• Registrarse
  • Iniciar sesión


  • Página 2 de 2 PrimeroPrimero 12
    Resultados 11 al 14 de 14

    pc muy muy lenta y pagina de babylon en exploradores

    ComboFix 12-12-04.01 - Jessica 07/12/2012 1:40.2.4 - x86 Microsoft Windows 7 Starter 6.1.7601.1.1252.52.3082.18.1013.227 [GMT -6:00] Running from: c:\users\Jessica\Desktop\ComboFix.exe AV: Panda Cloud Antivirus *Disabled/Updated* {3456760B-FDAA-FFFD-06C2-7BB528D2066C} FW: Cloud Antivirus Firewall *Disabled* {0C6DF72E-B7C5-FEA5-2D9D-D280D6014117} SP: Panda Cloud Antivirus *Disabled/Updated* ...

    1. #11
      Usuario Avatar de edson2012
      Registrado
      dic 2012
      Ubicación
      acapulco mexico
      Mensajes
      8
      ComboFix 12-12-04.01 - Jessica 07/12/2012 1:40.2.4 - x86
      Microsoft Windows 7 Starter 6.1.7601.1.1252.52.3082.18.1013.227 [GMT -6:00]
      Running from: c:\users\Jessica\Desktop\ComboFix.exe
      AV: Panda Cloud Antivirus *Disabled/Updated* {3456760B-FDAA-FFFD-06C2-7BB528D2066C}
      FW: Cloud Antivirus Firewall *Disabled* {0C6DF72E-B7C5-FEA5-2D9D-D280D6014117}
      SP: Panda Cloud Antivirus *Disabled/Updated* {8F3797EF-DB90-F073-3C72-40C753554CD1}
      SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      .
      .
      ((((((((((((((((((((((((( Files Created from 2012-11-07 to 2012-12-07 )))))))))))))))))))))))))))))))
      .
      .
      2012-12-07 08:01 . 2012-12-07 08:01 -------- d-----w- c:\users\Default\AppData\Local\temp
      2012-12-07 08:01 . 2012-12-07 08:01 -------- d-----w- c:\users\Administrator\AppData\Local\temp
      2012-12-07 07:34 . 2012-12-07 07:34 60872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C82D60AF-1867-4DA6-85C4-E98A046D3EE4}\offreg.dll
      2012-12-07 01:42 . 2012-11-08 18:00 6812136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C82D60AF-1867-4DA6-85C4-E98A046D3EE4}\mpengine.dll
      2012-12-07 01:20 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll
      2012-12-07 01:20 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe
      2012-12-07 01:20 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll
      2012-12-07 01:20 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll
      2012-12-07 01:19 . 2012-06-02 21:19 171904 ----a-w- c:\windows\system32\wuwebv.dll
      2012-12-07 01:19 . 2012-06-02 21:12 33792 ----a-w- c:\windows\system32\wuapp.exe
      2012-12-07 00:26 . 2012-12-07 00:26 -------- d-----w- c:\program files\DivXLand
      2012-12-07 00:26 . 2005-02-05 02:19 57344 ----a-w- c:\windows\system32\dslider.ocx
      2012-12-07 00:26 . 2001-06-12 20:04 244024 ----a-w- c:\windows\system32\msflxgrd.ocx
      2012-12-07 00:06 . 2011-06-24 21:58 153088 ----a-w- c:\windows\system32\xvid.ax
      2012-12-07 00:06 . 2011-06-24 22:28 650752 ----a-w- c:\windows\system32\xvidcore.dll
      2012-12-07 00:06 . 2011-06-24 22:44 243200 ----a-w- c:\windows\system32\xvidvfw.dll
      2012-12-07 00:06 . 2012-12-07 00:06 -------- d-----w- c:\program files\Xvid
      2012-12-07 00:01 . 2012-12-07 00:01 -------- d-----w- c:\users\Jessica\AppData\Local\Programs
      2012-12-06 23:56 . 2012-12-06 23:59 -------- d-----w- c:\program files\virtualdubmod
      2012-12-06 23:01 . 2012-12-06 23:21 -------- d-----w- c:\users\Jessica\AppData\Local\panda4_0dn
      2012-12-06 21:35 . 2012-12-06 21:35 -------- d-----w- c:\programdata\blekko toolbars
      2012-12-06 21:35 . 2012-12-06 21:35 -------- d-----w- c:\program files\Toolbar Cleaner
      2012-12-06 21:34 . 2012-11-07 15:00 46672 ----a-w- c:\windows\system32\drivers\PSKMAD.sys
      2012-12-06 21:34 . 2012-12-06 21:35 -------- d-----w- c:\program files\pandasecuritytb
      2012-12-06 20:49 . 2012-12-06 20:48 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
      2012-12-06 20:48 . 2012-12-06 20:48 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
      2012-12-06 20:30 . 2012-12-06 20:30 -------- d-----w- C:\_OTL
      2012-12-06 20:17 . 2012-12-06 20:17 -------- d-----w- c:\program files\ERUNT
      2012-12-06 11:02 . 2012-12-06 11:03 -------- d-----w- c:\program files\Google
      2012-12-05 08:44 . 2012-12-06 09:39 -------- d-----w- C:\_AT-Destroyer
      2012-12-05 03:58 . 2012-12-05 03:58 105692 ----a-w- c:\programdata\Microsoft\Windows Defender\LocalCopy\{6134778D-23CC-BF94-4CE5-9DB5C5703673}-Bu_.exe
      2012-12-05 03:52 . 2012-11-29 08:26 2397152 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll
      2012-12-05 03:35 . 2012-12-05 03:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
      2012-12-05 03:35 . 2012-09-30 01:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
      2012-12-02 18:24 . 2012-12-02 18:24 -------- d-----w- c:\program files\Apple Software Update
      2012-11-21 22:51 . 2012-11-21 22:51 -------- d-----w- c:\programdata\Browser Manager
      2012-11-21 22:51 . 2012-10-27 05:27 816608 ----a-w- c:\program files\Mozilla Firefox\sqlite3.dll
      2012-11-10 01:01 . 2012-11-10 01:01 123944 ----a-w- c:\windows\system32\drivers\PSINProt.sys
      2012-11-10 01:01 . 2012-11-10 01:01 114216 ----a-w- c:\windows\system32\drivers\PSINProc.sys
      2012-11-10 01:01 . 2012-11-10 01:01 174632 ----a-w- c:\windows\system32\drivers\PSINKNC.sys
      2012-11-10 01:00 . 2012-11-10 01:00 149544 ----a-w- c:\windows\system32\drivers\PSINAflt.sys
      2012-11-10 01:00 . 2012-11-10 01:00 104488 ----a-w- c:\windows\system32\drivers\PSINFile.sys
      2012-11-09 17:23 . 2012-11-09 17:23 276520 ----a-w- c:\windows\system32\drivers\NNSStrm.sys
      2012-11-09 17:23 . 2012-11-09 17:23 133928 ----a-w- c:\windows\system32\drivers\NNStlsc.sys
      2012-11-09 17:23 . 2012-11-09 17:23 370216 ----a-w- c:\windows\system32\drivers\NNSProt.sys
      2012-11-09 17:23 . 2012-11-09 17:23 191528 ----a-w- c:\windows\system32\drivers\NNSPrv.sys
      2012-11-09 17:23 . 2012-11-09 17:23 128040 ----a-w- c:\windows\system32\drivers\NNSSmtp.sys
      2012-11-09 17:23 . 2012-11-09 17:23 74792 ----a-w- c:\windows\system32\drivers\NNSPihsw.sys
      2012-11-09 17:23 . 2012-11-09 17:23 125480 ----a-w- c:\windows\system32\drivers\NNSPop3.sys
      2012-11-09 17:23 . 2012-11-09 17:23 163112 ----a-w- c:\windows\system32\drivers\NNSIds.sys
      2012-11-09 17:23 . 2012-11-09 17:23 139176 ----a-w- c:\windows\system32\drivers\NNSHttp.sys
      2012-11-09 17:23 . 2012-11-09 17:23 133544 ----a-w- c:\windows\system32\drivers\NNSpicc.sys
      2012-11-09 17:23 . 2012-11-09 17:23 119208 ----a-w- c:\windows\system32\drivers\NNSAlpc.sys
      2012-11-08 01:58 . 2012-11-08 01:59 -------- d-----w- c:\program files\WinPcap
      .
      .
      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2012-12-06 20:48 . 2012-04-02 00:10 746984 ----a-w- c:\windows\system32\deployJava1.dll
      2012-10-22 18:08 . 2012-10-22 18:08 29224 ----a-w- c:\windows\system32\drivers\NNSNAHSL.sys
      2012-10-08 20:00 . 2012-09-17 18:51 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
      2012-10-08 20:00 . 2011-07-19 15:43 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
      2012-09-28 16:32 . 2012-09-28 16:32 5989776 ----a-w- c:\windows\system32\usbaaplrc.dll
      2012-09-28 16:32 . 2012-09-28 16:32 44544 ----a-w- c:\windows\system32\drivers\usbaapl.sys
      2012-11-29 08:26 . 2012-12-05 03:53 262112 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
      .
      .
      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4
      .
      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}]
      2012-10-15 13:02 87176 ----a-w- c:\program files\pandasecuritytb\pandasecurityDx.dll
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
