes JMP 85B031D8 PAGE win32k.sys 92F00000 11 Bytes [90, 90, 90, 90, 90, 6A, 0C, ...]PAGE win32k.sys 92F0000C 49 Bytes CALL 92D98CF4 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)PAGE win32k.sys ... Read more

Read other 17 answers
RELEVANCY SCORE 88.4

Yes, I know I've had the same problem before, but now it's a different machine. I'm not sure if I can apply the same steps as before so here's a new HJT log.

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 20:50:00, on 03.07.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Thomson SpeedTouch\ST330\service\st330service.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Thomson SpeedTouch\ST330\diagnostics\diagnostics.exe
C:\Windows\system32\isys32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Launchy\Launchy.exe
C:\WINDOWS\system32\ntvdm.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Progra... Read more

A:Firefox opening random tabs again.

I thought you reformatted this machine. Where did those things come from?

Open notepad and copy/paste the text in the quotebox below into it:


Code:
File::
C:\Windows\system32\isys32.exe
Folder::
C:\Documents and Settings\Lumi\Policies
Driver::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MonAppli"=-
"catsrv"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"catsrv"=-
Save this as ComboFix-Do.txt




Refering to the picture above, drag ComboFix-Do.txt into ComboFix.exe
Then post the resultant log

Read other 5 answers
RELEVANCY SCORE 88.4

I really like Firefox over IE, but for the last several months, Firefox is spontaneously opening new tabs on its own. I've done research on how to fix this issue and here's what I've done...

-I've un and re-installed at least 4 times

-I've run Super Anti Spyware, Malware Bytes, and Ad Ware and eliminated all infections these programs found

-I've changed some of my add-on features

-I've even tried to replace the ws2_32.dll file (with no luck)

I'm getting really annoyed with this! What else can I try to make this stop happening? Any advice is welcome and much appreciated!!

A:Firefox is opening new tabs and re-directing

Hello as it appears you are infected I will move this to the Am I Infected forum. Let's see if we can get some more results.Reboot into Safe Mode with Networking How to enter safe mode(XP)Using the F8 MethodRestart your computer. When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with a Windows XP Advanced Options menu. Select the option for Safe Mode with Networking using the arrow keys. Then press enter on your keyboard to boot into Safe Mode. >>>> Download this file and doubleclick on it to run it. Allow the information to be merged with the registry.RKill....Download and Run RKillPlease download RKill by Grinler from one of the 4 links below and save it to your desktop.

Link 1
Link 2
Link 3
Link 4

Before we begin, you should disable your anti-malware softwares you have installed so they do not interfere RKill running as some anti-malware softwares detect RKill as malicious. Please refer to this page if you are not sure how.
Double-click on Rkill on your desktop to run it. (If you are using Windows Vista, please right-click on it and select Run As Administrator)
A black screen will appear and then disappear. Please do not worry, that is normal. This means that the tool has been successfully executed.
If nothing happens or if the tool does not run, please... Read more

Read other 1 answers
RELEVANCY SCORE 88.4

I have been using Firefox for a while and just recently installed it on my parents computer. On my computer, when I click the wheel over a link it opens in a new tab. Also when I click the left and right mouse buttons at the same time, it opens the link in a new tab. However, on my parents computer, only the wheel works for opening it in a new tab, not the left and right combo. Now I can't remember out how I got it working on my computer. Does anyone know how to turn this feature on or off?
 

Read other answers
RELEVANCY SCORE 88.4

Hey, just wondering if anyone could have a look at my log file to see if there is anything wrong. Basically i had the sdra64 virus and some other trojans and have cleaned them. But now firefox opens new tabs with search results from different websites. really annoying.I have ran malwarebytes, ad aware, spybot, super anti spy, windows defender and none of them can find any problems.My log file isRunning processes:C:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Program Files\Alwil Software\Avast5\AvastUI.exeC:\Program Files\Common Files\Java\Java Update\jusched.exeC:\Windows\system32\taskeng.exeC:\Program Files\Trusteer\Rapport\bin\RapportService.exeC:\Windows\system32\wbem\unsecapp.exeC:\Program Files\Lavasoft\Ad-Aware\AAWTray.exeC:\Windows\system32\ctfmon.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Thomas\Desktop\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.philips.com/pcR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.philips.com/pcR1 - HKLM\Software... Read more

Read other answers
RELEVANCY SCORE 88.4

FireFox keeps opening new tabs periodically to different websites. It screams malware but neither SpybotSD nor Avast! could find anything.

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 14:24:17, on 29.06.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Documents and Settings\maest\Policies\catsrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\system32\isys32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Launchy\Launchy.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.ex... Read more

A:[SOLVED] FireFox opening new tabs

Do a HijackThis scan & place a check next to these items and select "Fix checked":

F3 - REG:win.ini: load= C:\BC5\PIPELINE\remind.exe
O4 - HKLM\..\Run: [catsrv] C:\Documents and Settings\maest\Policies\catsrv.exe
O4 - HKLM\..\Run: [MonAppli] C:\Windows\system32\isys32.exe
O4 - HKCU\..\Run: [catsrv] C:\Documents and Settings\maest\Policies\catsrv.exe -AutoStart


---------------


1. Download & save this file to Desktop -> http://download.bleepingcomputer.com...a/ComboFix.exe

2. Double click on combofix.exe & follow the prompts.

3. When finished, it shall produce a log for you. Post that log & a fresh HJT log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Read other 7 answers
RELEVANCY SCORE 87.2