      "{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}"= "c:\program files\pandasecuritytb\pandasecurityDx.dll" [2012-10-15 87176]
      .
      [HKEY_CLASSES_ROOT\clsid\{b821bf60-5c2d-41eb-92dc-3e4ccd3a22e4}]
      .
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ares"="c:\program files\Ares\Ares.exe" [2012-02-02 3209216]
      "Pokki"="c:\users\Jessica\AppData\Local\Pokki\v0.260.8.396\pokki.exe" [2012-11-28 5453656]
      "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-02-11 10025576]
      "Persistence"="c:\windows\system32\igfxpers.exe" [2010-06-16 150552]
      "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-02-05 1692968]
      "Power Management"="c:\program files\eMachines\eMachines Power Management\ePowerTray.exe" [2011-05-10 715368]
      "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
      "Panda Security URL Filtering"="c:\programdata\Panda Security URL Filtering\Panda_URL_Filtering.exe" [2012-10-15 221832]
      "RIMBBLaunchAgent.exe"="c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-09-01 90448]
      "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-06-16 141848]
      "PSUAMain"="c:\program files\Panda Security\Panda Cloud Antivirus\PSUAMain.exe" [2012-11-15 32032]
      .
      c:\users\Jessica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
      ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
      "ConsentPromptBehaviorAdmin"= 5 (0x5)
      "ConsentPromptBehaviorUser"= 3 (0x3)
      "EnableUIADesktopToggle"= 0 (0x0)
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
      "aux"=wdmaud.drv
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
      2012-07-27 20:51 919008 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
      2011-07-28 23:08 1259376 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
      2010-06-16 14:33 173592 ----a-w- c:\windows\System32\hkcmd.exe
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
      2012-12-05 04:13 968592 ----a-w- c:\program files\uTorrent\uTorrent.exe
      .
      R1 NNSNAHSL;Network Activity Hook Server LightWeight Filter Driver;c:\windows\system32\DRIVERS\NNSNAHSL.sys [x]
      R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
      R3 EUCR;EUCR;c:\windows\system32\DRIVERS\EUCR6SK.SYS [x]
      R3 GamesAppService;GamesAppService;c:\program files\WildTangent Games\App\GamesAppService.exe [x]
      R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl.sys [x]
      R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
      R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
      R4 NNSPIHSW;NNSPIHSW;c:\windows\system32\DRIVERS\NNSPihsw.sys [x]
      R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
      S1 NNSALPC;NNSALPC;c:\windows\system32\DRIVERS\NNSAlpc.sys [x]
      S1 NNSHTTP;NNSHTTP;c:\windows\system32\DRIVERS\NNSHttp.sys [x]
      S1 NNSIDS;NNSIDS;c:\windows\system32\DRIVERS\NNSIds.sys [x]
      S1 NNSPICC;NNSPICC;c:\windows\system32\DRIVERS\NNSPicc.sys [x]
      S1 NNSPOP3;NNSPOP3;c:\windows\system32\DRIVERS\NNSPop3.sys [x]
      S1 NNSPROT;NNSPROT;c:\windows\system32\DRIVERS\NNSProt.sys [x]
      S1 NNSPRV;NNSPRV;c:\windows\system32\DRIVERS\NNSPrv.sys [x]
      S1 NNSSMTP;NNSSMTP;c:\windows\system32\DRIVERS\NNSSmtp.sys [x]
      S1 NNSSTRM;NNSSTRM;c:\windows\system32\DRIVERS\NNSStrm.sys [x]
      S1 NNSTLSC;NNSTLSC;c:\windows\system32\DRIVERS\NNSTlsc.sys [x]
      S1 PSINKNC;PSINKNC;c:\windows\system32\DRIVERS\psinknc.sys [x]
      S2 ePowerSvc;Acer ePower Service;c:\program files\eMachines\eMachines Power Management\ePowerSvc.exe [x]
      S2 GREGService;GREGService;c:\program files\eMachines\Registration\GREGsvc.exe [x]
      S2 Live Updater Service;Live Updater Service;c:\program files\eMachines\eMachines Updater\UpdaterService.exe [x]
      S2 NanoServiceMain;Panda Cloud Antivirus Service;c:\program files\Panda Security\Panda Cloud Antivirus\PSANHost.exe [x]
      S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x]
      S2 PSINAflt;PSINAflt;c:\windows\system32\DRIVERS\PSINAflt.sys [x]
      S2 PSINFile;PSINFile;c:\windows\system32\DRIVERS\PSINFile.sys [x]
      S2 PSINProc;PSINProc;c:\windows\system32\DRIVERS\PSINProc.sys [x]
      S2 PSINProt;PSINProt;c:\windows\system32\DRIVERS\PSINProt.sys [x]
      S2 PSUAService;Panda Product Service;c:\program files\Panda Security\Panda Cloud Antivirus\PSUAService.exe [x]
      S3 PSKMAD;PSKMAD;c:\windows\system32\DRIVERS\PSKMAD.sys [x]
      .
      .
      --- Other Services/Drivers In Memory ---
      .
      *NewlyCreated* - WS2IFSL
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
      LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc
      .
      Contents of the 'Scheduled Tasks' folder
      .
      2012-12-07 c:\windows\Tasks\Adobe Flash Player Updater.job
      - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-17 20:00]
      .
      2012-12-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
      - c:\program files\Google\Update\GoogleUpdate.exe [2012-12-06 11:02]
      .
      2012-12-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
      - c:\program files\Google\Update\GoogleUpdate.exe [2012-12-06 11:02]
      .
      .
      ------- Supplementary Scan -------
      .
      uStart Page = hxxp://pandasecurity.mystart.com/?source=5b97eeb3&tbp=homepage&toolbarid=pandasecuritytb&v=4_0&u=0D32F7F345CD6720DE482A50C10F21C0
      mStart Page = Google
      uInternet Settings,ProxyOverride = *.local
      IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
      TCP: DhcpNameServer = 192.168.1.254
      FF - ProfilePath - c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\
      FF - prefs.js: browser.search.selectedEngine - blekko
      FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.mx/
      FF - ExtSQL: 2012-11-21 17:52; {58bd07eb-0ee0-4df0-8121-dc9b693373df}; c:\programdata\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension
      FF - ExtSQL: 2012-12-04 21:57; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
      FF - ExtSQL: 2012-12-06 15:34; {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}; c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}
      .
      .
      --------------------- LOCKED REGISTRY KEYS ---------------------
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
      @Denied: (A 2) (Everyone)
      @="FlashBroker"
      "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
      "Enabled"=dword:00000001
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
      @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
      @Denied: (A 2) (Everyone)
      @="IFlashBroker5"
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
      @="{00020424-0000-0000-C000-000000000046}"
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      "Version"="1.0"
      .
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
      @Denied: (A) (Users)
      @Denied: (A) (Everyone)
      @Allowed: (B 1 2 3 4 5) (S-1-5-20)
      "BlindDial"=dword:00000000
      .
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
      @Denied: (Full) (Everyone)
      .
      --------------------- DLLs Loaded Under Running Processes ---------------------
      .
      - - - - - - - > 'Explorer.exe'(3612)
      c:\program files\eMachines\eMachines Power Management\SysHook.dll
      .
      Completion time: 2012-12-07 02:06:45
      ComboFix-quarantined-files.txt 2012-12-07 08:06
      ComboFix2.txt 2012-12-06 22:28
      .
      Pre-Run: 96,452,792,320 bytes libres
      Post-Run: 96,170,708,992 bytes libres
      .
      - - End Of File - - A0551A0A38EF845FC23E86F2303649B3