When i'm running firefox. Ads will randomly appear in a new tab, sometimes using my last google search, it would bring up something somewhat related. This has been happening for about 4 days now. I've tried using Ad-Aware, Combofix, Spybot Search and Destroy, and AVG. None of it has worked. Also, sometimes my windows taskbar changes into a windows 98 look. I have all of my logs right hereDDS (Ver_10-03-17.01) - NTFSx86 Run by Chris at 14:03:16.26 on Sun 04/18/2010Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_19Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3063.2483 [GMT -7:00]============== Running Processes ===============C:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\WINDOWS\System32\svchost.exe -k netsvcssvchost.exesvchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Analog Devices\Core\smax4pnp.exeC:\Program Files\ASUS\TurboV\TurboV.exeC:\WINDOWS\system32\RUNDLL32.EXEC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Common Files\Java\Java Update\jusched.exeC:\Program Files\Logitech\SetPoint\SetPoint.exeC:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXEsvchost.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Progra... Read more

A:Browser keeps getting Hijacked by ads and opening up new tabs in Firefox

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process. Please also continue to work with me until I give you the all clear. Even if your computer appears to act better, you may still be infected.Even if you have already provided information about your PC, we need a new log to see what has changed since you originally posted your problem.Once we start working together, please reply back within 3 days or this thread may be closed so we can help others who are waiting.We need to create an OTL report,Please download OT... Read more

Read other 2 answers
RELEVANCY SCORE 87.2

Hello all.


I really enjoy using firefox's tabbed interface, and it works great for 99% of webpages, but one website I have to use uses javascript links, and when I middle click the links I get a blank page. I've tried the smart middle click extension for firefox, and also the javascript in new tab script for greasemonkey. Neither will work properly with the site. The greasemonkey script duplicates the original tab, instead of opening the desired page, while the smart middle click link basically does nothing on this site.

The links on the website are like this:
javascript:go2TechNotes('******')
the ****** is just letters and numbers.


Is there a way to modify the "javascript in new tab" script to make it work properly? If I could get it to duplicate the tab first, then run the javascript after the new tab has loaded, it would be great.

Here's the script I want to modify (it is ok to modify someone else's script right?).
http://www.arantius.com/misc/greasemonkey/javascript-in-new-tab.user.js

I don't know a lot about scripts or programming, so take it easy on me.
Thanks.
 

A:Help with opening javascript links in new tabs with firefox.

it's not the fault of the javascript

pages are written for Frames or NoFrames and you can tell the difference
by looking at the ANCHOR tag (ie the link)

Code:
<a target="xxx" href="<script ..>foo();</script>">click here</a>
the XXX is the name of the window to display the results from the foo() script

If it is NOT written in this style, right-click for new tab will get exactly what you report, and there's nothing you can do about it.
 

Read other 6 answers
RELEVANCY SCORE 87.2

Hi all,

Recently I followed a link in a forum that supposedly installed the aurora hijack. I thought nothing of it as I have had no symptons. Until now. I cannot confirm this is the issue, but other members of the forum have said this.

This morning I started a chat with my dad in facebook, and everytime I pressed enter to send the message, two new tabs open in firefox with some car sales web page. The issue is ongoing in firefox at various times when pressing enter.

I installed hijack this, but did nothing other than the scan. I then remembered this site.

Logs as requested, thanks in advance.


.
DDS (Ver_2011-06-23.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514
Run by PJ at 19:44:16 on 2011-06-29
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.8029.5891 [GMT 8:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\sy... Read more

A:New Tabs opening in Firefox after pressing enter

Hello, Welcome to TSF.
I'm nasdaq and will be helping you.

You may wish to Subscribe to this thread (Thread Tools > Subscribe to this thread) so that you are notified when you receive a reply.

Please read these instructions carefully and then print out or copy this page to Notepad in order to assist you when carrying out the fix.

Note that the fix may take several posts. Please continue to respond to my instructions until I confirm that your logs are clean. Remember that although your symptoms may vanish, this does NOT mean that your system is clean.

If there is anything you don't understand, please ask BEFORE proceeding with the fixes.

Please ensure that you follow the instructions in the order I have them listed.

Please do not install or uninstall any programs, or run any other scanners or software, unless I specifically ask you to do so. Also please copy and paste logs into the thread, rather than add them as attachments.
===

Please download ComboFix from any of the links below, and save it to your desktop. For information regarding this download, please visit this web page: A guide and tutorial on using ComboFix

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

IMPORTANT....

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Do not install any other programs until this if fixed.

How to : Disable Anti-virus and Fir... Read more

Read other 2 answers
RELEVANCY SCORE 87.2

Hey guys. I recently removed a couple viruses using MalwareBytes Malware remover, but I'm still seeing some strange behaviour with Firefox. Every now and then, when I click a link to open it in a new tab, I actually get 2 tabs, with the second one being some kind of advertising page.I ran HijackThis, and it advised me to post the log output to a forum such as this one. I was hoping someone might be able to take a quick look and tell me if you see anything out of the ordinary. At the time I ran HijackThis, I was also doing an AdAware scan. Anyway, here's the log:-----------------------------------Logfile of Trend Micro HijackThis v2.0.4Scan saved at 8:16:37 PM, on 8/24/2010Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Acronis\Schedule2\schedul2.exeC:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\WINDOWS\system32\nvsvc32.exeC... Read more

A:Firefox opening random tabs - with HijackThis log

Hello , And to the Bleeping Computer Malware Removal Forum. My name is Elise and I'll be glad to help you with your computer problems.I will be working on your malware issues, this may or may not solve other issues you may have with your machine.Please note that whatever repairs we make, are for fixing your computer problems only and by no means should be used on another computer.The cleaning process is not instant. Logs can take some time to research, so please be patient with me. I know that you need your computer working as quickly as possible, and I will work hard to help see that happen. Please reply using the Add/Reply button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.Unfortunately, if I do not hear back from you within 5 days, I will be forced to close your topic. If you still need help after I have closed your topic, send me or a moderator a personal message with the address of the thread or feel free to create a new one.You may want to keep the link to this topic in your favorites. Alternatively, you can click the button at the top bar of this topic and Track this Topic, where you can choose email notifications. The topics you are tracking are shown here.-----------------------------------------------------------If you have since resolved the original problem you were having, we would appreciate you... Read more

Read other 2 answers
RELEVANCY SCORE 87.2

Hello! I'm completely new here and honestly not nearly so technologically-inclined as many of those here on the forums, so I'm hoping that I won't be too much of  a bother to assist. Before I go about posting my DDS results, I'll explain a little bit about the problems I've been having.
 