      *********************************************

      yapp..

      ha mejorado mucho la pc por cierto :)
      Última edición por @Javier_HF fecha: 07/12/12 a las 16:53:08 Razón: Unir mensajes.

    2. #12
      Moderador Gral.
      Avatar de @Javier_HF
      Registrado
      jun 2006
      Ubicación
      Spain.
      Mensajes
      21.708

      Re: pc muy muy lenta y pagina de babylon en exploradores

      1.- Abre el Notepad (Bloc de notas)

      • En Windows XP
        Ve a Inicio >> Selecciona Ejecutar >> Escribe dentro Notepad.


      • En Windows Vista y/o Windows 7
        Ve a Inicio >> Todos los programas >> Accesorios >> Selecciona Ejecutar >> Escribe dentro Notepad.


      2.-
      Ahora copia y pega la información, del interior del siguiente recuadro, dentro del Notepad.

      Atención : la palabra "Código:" NO se copia.
      Código:
      KillAll::
      ClearJavaCache::
      Firefox::
      FF - ProfilePath - c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\
      FF - prefs.js: browser.search.selectedEngine - blekko
      Folder::
      c:\programdata\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}

      3.-
      Guarda este archivo con el nombre CFScript.txt dentro del Escritorio.

      4.- Arrastra y suelta el archivo CFScript.txt dentro del archivo ComboFix.exe como muestra la animación aquí abajo. Esto activara ComboFix nuevamente.
      Antes de usar el CFScript....
      Súbenos el nuevo informe de ComboFix e indícanos como funciona tu equipo.

      Saludos, Javier.
      Quien no lo intenta no lo consigue | ;-)

      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    3. #13
      Usuario Avatar de edson2012
      Registrado
      dic 2012
      Ubicación
      acapulco mexico
      Mensajes
      8

      Re: pc muy muy lenta y pagina de babylon en exploradores

      ola, una disculpa por la demora :)

      ya hice lo que me pediste..ya no sale blekko en firefor,pero ahora sale la barra de babylon jejej


      por cierto como notas la p, han salido muchos virus?


      ................................................................................


      LOG DE COMBOFIX


      ComboFix 12-12-17.02 - Jessica 19/12/2012 3:05.3.4 - x86
      Microsoft Windows 7 Starter 6.1.7601.1.1252.52.3082.18.1013.271 [GMT -6:00]
      Running from: c:\users\Jessica\Desktop\ComboFix.exe
      Command switches used :: c:\users\Jessica\Desktop\CFScript.txt
      AV: Panda Cloud Antivirus *Disabled/Updated* {3456760B-FDAA-FFFD-06C2-7BB528D2066C}
      FW: Cloud Antivirus Firewall *Disabled* {0C6DF72E-B7C5-FEA5-2D9D-D280D6014117}
      SP: Panda Cloud Antivirus *Disabled/Updated* {8F3797EF-DB90-F073-3C72-40C753554CD1}
      SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      .
      .
      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      c:\programdata\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension
      c:\programdata\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\chrome.manifest
      c:\programdata\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\install.rdf
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome.manifest
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\custom.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\lib\about.xml
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\lib\dtxpanel.xul
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\lib\dtxpaneltransparent.xul
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\lib\dtxpanelwin.xul
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\lib\dtxprefwin.xul
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\lib\dtxtransparentwin.xul
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\lib\dtxwin.xul
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\lib\emailnotifierproviders.xml
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\lib\external.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\lib\neterror.xhtml
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\lib\rsspreview.html
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\lib\rsswin.xml
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\lib\rsswin.xsl
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\modules\datastore.jsm
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\modules\nsDragAndDrop.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\newtab\images\bullet.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\newtab\images\field_bg.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\newtab\images\powered_by_yahoo.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\newtab\newtab.html
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\partner.xml
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\preferences.xml
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\toolbar.htm
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\toolbar.xul
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.http://www.BrowserDataCleaner\ClearB...DataDialog.xml
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.BrowserDataCleaner\tb_icon.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.BrowserDataCleaner\widget.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.BrowserDataCleaner\widget.xml
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\.project
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\css\appversion.css
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\css\dialog.css
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\css\IE7Styles.css
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\css\jquery.tooltip.css
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\css\scrolbar.css
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\ico-coupon-hover.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\ico-coupon.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\ico-coupon1.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\images\bg-scrollbar-thumb-y.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\images\bg-scrollbar-track-y.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.http://www.Coupons_v4\images\bg-scro...rackend-yd.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\images\btn-activate-over.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\images\btn-activate.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\images\check.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\images\copy.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\images\delete.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\images\loader.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\images\ui-check-box.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\index.html
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\jquery.contextMenu.css
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\jquery.contextMenu.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\js\.#jquery.tooltip.js.1.1.2.1
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\js\appversion.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\js\jquery-1.4.2.min.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\js\jquery.cookie.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\js\jquery.event.wheel.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\js\jquery.pagination.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\js\jquery.scrollTo-min.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\js\jquery.tinyscrollbar.min.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\js\jquery.tooltip.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\js\jquery.tooltip.js.bak
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\js\JSON.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\js\listnav.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\js\main.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\page_white_copy.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\panel.html
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\panel\css\appversion.css
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\panel\css\dialog.css
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\panel\css\IE7Styles.css
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\panel\images\bgpanel.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\panel\images\btn-buy.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\panel\images\btn-close.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\panel\images\btn-getcoupon.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\panel\images\btn-search.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.http://www.Coupons_v4\panel\images\b...ons-disabl.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.http://www.Coupons_v4\panel\images\b...upons-over.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\panel\images\btn-viewcoupons.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\panel\images\check.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\panel\images\coupon-bg.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\panel\images\delete.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\panel\images\no-image.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\panel\images\save-sml.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.http://www.Coupons_v4\panel\images\u...ox-uncheck.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\panel\images\ui-check-box.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\panel\js\defscript.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\panel\main.html
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\partner.xml
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\placeholder-logo.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\css\appversion.css
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\css\dialog.css
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\css\dialog2.css
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\css\IE7Styles.css
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.http://www.Coupons_v4\skin\images\bg...ar-thumb-y.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.http://www.Coupons_v4\skin\images\bg...ar-track-y.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.http://www.Coupons_v4\skin\images\bg...trackend-y.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\images\bg_top.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\images\bgpanel-1.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\images\btn-activate-over.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\images\btn-activate.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\images\btn-buy.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\images\btn-close.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\images\btn-getcoupon.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\images\btn-search.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\images\check.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\images\coupon-activated.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\images\default.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\images\delete.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\images\ui-check-box.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\js\appversion.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\js\jquery-1.4.2.min.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\js\jquery.event.wheel.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\js\jquery.pagination.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\js\jquery.scrollTo-min.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.http://www.Coupons_v4\skin\js\jquery...rollbar.min.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\js\JSON.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\js\listnav.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\js\main.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\skin\main.html
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\tb_icon.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\tb_icon1.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\unchecked.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\widget.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\widget.xml
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\widget_version.txt
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.Coupons_v4\widget_version.txt.bak