For the past few days - I'd say maybe five now? - I've been having tabs spontaneously opening themselves in Firefox (the only browser I use with any regularity) without my prompting. They're all to obviously problematic websites - Vube.com, several "online casinos" and "FLV players", to name a few. (I notice that these have come up before on the forums, but the circumstances aren't the same, exactly.) The puzzling part is that nothing seems to be obviously detectable...
 
I've run Malwarebytes Anti-Malware, SuperAntiSpyware, and Spybot Search and Destroy, all updated, and found absolutely nothing. I've run MBAR and TDSSKiller, and also found nothing (well, nothing with MBAR at all and nothing that seemed to be of any consequence in TDSSKiller). Checking for malicious programs and extensions proved fruitless. In short, all of the obvious methods of detecting the problem have failed - this leads me to believe I have something like a rootkit (and I'm paranoid because I've never dealt with one of these before, nor have I run a recovery disc before).
 
I'm on a Windows 7 64-bit Home Premium Sager computer, with 12 GB RAM and an Intel i7 @ 2.40 GHz (I can provide any other info... Read more

A:Tabs consistently opening without prompts in Firefox

Hello and welcome to Bleeping Computer! I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.
We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.
To help Bleeping Computer better assist you please perform the following steps:
*************************************************** In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/506786 <<< CLICK THIS LINK
If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.
***************************************************If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of t... Read more

Read other 2 answers
RELEVANCY SCORE 87.2

EDIT:Moved to proper forum,Virus, Trojan, Spyware, and Malware Removal Logs ~~boopmeLogfile of Trend Micro HijackThis v2.0.4Scan saved at 12:15:27 AM, on 6/22/2010Platform: Windows 7 (WinNT 6.00.3504)MSIE: Internet Explorer v8.00 (8.00.7600.16385)Boot mode: NormalRunning processes:C:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Program Files\Raxco\PerfectSpeed20\PerfectSpeed.exeC:\Program Files\Grammar Check Anywhere\Grammar Check Anywhere.exeC:\Program Files\Java\jre6\bin\jusched.exeC:\Program Files\Ad Muncher\AdMunch.exeC:\Program Files\ESET\ESET Smart Security\egui.exeC:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exeC:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exeC:\Program Files\Windows Sidebar\sidebar.exeC:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exeC:\Program Files\Spybot - Search & Destroy\TeaTimer.exeC:\Program Files\BatteryCare\BatteryCare.exeC:\Program Files\Vista Start Menu\VistaStartMenu.exeC:\Program Files\CBS Software\SpeedConnect Internet Accelerator\SpeedConnectStartUp.exeC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exeC:\Program Files\Creative Home\Hallmark Car... Read more

A:Firefox browser tabs opening at random

Hello and Welcome to the forums! My name is Gringo and I'll be glad to help you with your computer problems. Somethings to remember while we are working together.Do not run any other tool untill instructed to do so!Do not Attach logs Tell me about any problems that have occurred during the fix.Tell me of any other symptoms you may be having as these can help also.Do not run anything while running a fix.Do not run any other tool untill instructed to do so!In the upper right hand corner of the topic you will see a button called Options. If you click on this in the drop-down menu you can choose Track this topic. By doing this and then choosing Immediate E-Mail notification and then clicking on Proceed you will be advised when we respond to your topic and facilitate the cleaning of your machine.Note** If you are having problems posting the complete log into this thread upload them here http://www.rapidshare.com/ and post the links in this thread Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.I would like to get a new set of logs Please.DeFogger: Please download DeFogger to your desktop.Double click DeFogger to run the tool. The application window will appear Click the Disable button to disable your CD Emulation drivers Click Yes to continue A 'Finished!' message will appear Click OKDeFogger may ask you to reboot the machine, if it does - click OKDo not re-... Read more

Read other 11 answers
RELEVANCY SCORE 87.2

The honest truth, and this hurts. I typically take as much caution as I can when I'm on the Internet, but the other night I left iTunes running to download some music podcasts when I went to bed. The next morning my wireless network icon was gone, and so was my battery icon. I restarted my computer and suddenly Firefox started opening new tabs on it's own with advertisements for anything from "win cash prizes" to "your computer is infected. download registry defender!"I googled the issue and ran malwarebytes anti-malware, superantispyware, then adaware. I also moved from AVG to Microsoft Security Essentials. Each program found and removed numerous different issues and problems, but it's still doing the same thing.As a side note, if I google any type of problem, such as "firefox virus" or "firefox opening new tabs", my browser will present the search results, but not take me to the result when I click on it. Instead it will take me to some obscure "buy me" or yahoo web page. I also can NOT get my network icon or battery icon to show back up. I've tried enabling and disabling both of them and they will not show.I've run ATF, DDS, and GMER and the DDS and GMER results are below this. Any help will be greatly appreciated.I'm not against formatting my hard drive and re-starting the whole thing, but I have a lot of pictures of my children, job search files (resumes), and music that I don't want to los... Read more

A:Firefox opening new tabs with ads and antivirus offers on its own

Have I made a mistake in my initial post? Still haven't received any reply and/or guidance. Have done NOTHING with computer since posting it.===========Hello While we understand your frustration at having to wait, please note that Bleeping Computer deals with several hundred requests for assistance such as yours on a daily basis. As a result, our backlog is quite large as are other comparable sites that help others with malware issues. Although our HJT Team members work on hundreds of requests each day, they are all volunteers who work logs when they can and are able to do so. No one is paid by Bleeping Computer for their assistance to our members.Further, our malware removal staff is comprised of team members with various levels of skill and expertise to deal with thousands of malware variants, some more complex than others. Although we try to take DDS/HJT logs in order (starting with the oldest), it is often the skill level of the particular helper and sometimes the operating system that dictates which logs get selected first. Some infections are more complicated than others and require a higher skill level to remove. Without that skill level attempted removal could result in disastrous results. In other instances, the helper may not be familiar with the operating system that you are using, since they use another. In either case, neither of us want someone to assist you who is not familiar with your issue and attempt to fix it.We ask that once you have posted your log a... Read more

Read other 28 answers
RELEVANCY SCORE 87.2

Mod EDIT: Moved to proper forum,Virus, Trojan, Spyware, and Malware Removal Logs ~~boopmeHello all,I have a 2K3 server that somebody recently logged onto and did some web browsing (I know, I deserve flames for even making this possible but the fact is I need to fix it).I recently noticed when I tried to RDP to the box that it appears the explorer process would crash within 24 hrs of booting. A little digging in the event viewer also showed errors indicating that Windows Updates could not reach the microsoft site. I've done a bit of digging with AutoRuns and ProcessExplorer and nothing is standing out, but Firefox is opening new tabs, and going to any microsoft sites times out. Googling MS sites gives results, but when I try to visit them I just get returned to google. As the OS on this box is Win2K3, a number of tools that I've read about are not compatible with this machine.I'm getting desperate, any assistance would be appreciated.HJT log attached:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 6:24:44 PM, on 8/25/2010Platform: Windows 2003 SP2 (WinNT 5.02.3790)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\WIN2K3\System32\smss.exeC:\WIN2K3\system32\winlogon.exeC:\WIN2K3\system32\services.exeC:\WIN2K3\system32\lsass.exeC:\WIN2K3\system32\svchost.exeC:\WIN2K3\System32\svchost.exeC:\WIN2K3\System32\dns.exeC:\... Read more

A:Win2K3 Server - Firefox opening new tabs

Hi,Welcome to Bleeping Computer. My name is m0le and I will be helping you with your log.Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Options box to the right of your topic title and selecting Track This Topic.Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.Please reply to this post so I know you are there.The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then I will close the topic.Once I receive a reply then I will return with your first instructions.Thanks

Read other 2 answers
RELEVANCY SCORE 87.2

Hi , I think my system has been under the clutches of some browser worm. All of a sudden as soon as i open firefox and start browing , multiple tabs keep on opening directing to various spooky addresses , sometimes it even shows the files present on my system (much like an index search). When i open INternet explorer it opens new IE windows randomly and says HTTP4440 on the title bar and says that teh page can nto be displayed. I hvae tried running superantispyware which found some adware cookies and a trojan. removed still no joy. Tried running MalwareBytes. It found nothing. Should i try to run combo fix ? . If yes , please advice me what to do after i am done running combo fix
 

Read other answers
RELEVANCY SCORE 87.2

Hi Ok, well I am not the kind of person who bothers people for help until I am at the end of my tether but the old tether is all but exhausted i am afraid.The problem: Seems to be pretty common symptoms. When I use firefox (chrome doesn't seem to work anymore and IE always crashes on exit so I only use firefox) I get two abherrant behaviours:1) Every so often (varies between ten minutes or a couple of hours) a new tab will open for no apparent reason with a pretty random link on it (never anything very exciting)2) Starting a search via either the little firefox search bar or direct via a google page brings up the results but clicking on any of the results gives maybe only a 50:50 chance of getting the required link as opposed to a redirect. copying and pasting the link into the address bar is a workaround.Both these behaviours redirect all over, quite often to ask.com (10% of the time maybe) and often redirects AND randomly opened tabs seem to be linked in some way to whatever word i have in the google search bar or had entered on the google webpage as if it is utilising that information. Oh and a lot of the links have a small tab/address bar icon that looks like a small blue swirly letter 'a'what have i tried?what haven't i tried:hitman promalwarebytesmicrosoft security essentialszonealarm scan (my usual firewall and virus scanner software)exterminate it!spybot search and destroyprevxa few others i have since deleted and cant recall their names...and then... Read more

A:Google redirects and tabs opening in firefox

Hello and Welcome to the forums! My name is Gringo and I'll be glad to help you with your computer problems. Somethings to remember while we are working together.1.Please do not run any other tool untill instructed to do so!2.Please reply to this thread, do not start another!3.Please tell me about any problems that have occurred during the fix.4.Please tell me of any other symptoms you may be having as these can help also.5.Please try as much as possible not to run anything while executing a fix.If you follow these instructions, everything should go smoothly.I would like to get a better look at your system, please do the following so I can get some more detailed logs.DeFogger: Please download DeFogger to your desktop.Double click DeFogger to run the tool.The application window will appearClick the Disable button to disable your CD Emulation driversClick Yes to continueA 'Finished!' message will appearClick OKDeFogger may ask you to reboot the machine, if it does - click OK Do not re-enable these drivers until otherwise instructed.IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.Download DDS:Please download DDS by sUBs from one of the links below and save it to your desktop:Download DDS and save it to your desktopLink1Link2Link3Please disable any anti-malware program that will block scripts from running before running DDS.Double-Click on dds.scr and a comman... Read more

Read other 3 answers
RELEVANCY SCORE 87.2

I've recently had quite a lot of malware removed from my computer, but my firefox browser still appears to be under the effect of some kind of virus which Malwarebytes and other virus scanners can't seem to find. Every now and then, a tab seems to open up that is either completely blank, or is reported as an attack site by firefox... I can't quite remember what the URLs were, except for one called "ceramics.com" or something...