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.ToolbarCleaner\tb_icon.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.ToolbarCleaner\widget.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\content\widgets\net.vmn.www.ToolbarCleaner\widget.xml
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\data\search\engines.xml
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\data\search\search.xsl
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\locale\lib\de.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\locale\lib\en.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\locale\lib\es.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\locale\lib\fr.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\locale\lib\it.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\locale\toolbar\de.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\locale\toolbar\en.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\locale\toolbar\es.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\locale\toolbar\fr.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\locale\toolbar\it.js
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\ActiveScan.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\blekko16.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\bluelite.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\bluesky.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-safe-de.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-safe-en.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-safe-es.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-safe-fr.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-safe-it.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-safe.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-search-de-over.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-search-de.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-search-en-over.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-search-en.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-search-es-over.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-search-es.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-search-fr-over.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-search-fr.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-search-it-over.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-search-it.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-settings-over.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-settings.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-unsafe-de.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-unsafe-en.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-unsafe-es.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-unsafe-fr.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-unsafe-it.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\btn-unsafe.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\custom.css
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\dictionary.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\downloadcom.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\facebook.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\games.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\grey.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\ico-cleaner.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\ico-clear.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\images.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\add.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\aol.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\arrow-dn.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\arrow-right-disabled.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\arrow-right.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\arrow-up.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\bg-btn-end.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\bg-btn-mdl.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\bg-btn-mdl_ff.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\bg-btn-start.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\bg-btnover-end.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\bg-btnover-mdl.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\bg-btnover-mdl_ff.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\bg-btnover-start.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\blank.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\btnback-down-vista.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\btnback-vista.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\btnleft-down-vista.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\btnleft-vista.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\btnright-down-vista.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\btnright-vista.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\button-splitter-down-vista.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\button-splitter-vista.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\checkmark.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\chevron.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\collapse.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\comcast.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\dtx.css
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\edit-back-hot.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\edit-back.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\expand.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\found.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\gmail.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\highlight.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\highlight_blue.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\highlight_cyan.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\highlight_lime.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\highlight_magenta.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\highlight_yellow.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\hotmail.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\imap.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\lastsearch-thumb-back.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\loadingMid.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\lock.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\mailcom.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\menu_bg-basic.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\menu_separator_bar.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\menuitem-splitter.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\menuitemback-down-vista.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\menuitemback-vista.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\menuitemleft-down-vista.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\menuitemleft-vista.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\menuitemright-down-vista.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\menuitemright-vista.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\modify.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\move.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\movetarget.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\pop.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\radio.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\reload.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\remove.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\rename.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\resize-box.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\rss.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\rsschannelback.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\RSSLogo.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\rsstabdivider.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\scroll-left.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\scroll-right.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\search-go.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lib\search.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\lichen.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\logo-about.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\logo-over.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\logo.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\modify-save.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\modify.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\music.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\news.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\orange.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\panda_small.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\search-background-de.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\search-background-en.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\search-background-es.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\search-background-fr.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\search-background-it.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\search-background.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\shopping.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\skin-bluelite.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\skin-bluesky.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\skin-grey.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\skin-lichen.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\skin-orange.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\skin-yellow.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\technorati.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\throbber.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\toolbarsplitter.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\vertical_separator.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\web.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\wikipedia.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\yellow.gif
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\chrome\skin\youtube.png
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\dtUser.exe
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\install.rdf