Does anyone know how to deal with this kind of thing?

A:Firefox opening tabs to attack sites

Hello and welcome to TSF.

We want all our members to perform the steps outlined in the link given below, before posting for assistance. There's a sticky at the top of this forum, and a
Quote:




Having problems with spyware and pop-ups? First Steps




link at the top of each page.

Please follow our pre-posting process outlined here:

http://www.techsupportforum.com/f50/...lp-305963.html

After running through all the steps, you shall have a proper set of logs. Please post them in a new topic, as this one shall be closed.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

Please note that the Virus/Trojan/Spyware Help forum is extremely busy, and it may take a while to receive a reply.

Read other 1 answers
RELEVANCY SCORE 87.2

Hi :)Ok, well I am not the kind of person who bothers people for help until I am at the end of my tether but the old tether is all but exhausted i am afraid.The problem: Seems to be pretty common symptoms. When I use firefox (chrome doesn't seem to work anymore and IE always crashes on exit so I only use firefox) I get two abherrant behaviours:1) Every so often (varies between ten minutes or a couple of hours) a new tab will open for no apparent reason with a pretty random link on it (never anything very exciting)2) Starting a search via either the little firefox search bar or direct via a google page brings up the results but clicking on any of the results gives maybe only a 50:50 chance of getting the required link as opposed to a redirect. copying and pasting the link into the address bar is a workaround.Both these behaviours redirect all over, quite often to ask.com (10% of the time maybe) and often redirects AND randomly opened tabs seem to be linked in some way to whatever word i have in the google search bar or had entered on the google webpage as if it is utilising that information. Oh and a lot of the links have a small tab/address bar icon that looks like a small blue swirly letter 'a'what have i tried?what haven't i tried:hitman promalwarebytesmicrosoft security essentialszonealarm scan (my usual firewall and virus scanner software)exterminate it!spybot search and destroyprevxa few others i have since deleted and cant recall their names...and th... Read more

A:Google redirects and tabs opening in firefox

i must be doing something wrong because it sure is pissing me around as i try and copy and past these logs

Read other 4 answers
RELEVANCY SCORE 87.2

Hi,

I recently upgraded to Windows 7 64 bit, and noticed a change that I can't figure out. I use www.msn.com for my homepage and email. I click on hotmail, and it now opens in a new tab instead of switching to hotmail in my current tab. I have not found a solution in the tools dropdown. Can anyone tell me how to set this back the way it was?

Ben

A:[SOLVED] Firefox question about tabs opening

Hi Ben, welcome to TSF

Go to Tools > Options > Tabs. Select 'Current Tab' from the dropdown menu for 'Open links that open in a new window in...'

If that doesn't fix it, do you have any addons installed that change the way tabs work, like Tab Mix Plus?

Read other 13 answers
RELEVANCY SCORE 86.4

Hey, I recently got the annoying rogue 'Internet Security 2010' on the my computer...I managed to get rid of it with rkill and MBAM but i still think somethings on my compOn firefox, sites will be redircted and random tabs will open automatically. I have: AVG Anti-Virus Free 9.0MBAMSpybotAd-AwareNone of these programs have picked up anything(Ad-Aware has picked up some cookies e.g. advertis, atdmt)But it hasn't gotten rid of the redirecting problem...What is it and can it be removed?Thanks for the help!Here's the DDS:C:\Program Files\AVG\AVG9\avgrsx.exeC:\Program Files\AVG\AVG9\avgcsrvx.exeC:\Program Files\Lavasoft\Ad-Aware\AAWService.exeC:\WINDOWS\system32\spoolsv.exesvchost.exeC:\Program Files\AVG\AVG9\avgwdsvc.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\WINDOWS\system32\CTsvcCDA.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\Program Files\Analog Devices\SoundMAX\SMAgent.exeC:\Program Files\AVG\AVG9\avgnsx.exeC:\WINDOWS\system32\svchost.exe -k imgsvcC:\Program Files\AVG\AVG9\avgemc.exeC:\WINDOWS\system32\wuauclt.exeC:\Program Files\AVG\AVG9\avgcsrvx.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Analog Devices\SoundMAX\SMTray.exeC:\Program Files\Adobe\Acroba... Read more

A:Random Website Redirections and Tabs Opening in Firefox

Hi thunderstruck!, and welcome to Bleeping Computer.Firstly,Please restore your Proxy settings as they have been modified by malware...To do this:In Internet Explorer: Tools Menu -> Internet Options -> Connections Tab ->Lan Settings > uncheck "use a proxy server" and check to "Automatically detect settings".In Firefox in Tools Menu -> Options... -> Advanced Tab -> Network Tab -> "Settings" under Connection.Secondly,Please launch Malwarebytes' Anti-Malware, click the Update tab, and then Check for Updates. Then choose the Scanner tab and select "Perform Quick Scan", then click Scan.The scan may take some time to finish,so please be patient.When the scan is complete, click OK, then Show Results to view the results.Make sure that everything is checked, and click Remove Selected.When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.Copy&Paste the entire report in your next reply along with a fresh HijackThis log.Thirdly,Download OTL.exe by OldTimer to your Desktop.Close all windows and double click OTL.exe.In the "Custom Scans/Fixes" window (under the light green bar) paste the following in bold:netsvcs%SYSTEMDRIVE%\*.*%systemroot%\*. /mp /sCREATERESTOREPOINT%systemroot%\system32\*.dll /lockedfiles%systemroot%\Tasks\*.job ... Read more

Read other 16 answers
RELEVANCY SCORE 86.4

Hey everyone, I'm hoping someone might be able to help me. Firefox and IE has been opening new tabs on random link clicks and sometimes without clicking at all. I'm getting links redirected to something with the site name followed by iebvz. (example of what I ran into while creating an account here http://bleepingcomputer.iebvz.com). The link then redirects to Quibids.com. I appreciate the time and assistance provided. Posted below are my DDS results and attach file. I've run malwarebytes, virus software, and spybot which removed mostly cookies and a couple of other "not so nasty" PUPs.
 
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16476  BrowserJavaVersion: 10.21.2
Run by Sean at 20:10:50 on 2013-05-07
Microsoft Windows 7 Professional   6.1.7601.1.1252.1.1033.18.4095.1663 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetwork... Read more

A:Firefox and IE Redirecting or opening new tabs to random sites

Hello Zonablazer I would like to welcome you to the Malware Removal section of the forum.Around here they call me Gringo and I will be glad to help you with your malware problems.Very Important --> Please read this post completely, I have spent my time to put together somethings for you to keep in mind while I am helping you to make things go easier, faster and smoother for both of us!Please do not run any tools unless instructed to do so.We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.Please do not attach logs or use code boxes, just copy and paste the text.Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.Please read every post completely before doing anything.Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.Please provide feedback about your experience as we go.A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the sam... Read more

Read other 32 answers
RELEVANCY SCORE 86.4

Referred from here: http://www.bleepingcomputer.com/forums/t/332780/browser-hijacked-redirects/ ~ OBAfter a virus attack / spyware attack last week, which I think I have managed to remove most of it using all the usual recommended software, I still have a remaining problem that my firefox browser keeps opening new tabs with random weird URL's ... the pages don't actually load though. Clearly there is some virus / malware or something present / corrupted in my system still. I have no idea how to repair it. All my scanners come up with nothing, so I get the impression that its the damage the virus has caused which needs to be rectified, but for all I know there could be more unknown viruses that are super stealthy or brand new. The only other odd behaviour I am noticing is that Ad-aware live keeps automatically blocking IP addresses from 'attacks' every now and then, this may also be completely common, or it may be a sign that I have malicious software on my pc still?I have just followed all the advice in the following post and have now been advised to post here following the preparation guide steps 6-9 which I have just done.Please see my 1) DDS log pasted below2) attach.txt file uploaded3) ark.txt file uploaded - TO BE POSTED TOMORROW WHEN THIS GMER SCAN FINISHES this is the DDS logQUOTEDDS (Ver_10-03-17.01) - NTFSx86 Run by Mike at 1:01:05.14 on 21/07/2010Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17Microsoft Windows XP Professional 5.1.2600.3.12... Read more

A:firefox browser opening new tabs with dodgy url's unpromptly

Ark log now attached.

Read other 6 answers
RELEVANCY SCORE 86.4

I have this weird problem for a few days now.

I'll try to describe my problem is bullet points.

1. I was searching something on google, i missclicked on a link that looked questionable by mistake. A new tab opened to some spam ad site. I clicked to close as soon as possible.
New pop up with javascript appears and asks me something about Leave Page - Stay. I press leave. I think i noticed a hickup in the browser at the time and i thought to myself if something happened.

2. At a random time a new tab appears to an ad site as i kept using firefox. It started to annoy me as the a new tab kept opening with spam ad

3. I thought that something is bad and started looking up to forums and tried the following

a. I had Nod32 5 installed and still instanlled, it's not picking up anything.

b. I ran TDDSkiller from Kaspersky and it finds nothing.

c. I ran Gmer and it finds nothing.

d. I ran MalwareBytes and it finds nothing.

e. I ran SuperAntiSpyware and it only finds Tracking Cookies that i repeatedly deleted without result.

f. I have tried Nod32 online scanner in case my local scanner is compromised and it picks nothing.

g. I have formatted the hard drive that holds the OS and reinstalled everything from scratch and still the same problem!

~The potential virus/malware acts like this.~

I can browse any sites without limitations, it doesn't prohibit me from accesing any antivirus or anti-malware sites and nothing may happen for 2-3 hours but suddenly w... Read more

A:Firefox keeps opening tabs to spam sites on click

DownloadTDSSkillerLaunch it.Click on change parameters-Select TDLFS file systemClick on "Scan".Please post the LOG report(log file should be in your C drive) Do not change the default options on scan resultsDownloadaswMBRLaunch it, allow it to download latest Avast! virus definitionsClick the "Scan" button to start scan.After scan finishes,click on Save logPost the log results here.If you get crashes in normal mode,run it in safemode with networkingDownloadESET online scannerInstall itClick on START,it should download the virus definitionsWhen scan gets completed,click on LIST of found threatsExport the list to desktop,copy the contents of the text file in your reply

Read other 9 answers
RELEVANCY SCORE 86.4

Hello and thank you in advance for your help.

I am currently experiencing some problems. On IE I continue to be redirected to random sites when using google or yahoo search engines.

On Firefox (Safe Mode) random tabs open up, also redirected and the browser crashes and then I get the do you want to send firefox a crash report feature and the option to restart firefox. Which then after clicking a couple times reopens firefox.