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\manifest.xml
      c:\users\Jessica\Desktop\System Check.lnk
      .
      .
      ((((((((((((((((((((((((( Files Created from 2012-11-19 to 2012-12-19 )))))))))))))))))))))))))))))))
      .
      .
      2012-12-19 09:30 . 2012-12-19 09:30 -------- d-----w- c:\users\Default\AppData\Local\temp
      2012-12-19 09:30 . 2012-12-19 09:30 -------- d-----w- c:\users\Administrator\AppData\Local\temp
      2012-12-19 04:09 . 2012-12-19 04:09 60872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9C5F5036-D925-4439-8989-CAFFE4C47B51}\offreg.dll
      2012-12-19 01:55 . 2012-11-08 18:00 6812136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9C5F5036-D925-4439-8989-CAFFE4C47B51}\mpengine.dll
      2012-12-12 05:12 . 2012-11-22 02:56 2345984 ----a-w- c:\windows\system32\win32k.sys
      2012-12-12 05:11 . 2012-11-02 05:11 376832 ----a-w- c:\windows\system32\dpnet.dll
      2012-12-12 05:11 . 2012-11-05 20:32 295424 ----a-w- c:\windows\system32\atmfd.dll
      2012-12-12 05:11 . 2012-11-05 20:32 34304 ----a-w- c:\windows\system32\atmlib.dll
      2012-12-12 05:11 . 2012-11-09 04:42 2048 ----a-w- c:\windows\system32\tzres.dll
      2012-12-07 09:17 . 2012-07-26 03:39 526952 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
      2012-12-07 09:17 . 2012-07-26 03:39 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
      2012-12-07 09:17 . 2012-07-26 02:46 9728 ----a-w- c:\windows\system32\Wdfres.dll
      2012-12-07 09:15 . 2012-07-26 02:33 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
      2012-12-07 09:15 . 2012-07-26 02:32 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
      2012-12-07 09:15 . 2012-07-26 03:20 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
      2012-12-07 09:15 . 2012-07-26 03:20 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
      2012-12-07 09:15 . 2012-07-26 03:20 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
      2012-12-07 09:15 . 2012-07-26 03:21 196608 ----a-w- c:\windows\system32\WUDFHost.exe
      2012-12-07 09:15 . 2012-07-26 03:20 613888 ----a-w- c:\windows\system32\WUDFx.dll
      2012-12-07 09:14 . 2012-03-01 05:46 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys
      2012-12-07 09:14 . 2012-03-01 05:33 159232 ----a-w- c:\windows\system32\imagehlp.dll
      2012-12-07 09:14 . 2012-03-01 05:29 5120 ----a-w- c:\windows\system32\wmi.dll
      2012-12-07 02:12 . 2012-02-11 05:43 492032 ----a-w- c:\windows\system32\win32spl.dll
      2012-12-07 02:12 . 2012-02-11 05:37 317440 ----a-w- c:\windows\system32\spoolsv.exe
      2012-12-07 02:12 . 2012-08-22 17:16 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
      2012-12-07 02:12 . 2012-07-04 19:45 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
      2012-12-07 02:11 . 2012-08-24 16:57 172544 ----a-w- c:\windows\system32\wintrust.dll
      2012-12-07 02:08 . 2012-06-02 04:36 140288 ----a-w- c:\windows\system32\cryptsvc.dll
      2012-12-07 02:08 . 2012-06-02 04:36 1159680 ----a-w- c:\windows\system32\crypt32.dll
      2012-12-07 02:08 . 2012-06-02 04:36 103936 ----a-w- c:\windows\system32\cryptnet.dll
      2012-12-07 02:07 . 2012-08-21 20:12 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
      2012-12-07 02:07 . 2012-04-28 03:17 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys
      2012-12-07 02:07 . 2012-06-06 05:05 1390080 ----a-w- c:\windows\system32\msxml6.dll
      2012-12-07 02:07 . 2012-06-06 05:05 1236992 ----a-w- c:\windows\system32\msxml3.dll
      2012-12-07 02:07 . 2010-06-26 03:24 2048 ----a-w- c:\windows\system32\msxml3r.dll
      2012-12-07 02:06 . 2012-06-02 04:40 369336 ----a-w- c:\windows\system32\drivers\cng.sys
      2012-12-07 02:06 . 2012-06-02 04:45 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
      2012-12-07 02:06 . 2012-06-02 04:39 219136 ----a-w- c:\windows\system32\ncrypt.dll
      2012-12-07 02:06 . 2012-06-02 04:45 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
      2012-12-07 02:06 . 2012-06-02 04:40 225280 ----a-w- c:\windows\system32\schannel.dll
      2012-12-07 02:05 . 2012-03-31 04:29 936960 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
      2012-12-07 02:03 . 2012-08-31 17:18 1211760 ----a-w- c:\windows\system32\drivers\ntfs.sys
      2012-12-07 02:03 . 2012-10-03 16:58 1293680 ----a-w- c:\windows\system32\drivers\tcpip.sys
      2012-12-07 02:03 . 2012-10-03 16:42 156672 ----a-w- c:\windows\system32\ncsi.dll
      2012-12-07 02:03 . 2012-10-03 16:40 499712 ----a-w- c:\windows\system32\iphlpsvc.dll
      2012-12-07 02:03 . 2012-08-22 17:16 240496 ----a-w- c:\windows\system32\drivers\netio.sys
      2012-12-07 02:03 . 2012-08-22 17:16 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
      2012-12-07 02:03 . 2012-10-03 16:42 242176 ----a-w- c:\windows\system32\nlasvc.dll
      2012-12-07 02:03 . 2012-10-03 16:42 175104 ----a-w- c:\windows\system32\netcorehc.dll
      2012-12-07 02:03 . 2012-10-03 16:42 52224 ----a-w- c:\windows\system32\nlaapi.dll
      2012-12-07 02:03 . 2012-10-03 16:42 18944 ----a-w- c:\windows\system32\netevent.dll
      2012-12-07 02:03 . 2012-10-03 15:21 35328 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
      2012-12-07 02:01 . 2012-04-07 11:26 2342400 ----a-w- c:\windows\system32\msi.dll
      2012-12-07 02:01 . 2012-08-02 16:57 490496 ----a-w- c:\windows\system32\d3d10level9.dll
      2012-12-07 02:01 . 2012-04-26 04:45 58880 ----a-w- c:\windows\system32\rdpwsx.dll
      2012-12-07 02:01 . 2012-04-26 04:45 129536 ----a-w- c:\windows\system32\rdpcorekmts.dll
      2012-12-07 02:01 . 2012-04-26 04:41 8192 ----a-w- c:\windows\system32\rdrmemptylst.exe
      2012-12-07 02:01 . 2012-03-17 07:27 56176 ----a-w- c:\windows\system32\drivers\partmgr.sys
      2012-12-07 02:01 . 2012-05-01 04:44 164352 ----a-w- c:\windows\system32\profsvc.dll
      2012-12-07 02:01 . 2012-09-25 22:47 78336 ----a-w- c:\windows\system32\synceng.dll
      2012-12-07 02:01 . 2012-05-14 04:33 769024 ----a-w- c:\windows\system32\localspl.dll
      2012-12-07 02:01 . 2012-03-03 05:31 1077248 ----a-w- c:\windows\system32\DWrite.dll
      2012-12-07 02:01 . 2012-10-09 17:40 193536 ----a-w- c:\windows\system32\dhcpcore6.dll
      2012-12-07 02:01 . 2012-10-09 17:40 44032 ----a-w- c:\windows\system32\dhcpcsvc6.dll
      2012-12-07 01:20 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll
      2012-12-07 01:20 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe
      2012-12-07 01:20 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll
      2012-12-07 01:20 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll
      2012-12-07 01:20 . 2012-06-02 22:19 35864 ----a-w- c:\windows\system32\wups.dll
      2012-12-07 01:20 . 2012-06-02 22:12 88576 ----a-w- c:\windows\system32\wudriver.dll
      2012-12-07 01:20 . 2012-06-02 22:19 577048 ----a-w- c:\windows\system32\wuapi.dll
      2012-12-07 01:19 . 2012-06-02 21:19 171904 ----a-w- c:\windows\system32\wuwebv.dll
      2012-12-07 01:19 . 2012-06-02 21:12 33792 ----a-w- c:\windows\system32\wuapp.exe
      2012-12-07 00:26 . 2012-12-07 00:26 -------- d-----w- c:\program files\DivXLand
      2012-12-07 00:26 . 2005-02-05 02:19 57344 ----a-w- c:\windows\system32\dslider.ocx
      2012-12-07 00:26 . 2001-06-12 20:04 244024 ----a-w- c:\windows\system32\msflxgrd.ocx
      2012-12-07 00:06 . 2011-06-24 21:58 153088 ----a-w- c:\windows\system32\xvid.ax
      2012-12-07 00:06 . 2011-06-24 22:28 650752 ----a-w- c:\windows\system32\xvidcore.dll
      2012-12-07 00:06 . 2011-06-24 22:44 243200 ----a-w- c:\windows\system32\xvidvfw.dll
      2012-12-07 00:06 . 2012-12-07 00:06 -------- d-----w- c:\program files\Xvid
      2012-12-07 00:01 . 2012-12-07 00:01 -------- d-----w- c:\users\Jessica\AppData\Local\Programs
      2012-12-06 23:56 . 2012-12-06 23:59 -------- d-----w- c:\program files\virtualdubmod
      2012-12-06 23:01 . 2012-12-06 23:21 -------- d-----w- c:\users\Jessica\AppData\Local\panda4_0dn
      2012-12-06 21:35 . 2012-12-06 21:35 -------- d-----w- c:\programdata\blekko toolbars
      2012-12-06 21:35 . 2012-12-06 21:35 -------- d-----w- c:\program files\Toolbar Cleaner
      2012-12-06 21:34 . 2012-11-07 15:00 46672 ----a-w- c:\windows\system32\drivers\PSKMAD.sys
      2012-12-06 21:34 . 2012-12-06 21:35 -------- d-----w- c:\program files\pandasecuritytb
      2012-12-06 20:49 . 2012-12-06 20:48 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
      2012-12-06 20:48 . 2012-12-06 20:48 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
      2012-12-06 20:30 . 2012-12-06 20:30 -------- d-----w- C:\_OTL
      2012-12-06 20:17 . 2012-12-06 20:17 -------- d-----w- c:\program files\ERUNT
      2012-12-06 11:02 . 2012-12-06 11:03 -------- d-----w- c:\program files\Google
      2012-12-05 08:44 . 2012-12-06 09:39 -------- d-----w- C:\_AT-Destroyer
      2012-12-05 03:58 . 2012-12-05 03:58 105692 ----a-w- c:\programdata\Microsoft\Windows Defender\LocalCopy\{6134778D-23CC-BF94-4CE5-9DB5C5703673}-Bu_.exe
      2012-12-05 03:52 . 2012-11-29 08:26 2397152 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll
      2012-12-05 03:35 . 2012-12-05 03:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
      2012-12-05 03:35 . 2012-09-30 01:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
      2012-12-02 18:24 . 2012-12-02 18:24 -------- d-----w- c:\program files\Apple Software Update
      2012-11-21 22:51 . 2012-11-21 22:51 -------- d-----w- c:\programdata\Browser Manager
      2012-11-21 22:51 . 2012-10-27 05:27 816608 ----a-w- c:\program files\Mozilla Firefox\sqlite3.dll
      .
      .
      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2012-12-12 19:29 . 2012-09-17 18:51 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
      2012-12-12 19:29 . 2011-07-19 15:43 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
      2012-12-06 20:48 . 2012-04-02 00:10 746984 ----a-w- c:\windows\system32\deployJava1.dll
      2012-11-10 01:01 . 2012-11-10 01:01 123944 ----a-w- c:\windows\system32\drivers\PSINProt.sys
      2012-11-10 01:01 . 2012-11-10 01:01 114216 ----a-w- c:\windows\system32\drivers\PSINProc.sys
      2012-11-10 01:01 . 2012-11-10 01:01 174632 ----a-w- c:\windows\system32\drivers\PSINKNC.sys
      2012-11-10 01:00 . 2012-11-10 01:00 149544 ----a-w- c:\windows\system32\drivers\PSINAflt.sys