I have Windows 7, so 64bit. I have run every program I could find. Malwarebytes, SuperAntispyware, AVG, HijackThis, Spyblaster, etc. I still have AVG, Malwarebytes and Advanced System Care 3 on my computer, uninstalled the others. So if someone can help me figure out the problem that'd be great. I tried system restore it didn't work. I deleted problems that all those system found and still the problem seems to come back. It almost does a temporary fix, but something is alive in my browser or system that brings the issue back.
I will gladly subscribe to this thread, I am eager to get started.
DDS (Ver_10-11-10.01) - NTFS_AMD64
Run by Carter at 0:56:27.28 on Wed 11/24/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_21
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.4061.2656 [GMT -8:00]
============== Running Processes ===============

C:\PROGRA~2\AVG\AVG10\avgchsva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe ... Read more

A:Issues with IE and Firefox redirecting pages and opening tabs

Hi

Please do the following:

Download OTL and save it to your desktop.
Double click on the icon to run it.
Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top, make sure Standard output is selected.
Under the Extra Registry section, check Use SafeList
Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
Double click inside the Custom Scan box at the bottom
A window will appear saying "Click Ok to load a custom scan from a file or Cancel to cancel"
Click the Ok button and navigate to the file scan.txt which we just saved to your desktop
Select scan.txt and click Open. Writing will now appear under the Custom Scan box
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic

Read other 19 answers
RELEVANCY SCORE 86.4

History as follows:Had the "antivir" virus a few weeks back (random windows opening on desktop, limiting use of icons and applications, leading to safemode restart and mutiliple virus scans) and since then my laptop hasn't been the same. Managed to clear out a great deal of the virus, but a few things remain.Most recent symptoms: After I thought most of the trouble had been cleaned away, windows then opened and was noticeably lagging. Start bar (usually your typical XP blue) has turned white and block (like old version of windows!) and laptop would stall, freeze, and not shutdown. Had to force shutdown. Rebooted in safemode, rescanned, cleared out some malware. Deleted two dodgey applications (both had random item names, linking to random .dll names, both connected to rundll32.exe) in startup menu using Advanaced SystemCare3. Returned to a Restore Checkpoint. Returned to normal mode to find everything back to normal, EXCEPT:Firefox is auto-opening tabs periodically. One leads to www.google.com/webhp and the others to random sites, often blocked by AVG as "threats". have rescanned, but nothing doing. Firefox continues to autoopen these tabs.I'd like to know how to get my laptop clean again. So, here the technical details:DDS (Ver_10-03-17.01) - NTFSx86 Run by John at 18:42:35.14 on 04/08/2010Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_17Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.3454.2752 [GMT 1:00]AV: AVG Anti-... Read more

A:Unknown Malware opening random tabs on Firefox

Hello and Welcome to the forums! My name is Gringo and I'll be glad to help you with your computer problems. Somethings to remember while we are working together.Do not run any other tool untill instructed to do so!Please Do not Attach logs or put in code boxes.Tell me about any problems that have occurred during the fix.Tell me of any other symptoms you may be having as these can help also.Do not run anything while running a fix.In the upper right hand corner of the topic you will see a button called Options. If you click on this in the drop-down menu you can choose Track this topic. By doing this and then choosing Immediate E-Mail notification and then clicking on Proceed you will be advised when we respond to your topic and facilitate the cleaning of your machine.We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.In order for me to see the status of the infection I will need a new set of logs to start with.Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.DeFogger: Please download DeFogger to your desktop.Double click DeFogger to run the tool. The ap... Read more

Read other 22 answers
RELEVANCY SCORE 86.4

Hi,

While I think I have temporarily stopped this problem, by blocking redirects in Firefox, I think there is still a malware/trojan on the system, which may cause other problems, so I?d appreciate help from a pro. Many thanks in advance.

Every five of so minutes firefox would open a new Window with 11 tabs 3 or four of them were Index of the folder where firefox is stored, another one is xn-eba.com and the others are page could not be loaded with addresses with lots of odd symbols, but always including the xn- characters. I can just close it but I notice in the Cookies section that a cookie is added each time there is the redirect that I have removed.

I have ran Malwarebytes and spybot search and destroy (which found three problems that I cleaned the first run and none the second) as well as the antivirus (avira). I?ve also cleaned out the temporary files and temporary internet files.

Thanks again,
Chris.

DDS.txt

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Berta at 13:11:18 on 2012-05-01
Microsoft Windows XP Professional 5.1.2600.3.1252.34.3082.18.1022.30 [GMT 2:00]
.
AV: AntiVir Desktop *Disabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Norton Internet Worm Protection *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Archivo... Read more

A:Firefox opens new window with 11 various tabs, including xn-eba.com

Hello and Welcome to Bleeping Computer!!My name is Gringo and I'll be glad to help you with your computer problems. I have put together somethings for you to keep in mind while I am helping you to make things go easier and faster for both of usPlease do not run any tools unless instructed to do so.
We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.Please do not attach logs or use code boxes, just copy and paste the text.
Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.Please read every post completely before doing anything.
Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.Please provide feedback about your experience as we go.
A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.NOTE:... Read more

Read other 3 answers
RELEVANCY SCORE 86.4

Hello,

My Firefox browser always starts up by opening up a -second- browser window containing one tab of the AOL.com home page, and one tab of the "anchorfree.com" page, neither of which I have set in my Firefox settings. This was probably ever since I installed my Hotspot Shield v1.57, an IP hiding software that I want to keep, but I never told it it could do anything like this to my Firefox, and there are no options or preferences in the software itself to alter this, nor in my Firefox settings or Add-ons that are related to this. How can I disable this endorsing of AOL.com and anchorfree.com without losing the IP software itself? I already ran a full scan of MalwareBytes and Microsoft Essentials. HiJack log attached.

Thanks!

A:Firefox always starts up with a second window of AOL.com and anchorfree.com tabs

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below I will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results.Follow the ... Read more

Read other 2 answers
RELEVANCY SCORE 86.4

Please help. Our family computer has started opening up explorer windows, some of which are not for family viewing.
It all started after my son checked his emails and played on Runescape, according to the history. I have AVG free running and Spywaredoctor but he insists there were no warnings??!!??
I am on the verge of a re-format but the thought of installing all that stuff is putting me off.