      2012-11-10 01:00 . 2012-11-10 01:00 104488 ----a-w- c:\windows\system32\drivers\PSINFile.sys
      2012-11-09 17:23 . 2012-11-09 17:23 276520 ----a-w- c:\windows\system32\drivers\NNSStrm.sys
      2012-11-09 17:23 . 2012-11-09 17:23 133928 ----a-w- c:\windows\system32\drivers\NNStlsc.sys
      2012-11-09 17:23 . 2012-11-09 17:23 370216 ----a-w- c:\windows\system32\drivers\NNSProt.sys
      2012-11-09 17:23 . 2012-11-09 17:23 191528 ----a-w- c:\windows\system32\drivers\NNSPrv.sys
      2012-11-09 17:23 . 2012-11-09 17:23 128040 ----a-w- c:\windows\system32\drivers\NNSSmtp.sys
      2012-11-09 17:23 . 2012-11-09 17:23 74792 ----a-w- c:\windows\system32\drivers\NNSPihsw.sys
      2012-11-09 17:23 . 2012-11-09 17:23 125480 ----a-w- c:\windows\system32\drivers\NNSPop3.sys
      2012-11-09 17:23 . 2012-11-09 17:23 163112 ----a-w- c:\windows\system32\drivers\NNSIds.sys
      2012-11-09 17:23 . 2012-11-09 17:23 139176 ----a-w- c:\windows\system32\drivers\NNSHttp.sys
      2012-11-09 17:23 . 2012-11-09 17:23 133544 ----a-w- c:\windows\system32\drivers\NNSpicc.sys
      2012-11-09 17:23 . 2012-11-09 17:23 119208 ----a-w- c:\windows\system32\drivers\NNSAlpc.sys
      2012-10-22 18:08 . 2012-10-22 18:08 29224 ----a-w- c:\windows\system32\drivers\NNSNAHSL.sys
      2012-10-16 07:39 . 2012-12-07 02:08 561664 ----a-w- c:\windows\apppatch\AcLayers.dll
      2012-09-28 16:32 . 2012-09-28 16:32 5989776 ----a-w- c:\windows\system32\usbaaplrc.dll
      2012-09-28 16:32 . 2012-09-28 16:32 44544 ----a-w- c:\windows\system32\drivers\usbaapl.sys
      2012-11-29 08:26 . 2012-12-05 03:53 262112 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
      .
      .
      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4
      .
      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}]
      2012-10-15 13:02 87176 ----a-w- c:\program files\pandasecuritytb\pandasecurityDx.dll
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
      "{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}"= "c:\program files\pandasecuritytb\pandasecurityDx.dll" [2012-10-15 87176]
      .
      [HKEY_CLASSES_ROOT\clsid\{b821bf60-5c2d-41eb-92dc-3e4ccd3a22e4}]
      .
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ares"="c:\program files\Ares\Ares.exe" [2012-02-02 3209216]
      "Pokki"="c:\users\Jessica\AppData\Local\Pokki\v0.260.8.396\pokki.exe" [2012-11-28 5453656]
      "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-02-11 10025576]
      "Persistence"="c:\windows\system32\igfxpers.exe" [2010-06-16 150552]
      "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-02-05 1692968]
      "Power Management"="c:\program files\eMachines\eMachines Power Management\ePowerTray.exe" [2011-05-10 715368]
      "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
      "Panda Security URL Filtering"="c:\programdata\Panda Security URL Filtering\Panda_URL_Filtering.exe" [2012-10-15 221832]
      "RIMBBLaunchAgent.exe"="c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-09-01 90448]
      "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-06-16 141848]
      "PSUAMain"="c:\program files\Panda Security\Panda Cloud Antivirus\PSUAMain.exe" [2012-11-15 32032]
      .
      c:\users\Jessica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
      ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
      "ConsentPromptBehaviorAdmin"= 5 (0x5)
      "ConsentPromptBehaviorUser"= 3 (0x3)
      "EnableUIADesktopToggle"= 0 (0x0)
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
      "aux"=wdmaud.drv
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
      2012-07-27 20:51 919008 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
      2011-07-28 23:08 1259376 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
      2010-06-16 14:33 173592 ----a-w- c:\windows\System32\hkcmd.exe
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
      2012-12-05 04:13 968592 ----a-w- c:\program files\uTorrent\uTorrent.exe
      .
      R1 NNSNAHSL;Network Activity Hook Server LightWeight Filter Driver;c:\windows\system32\DRIVERS\NNSNAHSL.sys [x]
      R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
      R3 EUCR;EUCR;c:\windows\system32\DRIVERS\EUCR6SK.SYS [x]
      R3 GamesAppService;GamesAppService;c:\program files\WildTangent Games\App\GamesAppService.exe [x]
      R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl.sys [x]
      R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
      R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
      R4 NNSPIHSW;NNSPIHSW;c:\windows\system32\DRIVERS\NNSPihsw.sys [x]
      R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
      S1 NNSALPC;NNSALPC;c:\windows\system32\DRIVERS\NNSAlpc.sys [x]
      S1 NNSHTTP;NNSHTTP;c:\windows\system32\DRIVERS\NNSHttp.sys [x]
      S1 NNSIDS;NNSIDS;c:\windows\system32\DRIVERS\NNSIds.sys [x]
      S1 NNSPICC;NNSPICC;c:\windows\system32\DRIVERS\NNSPicc.sys [x]
      S1 NNSPOP3;NNSPOP3;c:\windows\system32\DRIVERS\NNSPop3.sys [x]
      S1 NNSPROT;NNSPROT;c:\windows\system32\DRIVERS\NNSProt.sys [x]
      S1 NNSPRV;NNSPRV;c:\windows\system32\DRIVERS\NNSPrv.sys [x]
      S1 NNSSMTP;NNSSMTP;c:\windows\system32\DRIVERS\NNSSmtp.sys [x]
      S1 NNSSTRM;NNSSTRM;c:\windows\system32\DRIVERS\NNSStrm.sys [x]
      S1 NNSTLSC;NNSTLSC;c:\windows\system32\DRIVERS\NNSTlsc.sys [x]
      S1 PSINKNC;PSINKNC;c:\windows\system32\DRIVERS\psinknc.sys [x]
      S2 ePowerSvc;Acer ePower Service;c:\program files\eMachines\eMachines Power Management\ePowerSvc.exe [x]
      S2 GREGService;GREGService;c:\program files\eMachines\Registration\GREGsvc.exe [x]
      S2 Live Updater Service;Live Updater Service;c:\program files\eMachines\eMachines Updater\UpdaterService.exe [x]
      S2 NanoServiceMain;Panda Cloud Antivirus Service;c:\program files\Panda Security\Panda Cloud Antivirus\PSANHost.exe [x]
      S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x]
      S2 PSINAflt;PSINAflt;c:\windows\system32\DRIVERS\PSINAflt.sys [x]
      S2 PSINFile;PSINFile;c:\windows\system32\DRIVERS\PSINFile.sys [x]
      S2 PSINProc;PSINProc;c:\windows\system32\DRIVERS\PSINProc.sys [x]
      S2 PSINProt;PSINProt;c:\windows\system32\DRIVERS\PSINProt.sys [x]
      S2 PSUAService;Panda Product Service;c:\program files\Panda Security\Panda Cloud Antivirus\PSUAService.exe [x]
      S3 PSKMAD;PSKMAD;c:\windows\system32\DRIVERS\PSKMAD.sys [x]
      .
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
      LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc
      .
      Contents of the 'Scheduled Tasks' folder
      .
      2012-12-19 c:\windows\Tasks\Adobe Flash Player Updater.job
      - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-17 19:29]
      .
      2012-12-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
      - c:\program files\Google\Update\GoogleUpdate.exe [2012-12-06 11:02]
      .
      2012-12-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
      - c:\program files\Google\Update\GoogleUpdate.exe [2012-12-06 11:02]
      .
      .
      ------- Supplementary Scan -------
      .
      uStart Page = hxxp://pandasecurity.mystart.com/?source=5b97eeb3&tbp=homepage&toolbarid=pandasecuritytb&v=4_0&u=0D32F7F345CD6720DE482A50C10F21C0
      mStart Page = Google
      uInternet Settings,ProxyOverride = *.local
      IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
      TCP: DhcpNameServer = 192.168.1.254
      FF - ProfilePath - c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\
      FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.mx/
      FF - ExtSQL: 2012-11-21 17:52; {58bd07eb-0ee0-4df0-8121-dc9b693373df}; c:\programdata\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension
      FF - ExtSQL: 2012-12-04 21:57; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
      FF - ExtSQL: 2012-12-06 15:34; {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}; c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}
      .
      .
      --------------------- LOCKED REGISTRY KEYS ---------------------
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
      @Denied: (A 2) (Everyone)
      @="FlashBroker"
      "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101"
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
      "Enabled"=dword:00000001
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
      @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe"
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
      @Denied: (A 2) (Everyone)
      @="IFlashBroker5"
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
      @="{00020424-0000-0000-C000-000000000046}"
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      "Version"="1.0"
      .
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
      @Denied: (A) (Users)
      @Denied: (A) (Everyone)
      @Allowed: (B 1 2 3 4 5) (S-1-5-20)
      "BlindDial"=dword:00000000
      .
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
      @Denied: (Full) (Everyone)
      .
      --------------------- DLLs Loaded Under Running Processes ---------------------
      .
      - - - - - - - > 'Explorer.exe'(5100)
      c:\programdata\Panda Security URL Filtering\panda_url_filtering.dll
      .
      ------------------------ Other Running Processes ------------------------
      .
      c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
      c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
      c:\program files\Bonjour\mDNSResponder.exe
      c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
      c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
      c:\windows\system32\taskhost.exe
      c:\windows\system32\conhost.exe
      c:\program files\Panda USB Vaccine\USBVaccine.exe
      c:\windows\system32\igfxsrvc.exe
      c:\program files\Synaptics\SynTP\SynTPHelper.exe
      c:\windows\system32\igfxext.exe
      c:\windows\system32\wbem\unsecapp.exe
      c:\program files\Windows Media Player\wmpnetwk.exe
      .
      **************************************************************************
      .
      Completion time: 2012-12-19 03:42:06 - machine was rebooted
      ComboFix-quarantined-files.txt 2012-12-19 09:42
      ComboFix2.txt 2012-12-07 08:06
      ComboFix3.txt 2012-12-06 22:28
      .
      Pre-Run: 97,570,127,872 bytes libres
      Post-Run: 97,668,222,976 bytes libres
      .
      - - End Of File - - 22BA34C8FC4639244038799E94EBE42A