Here is the latest HJT file.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:02:36, on 07/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
T:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Kontiki\KService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Raxco\Perfe... Read more

Read other answers
RELEVANCY SCORE 85.6

Internet explorer won't stop opening tabs unless I end the process.
Also the internet settings for IE keep changing to accept all cookies and I don't use IE ever.
While surfing the internet Firefox opens a new window to random websites or ads and sometimes blank pages with a changing url similar to these two:
(Urls are really long so I'll only post part of it)

Code:
http://77.93.75.150/dot.gif/?ver=120&cmp=profiling4&uid=
Code:
http://82.98.235.113/dot.gif/?ver=120&cmp=profiling4&uid=
I found this within the urls if it helps any.

Code:
www.google.com%2Fsearch%3Fq=rundll32.exe
Also when I shut down my PC an end task window appears labeled SuperMwindow
and when my PC boots up, a window appears saying:
Windows Drive not ready
Exception Processing Message
c00000a3 Parameters 75b6bf9c 4 75b6bf9c 75b6bf9c
asking me to continue cancel or try again
I'm new here and I don't know what's going on Please Help

I read the the first sticky and and downloaded Hijackthis
Here's the log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:26:06 PM, on 1/27/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common F... Read more

A:IE tabs won't stop opening, FireFox opens up random sites

Read other 16 answers
RELEVANCY SCORE 85.6

Greetings all.

I came here in early 2009 with a problem and you guys were great, so I am hoping we can do this again.

I noticed my PC (Win XP SP2) would give me false Google search results with Firefox. It would open the Google search results, but when you clicked any link it took you to a different site, either in that tab or by opening another.

My fiancee says this had happened to her on her side of the PC while on Facebook.

I scanned with Superantivirus which picked up a trojan, but after the PC went into sleep mode I could not get back to Windows and had to reset via the power button.
I scanned with both Superantispyware and Avira Anti virus but it picked up nothing besides a few cookies.

I also cannot access the net in safe mode...

Have not been home to really do anything about this, but my methods have failed. Any help would be greatly appreciated.
I plan to buy a new PC soon, but still want to use this as a media PC connected to my TV as it is a WinXP Media Center edition, so I hope the old girls is not too far gone.

EDIT: Oh, later I may have to reply by smart phone from my job so excuse my typos as my phone based forum posting is not the best lol.


DDS (Ver_10-12-12.02) - NTFSx86
Run by Tomspy77 at 14:43:26.81 on Mon 02/28/2011
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.65 [GMT -6:00]

AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FD... Read more

A:Trojan Infecting Google searches, opening Tabs in Firefox?

Hello and Welcome to TSF.

Please Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant notification by email, then click Add Subscription.

Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed.

------------------------------------------------------

One or more of the identified infections is a backdoor trojan/rootkit.

This type of infection allows hackers to remotely control your computer, log keystrokes, steal critical system information, and download and execute files without your knowledge.

If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Please refer to Microsoft's Online Safety article for tips on creating a strong password.

Do not change passwords or do any transactions from the infected computer until it has been cleaned.

------------------------------------------------------

I need to see a gmer log in order to help you.

NEW INSTRUCTIONS - Read This Before Posting For Malware Removal Help - Tech Support Forum

------------------------------------------------------

Read other 19 answers
RELEVANCY SCORE 85.6

A short summary of what happens:Ex: I search for something on Google. I see results. I click on one of the results. Instead of the actual webpage www.somewebpage.com/etcetc, I get "http://link-box.com/search.php" or some other random sites/ads. The actual content itself is blocked via noscript, so all I see is http://tru01dms3.com/VKr0RIhx6C5JHmu22a47a...12cce89233cd18Z on the page.Sometimes tabs will open by themselves, but for the most part, it's the result of clicking on something. What I've done so far:I've run full system scans with avast, Super Antispyware, Malwarebytes Anti-Malware, and Spybot S&D. I haven't run Lavasoft Ad-aware because it's been iffy since 2007 in terms of running smoothly. Nothing else I'm using is turning up anything, so I'm thinking it's time to pull out the big guns, via any help I can get from you guys through either ComboFix or HijackThis log analysis.Is there anything else I can do?One last note, I think it's only limited to Firefox, but I'm not positive. I don't really use IE very often, so I can't say whether or not for certain it's only limited to FF.One more thing. Evidently a forum I was on had some issues with infected scripts or something. At the time I didn't have the noscript extension running, so alas I think something found its way onto my computer. Somebody made a comment about some javascript thing, but I'm not sure.Any help would be greatly appreciated.Oh, ... Read more

A:Link/Click Hijacking randomly opening new ad tabs in firefox

Half bump, half update.I've been reading a lot of the things on the forum, so out of curiosity, I ran Kaspersky TDSSKiller from http://support.kaspersky.com/viruses/solutions?qid=208280684Results: 1 File object infected/1 cured on reboot. I rebooted, and that particular problem is now gone. It's been about a day so far, and no link/click hijacking/redirecting has occurred at all. I don't know if the problem is fixed (I doubt it is), but at least superficially something worked. Is there anything else I should take into consideration?

Read other 1 answers
RELEVANCY SCORE 85.6

Yes, I don't know why, but this is the second time that I've actually experienced this problem. The first time I thought that it was a trojan and I decided to reformat my computer.

Now, I want to be absolutely positive. Whenever I open firefox every now and then when I'm visiting websites multiple tabs will open at high rates of speed and I cannot stop them from opening. I have to CTRL-ALT-DELETE and end firefox & sometimes I basically have to get lucky doing that. Otherwise I just reboot.

Can someone educate me on what the problem might be, what I can do to solve it, & keep it from happening again?

Thank you very much!
Courtney
 

A:Multiple tabs opening simultaneously at high speed (Firefox)

Read other 9 answers