    4. #14
      Moderador Gral.
      Avatar de @Javier_HF
      Registrado
      jun 2006
      Ubicación
      Spain.
      Mensajes
      21.708

      Re: pc muy muy lenta y pagina de babylon en exploradores

      1.- Abre el Notepad (Bloc de notas)

      • En Windows XP
        Ve a Inicio >> Selecciona Ejecutar >> Escribe dentro Notepad.


      • En Windows Vista y/o Windows 7
        Ve a Inicio >> Todos los programas >> Accesorios >> Selecciona Ejecutar >> Escribe dentro Notepad.


      2.-
      Ahora copia y pega la información, del interior del siguiente recuadro, dentro del Notepad.

      Atención : la palabra "Código:" NO se copia.
      Código:
      KillAll::
      ClearJavaCache::
      Folder::
      c:\programdata\blekko toolbars
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}
      c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
      c:\programdata\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension
      File::
      c:\users\Jessica\AppData\Local\Pokki\v0.260.8.396\pokki.exe
      Registry::
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Pokki"=-
      DDS::
      uStart Page = hxxp://pandasecurity.mystart.com/?source=5b97eeb3&tbp=homepage&toolbarid=pandasecuritytb&v=4_0&u=0D32F7F345CD6720DE482A50C10F21C0
      Firefox::
      FF - ProfilePath - c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\
      FF - ExtSQL: 2012-11-21 17:52; {58bd07eb-0ee0-4df0-8121-dc9b693373df}; c:\programdata\Browser Manager\2.5.911.18\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension
      FF - ExtSQL: 2012-12-04 21:57; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
      FF - ExtSQL: 2012-12-06 15:34; {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}; c:\users\Jessica\AppData\Roaming\Mozilla\Firefox\Profiles\mrho76bv.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}

      3.-
      Guarda este archivo con el nombre CFScript.txt dentro del Escritorio.

      4.- Arrastra y suelta el archivo CFScript.txt dentro del archivo ComboFix.exe como muestra la animación aquí abajo. Esto activara ComboFix nuevamente.
      Antes de usar el CFScript....
      Súbenos el nuevo informe de ComboFix e indícanos como funciona tu equipo.

      Saludos, Javier.
      Quien no lo intenta no lo consigue | ;-)

      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    Página 2 de 2 PrimeroPrimero 12